CVE-2026-21909: Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition.
Memory usage can be monitored through the use of the 'show task memory detail' command. For example:
user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229
user@junos>
show task memory detail | match ted-infra TED-INFRA-COOKIE 31 1360 34 1472 307
This issue affects:
Junos OS:
from 23.2 before 23.2R2, from 23.4 before 23.4R1-S2, 23.4R2, from 24.1 before 24.1R2;
Junos OS Evolved:
from 23.2 before 23.2R2-EVO, from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO, from 24.1 before 24.1R2-EVO.
This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21909?
CVE-2026-21909 is considered a high severity vulnerability due to its potential to cause RPD crashes through a memory leak.
How do I fix CVE-2026-21909?
To fix CVE-2026-21909, you should upgrade your Junos OS or Junos OS Evolved to the latest patched version as recommended by Juniper Networks.
What impact does CVE-2026-21909 have on my network?
CVE-2026-21909 can lead to a denial-of-service condition by crashing the routing protocol daemon on affected devices.
Which versions of Junos OS are affected by CVE-2026-21909?
Versions of Junos OS between unspecified and 23.4R2, as well as Junos OS Evolved up to 23.4R2-EVO, are affected by CVE-2026-21909.
Who can exploit the CVE-2026-21909 vulnerability?
CVE-2026-21909 can potentially be exploited by unauthenticated attackers who send specific IS-IS update packets.