CVE-2026-21914
7.5Juniper Networks · Junos OS (SRX Series)
An improper locking flaw in the GTP plugin of Juniper Junos OS on SRX Series devices allows unauthenticated network attackers to cause a device crash and denial of service via malformed packets.
Executive summary
A critical denial of service vulnerability in Juniper Networks SRX Series firewalls allows unauthenticated remote attackers to trigger a device crash and complete traffic outage.
Vulnerability
This issue is caused by improper locking within the GPRS Tunnelling Protocol (GTP) plugin, which fails to release a lock when processing a malformed Modify Bearer Request message. This unauthenticated remote exploit forces other threads to hang, ultimately triggering a watchdog timeout that results in an FPC crash and service interruption.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high potential for operational disruption. Because the exploit can be triggered by an unauthenticated network attacker, it poses a significant risk to perimeter security and network availability. A successful attack will force a device restart, leading to a complete traffic outage and potential loss of connectivity for all downstream services protected by the SRX appliance.
Remediation
Immediate Action: Upgrade to the patched versions as specified in the Juniper security advisory, specifically releases 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, 25.2R1-S1, 25.2R2, or 25.4R1 and later.
Proactive Monitoring: Monitor system logs for repeated FPC crashes or unexpected watchdog timeouts that correlate with incoming traffic patterns.
Compensating Controls: If immediate patching is not possible, implement firewall filters at the network edge to drop unexpected or malformed GTP traffic directed toward the SRX control plane.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given that this vulnerability allows for unauthenticated remote denial of service on critical network infrastructure, organizations should prioritize the deployment of the provided firmware updates. Ensure that all SRX Series devices are audited against the affected version list and that patch management schedules are accelerated to mitigate the risk of unplanned outages.