HIGH🇬🇧 English

CVE-2026-57030

Race condition w PFE Juniper SRX Series — DoS przez akumulację sesji

CVSS 8.2v4.0pub. 2026-07-09upd. 2026-07-13

Podatność typu race condition w silniku przekazywania pakietów (PFE) systemu Juniper Junos OS na urządzeniach SRX Series umożliwia nieuwierzytelnionemu atakującemu zdalnie wywołanie odmowy usługi (DoS). Błąd może prowadzić do zatrzymania ruchu sieciowego lub automatycznego restartu urządzenia.

Pokaż oryginał (EN)

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds: user@host> show security flow session | match timeout Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary': user@host> show security flow session summary | match invalid Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot. This issue affects Junos OS on SRX Series: * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S1, 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect releases earlier than 24.2R1;

🤖 Analiza AI
Jak działa

Podczas usuwania wygasłych sesji ruchu stanowego w urządzeniach SRX Series proces powinien ustawiać timeout przepływu na 3 sekundy przed jego usunięciem. Na skutek race condition podczas ustawiania tego timeoutu istnieje szansa, że zostanie on błędnie ustawiony na bardzo wysoką wartość (powyżej 10 000 sekund). Prowadzi to do stopniowej akumulacji nieprawidłowych sesji (invalidated sessions), których nie można ręcznie wyczyścić poleceniem 'clear security flow session'. W konsekwencji dochodzi do wstrzymania przekazywania ruchu (wymagającego ręcznego restartu) lub do awarii procesu flowd i automatycznego restartu urządzenia.

Skutki

Atakujący może doprowadzić do całkowitego zatrzymania przekazywania ruchu sieciowego przez urządzenie lub wywołać jego niekontrolowany restart, co skutkuje przerwą w dostępności usług sieciowych.

Mitygacja

Należy zaktualizować Junos OS do wersji 24.2R2-S3 lub nowszej (w gałęzi 24.2), 24.4R2-S1 / 24.4R2-S2 lub nowszej (w gałęzi 24.4) albo 25.2R1-S2 / 25.2R2 lub nowszej (w gałęzi 25.2). Szczegóły dostępne w portalu producenta: https://supportportal.juniper.net/JSA110090

Kogo dotyczy

Juniper Junos OS na platformach SRX Series (w tym SRX1500, SRX1600): wersje 24.2 przed 24.2R2-S3, wersje 24.4 przed 24.4R2-S1 i 24.4R2-S2, wersje 25.2 przed 25.2R1-S2 i 25.2R2. Problem nie dotyczy wersji wcześniejszych niż 24.2R1.

Uwagi

Dokładne warunki wywołania race condition są częściowo poza kontrolą atakującego (AT:P w wektorze CVSS), jednak luka jest eksploatowalna zdalnie bez uwierzytelnienia. W opisie wskazano możliwość monitorowania efektu ataku poprzez obserwację rosnącej wartości 'Invalidated sessions' w poleceniu 'show security flow session summary'.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
  • Juniper Junos

    OS
    Juniper
    24.224.425.2
  • Juniper Srx1500

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx1600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx2300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx320

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx340

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx345

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx380

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx400

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4100

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4120

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4200

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4300

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx440

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx4700

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5400

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5600

    HW
    Juniper
    wszystkie wersje
  • Juniper Srx5800

    HW
    Juniper
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Race Condition
CWE
Referencje

Powiązane podatności

CVE-2023-36845CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE przez modyfikację zmiennej PHP w J-Web Juniper Junos OS (EX/SRX)

CVE-2024-21591CRITICAL9.8PL ✓ten sam produkt

Out-of-bounds Write w J-Web Juniper Junos OS — RCE z uprawnieniami root

CVE-2021-0248CRITICAL10.0PL ✓ten sam produkt

Hard-coded Credentials w Juniper Junos OS na urządzeniach NFX Series

CVE-2021-0254CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w usłudze overlayd Juniper Junos OS — RCE i DoS

CVE-2021-0211CRITICAL10.0PL ✓ten sam produkt

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message