Database/Firmware, BMC & network fabric
Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): A specific *valid* IP packet that needs to be routed
Impact
A specific *valid* IP packet that needs to be routed over a VXLAN tunnel wedges the Packet Forwarding Engine on a QFX10000. Because the trigger is a legitimate packet rather than a malformed one, no input filter catches it, and QFX10000 sits in the spine or super-spine role where a wedge partitions the fabric rather than dropping one rack.
Who can reach it
A network-based attacker — or, given the trigger is valid traffic, an unlucky workload — sending the specific packet into a VXLAN-routed path.
What to do
Junos upgrade plus reboot on affected QFX10000 devices, staged so redundant spines are never both down. No filtering workaround, since the triggering packet is valid.
References
Related entries
- UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootCVE-2023-39538 · UEFI image parsers, AMI AptioVHigh
- UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOSCVE-2023-39539 · UEFI image parsers, AMI AptioVHigh
- Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet ForwardingCVE-2023-44199 · Juniper Junos OS Packet Forwarding Engine (MX Series)High
- AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6CVE-2023-45232 · AMI AptioV UEFI BIOS (EDK II network stack, IPv6)High
- EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butCVE-2023-45233 · EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing)High
- EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersCVE-2023-45236 · EDK II NetworkPkg (TCP initial sequence number generation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.