PT-2026-3130 · Juniper Networks · Mx Series+2
Published
2026-01-14
·
Updated
2026-01-16
·
CVE-2026-21918
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 22.4R3-S7
Juniper Networks Junos OS versions 23.2 before 23.2R2-S3
Juniper Networks Junos OS versions 23.4 before 23.4R2-S4
Juniper Networks Junos OS versions 24.2 before 24.2R2
Description
A Double Free issue exists in the flow processing daemon (
flowd) of Juniper Networks Junos OS on SRX and MX Series devices. An unauthenticated, network-based attacker can trigger a Denial-of-Service (DoS) condition by sending a specific sequence of packets during TCP session establishment. This sequence causes a double free, leading to a crash of the flowd daemon and a restart of the Flexible Packet Processing (FPC).Recommendations
Upgrade to Junos OS version 22.4R3-S7 or later.
Upgrade to Junos OS version 23.2R2-S3 or later.
Upgrade to Junos OS version 23.4R2-S4 or later.
Upgrade to Junos OS version 24.2R2 or later.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos
Mx Series
Srx Series