VYPR
Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 10, 2026

Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash

CVE-2026-57029

Description

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).

When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.

This issue affects Junos OS Evolved on QFX Series:

  • all 23.2 versions,
  • 23.4 versions before 23.4R2-S7-EVO,
  • 24.2 versions before 24.2R2-S5-EVO,
  • 24.4 versions before 24.4R2-S3-EVO,
  • 25.2 versions before 25.2R2-EVO.

Affected products

1
  • Range: all 23.2 versions, 23.4 versions before 23.4R2-S7-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S3-EVO, 25.2 versions before 25.2R2-EVO

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.