CVE-2026-21918: Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens. This causes flowd to crash and the respective FPC to restart.
This issue affects Junos OS on SRX and MX Series:
all versions before 22.4R3-S7, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21918?
CVE-2026-21918 has been classified as a high severity vulnerability due to its potential to cause a Denial-of-Service (DoS).
How do I fix CVE-2026-21918?
To mitigate CVE-2026-21918, update your Junos OS software to a version beyond 22.4R3-S7, 23.2R2-S3, 23.4R2-S4, or 24.2R2.
What systems are affected by CVE-2026-21918?
CVE-2026-21918 affects Juniper Networks Junos OS on SRX and MX Series devices.
Can CVE-2026-21918 be exploited remotely?
Yes, CVE-2026-21918 can be exploited by unauthenticated, network-based attackers.
What impact does CVE-2026-21918 have on system performance?
CVE-2026-21918 can lead to a Denial-of-Service (DoS), causing affected systems to crash and become unavailable.