CVE-2021-0230
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/04/2021
Last modified:
05/08/2022
Description
On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is consumed, the traffic will be impacted and a reboot might be required. The following log can be seen if this issue happens. /kernel: rt_pfe_veto: Memory over consumed. Op 1 err 12, rtsm_id 0:-1, msg type 72 /kernel: rt_pfe_veto: free kmem_map memory = (20770816) curproc = kmd An administrator can use the following CLI command to monitor the status of memory consumption (ifstat bucket): user@device > show system virtual-memory no-forwarding | match ifstat Type InUse MemUse HighUse Limit Requests Limit Limit Size(s) ifstat 2588977 162708K - 19633958
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:juniper:junos:17.1:r3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.1:r3-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.1:r3-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.1:r3-s3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:-:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s1:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s2:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s3:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s4:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s5:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s6:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s7:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r1-s8:*:*:*:*:*:* | ||
| cpe:2.3:o:juniper:junos:17.2:r2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



