PT-2026-56979 · Juniper Networks · Junos+4
CVE-2026-57025
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS versions prior to 23.2R2-S7
Junos OS versions 23.4 prior to 23.4R2-S7
Junos OS versions 24.2 prior to 24.2R2
Junos OS versions 24.4 prior to 24.4R1-S2
Junos OS Evolved versions prior to 23.2R2-S7-EVO
Junos OS Evolved versions 23.4 prior to 23.4R2-S8-EVO
Junos OS Evolved versions 24.2 prior to 24.2R2-EVO
Junos OS Evolved versions 24.4 prior to 24.4R1-S3-EVO
Description
A Return of Pointer Value Outside of Expected Range in the fileio library allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series, and MX Series, executing a specific
show l2-learning command triggers an l2ald crash, resulting in a temporary service impact for all layer 2 services until the process automatically restarts.Recommendations
Update Junos OS to version 23.2R2-S7 or later.
Update Junos OS 23.4 to version 23.4R2-S7 or later.
Update Junos OS 24.2 to version 24.2R2 or later.
Update Junos OS 24.4 to version 24.4R1-S2 or later.
Update Junos OS Evolved to version 23.2R2-S7-EVO or later.
Update Junos OS Evolved 23.4 to version 23.4R2-S8-EVO or later.
Update Junos OS Evolved 24.2 to version 24.2R2-EVO or later.
Update Junos OS Evolved 24.4 to version 24.4R1-S3-EVO or later.
As a temporary mitigation, restrict the use of the
show l2-learning command by low-privileged users.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Series
Junos
Junos Evolved
Mx Series
Qfx Series