CVE-2026-21914: Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos).
If an SRX Series device receives a specifically malformed GPRS Tunnelling Protocol (GTP) Modify Bearer Request message, a lock is acquired and never released. This results in other threads not being able to acquire a lock themselves, causing a watchdog timeout leading to FPC crash and restart. This issue leads to a complete traffic outage until the device has automatically recovered.
This issue affects Junos OS on SRX Series:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R1-S1, 25.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21914?
CVE-2026-21914 is classified as a high severity Denial-of-Service vulnerability.
How do I fix CVE-2026-21914?
To mitigate CVE-2026-21914, you should upgrade to the latest version of Junos OS that addresses this vulnerability.
Which versions of Junos OS are affected by CVE-2026-21914?
CVE-2026-21914 affects Junos OS versions up to 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S3, and 24.4R2-S2.
Can CVE-2026-21914 be exploited remotely?
Yes, CVE-2026-21914 can be exploited by an unauthenticated, remote attacker via malformed GTP messages.
What impact does CVE-2026-21914 have on affected systems?
Exploiting CVE-2026-21914 can cause affected Junos OS devices to crash, leading to potential Denial-of-Service conditions.