CVE-2023-22395 Details
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In an MPLS scenario specific packets destined to an Integrated Routing and Bridging (irb) interface of the device will cause a buffer (mbuf) to leak. Continued receipt of these specific packets will eventually cause a loss of connectivity to and from the device, and requires a reboot to recover. These mbufs can be monitored by using the CLI command 'show system buffers': user@host> show system buffers 783/1497/2280 mbufs in use (current/cache/total) user@host> show system buffers 793/1487/2280 mbufs in use (current/cache/total) <<<<<< mbuf usage increased This issue affects Juniper Networks Junos OS: All versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R3-S9; 20.1 version 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S3; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3-S1; 21.4 versions prior to 21.4R3; 22.1 versions prior to 22.1R2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA70191 | CVE | Vendor Advisory |
| https://kb.juniper.net/JSA70191 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 19.3 19.3 - 19.3 r1 19.3 r1-s1 19.3 r2 19.3 r2-s1 19.3 r2-s2 19.3 r2-s3 19.3 r2-s4 19.3 r2-s5 19.3 r2-s6 19.3 r3 19.3 r3-s1 19.3 r3-s2 19.3 r3-s3 19.3 r3-s4 19.3 r3-s5 19.3 r3-s6 19.4 - 19.4 r1 19.4 r1-s1 19.4 r1-s2 19.4 r1-s3 19.4 r1-s4 19.4 r2 19.4 r2-s1 19.4 r2-s2 19.4 r2-s3 19.4 r2-s4 19.4 r2-s5 19.4 r2-s6 19.4 r2-s7 19.4 r3 19.4 r3-s1 19.4 r3-s2 19.4 r3-s3 19.4 r3-s4 19.4 r3-s5 19.4 r3-s6 19.4 r3-s7 19.4 r3-s8 19.4 r3-s9 20.1 r1 20.1 r1-s1 20.1 r1-s2 20.1 r1-s3 20.1 r1-s4 20.1 r2 20.1 r2-s1 20.1 r2-s2 20.1 r3 20.1 r3-s1 20.1 r3-s2 20.1 r3-s3 20.1 r3-s4 20.2 - 20.2 r1 20.2 r1-s1 20.2 r1-s2 20.2 r1-s3 20.2 r2 20.2 r2-s1 20.2 r2-s2 20.2 r2-s3 20.2 r3 20.2 r3-s1 20.2 r3-s2 20.2 r3-s3 20.2 r3-s4 20.3 - 20.3 r1 20.3 r1-s1 20.3 r1-s2 20.3 r2 20.3 r2-s1 20.3 r3 20.3 r3-s1 20.3 r3-s2 20.3 r3-s3 20.3 r3-s4 20.4 - 20.4 r1 20.4 r1-s1 20.4 r2 20.4 r2-s1 20.4 r2-s2 20.4 r3 20.4 r3-s1 20.4 r3-s2 20.4 r3-s3 21.1 - 21.1 r1 21.1 r1-s1 21.1 r2 21.1 r2-s1 21.1 r2-s2 21.1 r3 21.1 r3-s1 21.1 r3-s2 21.2 - 21.2 r1 21.2 r1-s1 21.2 r1-s2 21.2 r2 21.2 r2-s1 21.2 r2-s2 21.2 r3 21.2 r3-s1 21.3 - 21.3 r1 21.3 r1-s1 21.3 r1-s2 21.3 r2 21.3 r2-s1 21.3 r2-s2 21.3 r3 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 22.1 r1 22.1 r1-s1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 24, 2023 | Initial Analysis | [email protected] |