Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 10, 2026
Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
CVE-2026-57029
Description
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).
When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.
This issue affects Junos OS Evolved on QFX Series:
- all 23.2 versions,
- 23.4 versions before 23.4R2-S7-EVO,
- 24.2 versions before 24.2R2-S5-EVO,
- 24.4 versions before 24.4R2-S3-EVO,
- 25.2 versions before 25.2R2-EVO.
Affected products
1- Range: all 23.2 versions, 23.4 versions before 23.4R2-S7-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S3-EVO, 25.2 versions before 25.2R2-EVO
Patches
Vulnerability mechanics
References
1- supportportal.juniper.net/JSA110089mitrevendor-advisory
News mentions
0No linked articles in our index yet.