CVE-2026-21921: Junos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribing to sensors chassisd or rpd will crash
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS).
When telemetry collectors are frequently subscribing and unsubscribing to sensors continuously over a long period of time, telemetry-capable processes like chassisd, rpd or mib2d will crash and restart, which - depending on the process - can cause a complete outage until the system has recovered.
This issue affects:
Junos OS:
all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2;
Junos OS Evolved:
all versions before 22.4R3-S8-EVO, 23.2 versions before 23.2R2-S5-EVO, 23.4 versions before 23.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21921?
CVE-2026-21921 is a critical severity vulnerability due to potential crashes in the chassisd of Junos OS and Junos OS Evolved.
How do I fix CVE-2026-21921?
To fix CVE-2026-21921, upgrade to the patched versions of Junos OS and Junos OS Evolved beyond the specified vulnerable releases.
What causes CVE-2026-21921?
CVE-2026-21921 is caused by a Use After Free condition in the chassis daemon (chassisd) when telemetry collectors frequently subscribe and unsubscribe.
Which versions are affected by CVE-2026-21921?
CVE-2026-21921 affects Junos OS versions up to 22.4R3-S8, 23.2R2-S5, and 23.4R2, as well as Junos OS Evolved up to 22.4R3-S8-EVO, 23.2R2-S5-EVO, and 23.4R2-EVO.
Can CVE-2026-21921 be exploited remotely?
Yes, CVE-2026-21921 can be exploited remotely by an authenticated attacker.