PT-2025-29237 · Juniper Networks+1 · Junos+1
Published
2025-07-09
·
Updated
2025-07-11
·
CVE-2025-52948
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X |
Name of the Vulnerable Software and Affected Versions:
Juniper Networks Junos OS versions prior to 21.2R3-S9
Juniper Networks Junos OS versions 21.4 before 21.4R3-S10
Juniper Networks Junos OS versions 22.2 before 22.2R3-S6
Juniper Networks Junos OS versions 22.4 before 22.4R3-S7
Juniper Networks Junos OS versions 23.2 before 23.2R2-S3
Juniper Networks Junos OS versions 23.4 before 23.4R2-S3
Juniper Networks Junos OS versions 24.2 before 24.2R1-S1, 24.2R2
Description:
An Improper Handling of Exceptional Conditions vulnerability exists in Berkeley Packet Filter (BPF) processing. This can allow an attacker, in rare cases, to send specific traffic patterns that cause the Flexible Packet Control (FPC) and system to crash and restart. The issue is due to a race condition during BPF instance cloning, leading to internal structure leakage. This is more likely to occur when packet capturing is enabled.
Recommendations:
Update to Junos OS version 21.2R3-S9 or later.
Update to Junos OS version 21.4R3-S10 or later.
Update to Junos OS version 22.2R3-S6 or later.
Update to Junos OS version 22.4R3-S7 or later.
Update to Junos OS version 23.2R2-S3 or later.
Update to Junos OS version 23.4R2-S3 or later.
Update to Junos OS version 24.2R1-S1 or later.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Berkeley Packet Filter
Junos