CVE-2026-21920: Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd will crash and restart, which causes a service interruption until the process has recovered.
This issue affects Junos OS on SRX Series:
23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R2.
This issue does not affect Junos OS versions before 23.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21920?
CVE-2026-21920 is classified as a high-severity vulnerability that can lead to Denial-of-Service (DoS).
How do I fix CVE-2026-21920?
To fix CVE-2026-21920, update the Junos OS on SRX Series devices to a version higher than 24.4R2, such as 23.4R2-S6 or later.
What is the impact of CVE-2026-21920?
The impact of CVE-2026-21920 is that it allows an unauthenticated attacker to crash the DNS subsystem, causing a DoS condition.
Who is affected by CVE-2026-21920?
CVE-2026-21920 affects devices running Junos OS on all SRX Series versions up to 24.4R2, making them vulnerable to an attack.
Is CVE-2026-21920 remotely exploitable?
Yes, CVE-2026-21920 can be exploited remotely by a network-based attacker due to the nature of the vulnerability in the DNS module.