A Protection Mechanism Failure vulnerability in kernel...
Moderate severity
Unreviewed
Published
Jul 11, 2025
to the GitHub Advisory Database
•
Updated Jul 11, 2025
Description
Published by the National Vulnerability Database
Jul 11, 2025
Published to the GitHub Advisory Database
Jul 11, 2025
Last updated
Jul 11, 2025
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic to an interface to effectively bypass any firewall filtering configured on the interface.
Due to an issue with Junos OS kernel filter processing, the 'payload-protocol' match is not being supported, causing any term containing it to accept all packets without taking any other action. In essence, these firewall filter terms were being processed as an 'accept' for all traffic on the interface.
This issue affects Junos OS:
This is a more complete fix for previously published CVE-2024-21607 (JSA75748).
References