Specifications
1082
Cross-Platform Release Notes for Cisco IOS Release 12.0S
OL-1617-14 Rev. Q0
Resolved Caveats—Cisco IOS Release 12.0(28)S4
• CSCei61732
Cisco IOS may permit arbitrary code execution after exploitation of a heap-based buffer overflow
vulnerability. Cisco has included additional integrity checks in its software, as further described
below, that are intended to reduce the likelihood of arbitrary code execution.
Cisco has made free software available that includes the additional integrity checks for affected
customers.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20051102-timers.shtml.
• CSCei81634
Symptoms: A Cisco 10000 series may leak packet buffers at a low rate.
Conditions: This symptom is observed on a Cisco 10000 series that processes multicast packets
when WRED is configured on any interface.
Workaround: Disable WRED.
• CSCsa86214
Symptoms: Locally-originated and transit packets that are greater than 1599 bytes in length do not
leave a router. BGP and other TCP-based protocols that negotiate large MSS values may go down.
Conditions: This symptom is observed on a Cisco 10000 series that is configured with a PRE or
PRE1 and that performs IP fragmentation.
Workaround: First, enter the show hardware pxf cpu buffer or show pxf cpu buffers command to
verify buffer depletion. Then, perform a microcode-reload of the PXF engine.
• CSCsa95353
Symptoms: A Cisco 10000 series that is configured with an inbound service policy may generate the
following error message:
TOASTER-2-FAULT: T0 HW Exception: CPU[t0r1c3] NULLRD at 0x0CD6 LR 0x096E
Conditions: This symptom is observed on a Cisco 10000 series that runs Cisco IOS
Release 12.0(27)S4 and that is configured with a PRE1 when an MPLS-encapsulated IPv4 packet
that contains IP options is processed. The symptom may also occur in other releases.
Workaround: Remove the inbound service policy.
Resolved Caveats—Cisco IOS Release 12.0(28)S4
Cisco IOS Release 12.0(28)S4 is a rebuild of Cisco IOS Release 12.0(28)S. The caveats listed in this
section are resolved in Cisco IOS Release 12.0(28)S4 but may be open in previous Cisco IOS releases.
This section describes only severity 1, severity 2, and select severity 3 caveats.
Basic System Services
• CSCed44414
Symptoms: When the slave RSP crashes, a QAERROR is observed in the master console, resulting
in a cbus complex. The cbus complex will reload all the VIPs in the router.
Conditions: This symptom happens when the slave crashes in a period when there is a large number
of packets going towards the RSP. A large number of packets go to the RSP when CEF switching is
configured or when routing protocol updates are numerous.
Workaround: There is no workaround.