A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).
When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.
This issue affects Junos OS Evolved on QFX Series:
* all 23.2 versions,
* 23.4 versions before 23.4R2-S7-EVO,
* 24.2 versions before 24.2R2-S5-EVO,
* 24.4 versions before 24.4R2-S3-EVO,
* 25.2 versions before 25.2R2-EVO.
References
| Link | Resource |
|---|---|
| https://supportportal.juniper.net/JSA110089 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-09 22:17
Updated : 2026-07-13 20:23
NVD link : CVE-2026-57029
Mitre link : CVE-2026-57029
CVE.ORG link : CVE-2026-57029
JSON object : View
Products Affected
juniper
- qfx5230-64cd
- qfx10008
- qfx5120
- qfx5140
- qfx5210
- qfx5250
- qfx5200
- qfx5110
- qfx5240
- qfx5700
- junos_os_evolved
- qfx5241
- qfx10016
- qfx5220
- qfx5130
CWE
CWE-820
Missing Synchronization
