Skip to content

An Uncontrolled Resource Consumption vulnerability in the...

High severity Unreviewed Published Jul 11, 2024 to the GitHub Advisory Database

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

An Uncontrolled Resource Consumption vulnerability in the

Layer 2 Address Learning Daemon (l2ald)

of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS).

Certain MAC table updates cause a small amount of memory to leak.  Once memory utilization reaches its limit, the issue will result in a system crash and restart.

To identify the issue, execute the CLI command:

user@device> show platform application-info allocations app l2ald-agent
EVL Object Allocation Statistics:

Node   Application     Context Name                               Live   Allocs   Fails     Guids
re0   l2ald-agent               net::juniper::rtnh::L2Rtinfo       1069096 1069302   0         1069302
re0   l2ald-agent               net::juniper::rtnh::NHOpaqueTlv     114     195       0         195

This issue affects Junos OS Evolved:

  • All versions before 21.4R3-S8-EVO,

  • from 22.2-EVO before 22.2R3-S4-EVO,

  • from 22.3-EVO before 22.3R3-S3-EVO,

  • from 22.4-EVO before 22.4R3-EVO,

  • from 23.2-EVO before 23.2R2-EVO.

References

Published by the National Vulnerability Database Jul 10, 2024
Published to the GitHub Advisory Database Jul 11, 2024

Severity

High

Weaknesses

CVE ID

CVE-2024-39557

GHSA ID

GHSA-g26w-g327-7xm5

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.