CVE-2026-21918
7.5Juniper Networks · Junos OS
A double free vulnerability in the flow processing daemon of Juniper Junos OS allows unauthenticated network attackers to cause a denial of service via a specific sequence of TCP packets.
Executive summary
A critical denial of service vulnerability in Juniper Networks Junos OS allows unauthenticated attackers to crash the flow processing daemon and restart the Flexible PIC Concentrator.
Vulnerability
This is a double free vulnerability (CWE-415) triggered within the flowd daemon during TCP session establishment. An unauthenticated, network-based attacker can exploit this by sending a specific sequence of packets to SRX or MX Series devices.
Business impact
The successful exploitation of this vulnerability results in a denial of service, causing the flowd daemon to crash and forcing the affected Flexible PIC Concentrator (FPC) to restart. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to network availability and operational continuity. Organizations relying on SRX and MX Series hardware for perimeter security or core routing face potential service outages if this vulnerability is triggered.
Remediation
Immediate Action: Upgrade Junos OS on affected SRX and MX Series devices to version 22.4R3-S7, 23.2R2-S3, 23.4R2-S4, 24.2R2, 24.4R1, or any subsequent release.
Proactive Monitoring: Monitor system logs for repeated FPC crashes or unexpected daemon restarts that may indicate attempted exploitation.
Compensating Controls: Implement infrastructure access control lists to restrict traffic to the management plane and verify that ingress traffic is strictly filtered to authorized sources where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for service disruption on critical networking infrastructure, administrators should prioritize the deployment of the provided vendor patches. Ensure that all SRX and MX Series devices are updated to the specified secure versions to eliminate the risk of remote denial of service attacks.