A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). In a segment-routing scenario with OSPF as IGP, when a peer interface continuously flaps, next-hop churn will happen and a continuous increase in Routing Protocol Daemon (rpd) memory consumption will be observed. This will eventually lead to an rpd crash and restart when the memory is full. The memory consumption can be monitored using the CLI command "show task memory detail" as shown in the following example: user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 412330 158334720 412330 158334720 RT_TEMPLATE_BOOK_KEE 2064 2560 T 33315 85286400 33315 85286400 user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 419005 160897920 419005 160897920 <=== RT_TEMPLATE_BOOK_KEE 2064 2560 T 39975 102336000 39975 10233600 <=== This issue affects: Juniper Networks Junos OS All versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S8, 19.4R3-S9; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3-S1; 21.4 versions prior to 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R2. Juniper Networks Junos OS Evolved All versions prior to 20.4R3-S4-EVO; 21.4 versions prior to 21.4R2-S1-EVO, 21.4R3-EVO; 22.1 versions prior to 22.1R2-EVO.
This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.5, indicating it requires adjacent network access with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 2 products from juniper, from juniper organizations running these solutions should prioritize assessment and patching.
Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.
2023-01-13T00:15:10.990
2024-11-21T07:44:45.213
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | juniper | junos | < 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.3 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 19.4 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.2 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.3 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 20.4 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.1 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.2 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.3 | Yes |
| Operating System | juniper | junos | 21.4 | Yes |
| Operating System | juniper | junos | 21.4 | Yes |
| Operating System | juniper | junos | 21.4 | Yes |
| Operating System | juniper | junos | 21.4 | Yes |
| Operating System | juniper | junos | 21.4 | Yes |
| Operating System | juniper | junos | 22.1 | Yes |
| Operating System | juniper | junos | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | < 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 20.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 21.4 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
| Operating System | juniper | junos_os_evolved | 22.1 | Yes |
SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For juniper's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.