Database/Firmware, BMC & network fabric
Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): FABRIC DOS: a specific *valid* IP packet that needs
Impact
FABRIC DOS: a specific *valid* IP packet that needs to be routed over a VXLAN tunnel wedges the Packet Forwarding Engine on a QFX10000. Because the trigger is a legitimate packet rather than a malformed one, no input filter catches it, and QFX10000 sits in the spine or super-spine role where a wedge partitions the fabric rather than dropping one rack.
Who can reach it
A network-based attacker — or, given the trigger is valid traffic, an unlucky workload — sending the specific packet into a VXLAN-routed path.
What to do
Junos upgrade plus reboot on affected QFX10000 devices, staged so redundant spines are never both down. No filtering workaround, since the triggering packet is valid.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.