GPU VulnDB

Database/Firmware, BMC & network fabric

Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): A specific *valid* IP packet that needs to be routed

CVSS 7.5CVE-2023-36835Firmware, BMC & network fabriccurated

Impact

A specific *valid* IP packet that needs to be routed over a VXLAN tunnel wedges the Packet Forwarding Engine on a QFX10000. Because the trigger is a legitimate packet rather than a malformed one, no input filter catches it, and QFX10000 sits in the spine or super-spine role where a wedge partitions the fabric rather than dropping one rack.

Who can reach it

A network-based attacker — or, given the trigger is valid traffic, an unlucky workload — sending the specific packet into a VXLAN-routed path.

What to do

Junos upgrade plus reboot on affected QFX10000 devices, staged so redundant spines are never both down. No filtering workaround, since the triggering packet is valid.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.