PT-2026-56983 · Juniper Networks · Junos Evolved

CVE-2026-57029

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Junos OS Evolved on QFX Series versions 23.2 Junos OS Evolved on QFX Series versions prior to 23.4R2-S7-EVO Junos OS Evolved on QFX Series versions prior to 24.2R2-S5-EVO Junos OS Evolved on QFX Series versions prior to 24.4R2-S3-EVO Junos OS Evolved on QFX Series versions prior to 25.2R2-EVO
Description A missing synchronization issue in the flow collector handler allows an adjacent, unauthenticated attacker to trigger a Denial-of-Service (DoS). The problem occurs when the reachability of an sFlow collector changes, causing a next-hop entry update. If this update happens simultaneously with the sFlow thread accessing the next-hop data, the evo-pfemand process crashes, which disrupts all traffic forwarding until the process automatically restarts.
Recommendations Update Junos OS Evolved on QFX Series version 23.2 to a fixed release. Update Junos OS Evolved on QFX Series to version 23.4R2-S7-EVO or later. Update Junos OS Evolved on QFX Series to version 24.2R2-S5-EVO or later. Update Junos OS Evolved on QFX Series to version 24.4R2-S3-EVO or later. Update Junos OS Evolved on QFX Series to version 25.2R2-EVO or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57029

Affected Products

Junos Evolved