CVE-2026-57025: Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).
On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.
This issue affects EX Series, QFX Series, MX Series: Junos OS:
all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2, 24.4 versions before 24.4R1-S2.
Junos OS Evolved: all versions before 23.2R2-S7-EVO, 23.4 versions before 23.4R2-S8-EVO, 24.2 versions before 24.2R2-EVO, 24.4 versions before 24.4R1-S3-EVO.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 23.2R2-S7 - Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 23.4R2-S7 - Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 24.2R2 - Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 24.4R1-S2 - Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 24.4R2 - Upgrade
Upgrade
Junos OS (EX/QFX/MX)to a version that resolves this vulnerability.Fixed in 25.2R1 - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 23.2R2-S7-EVO - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 23.4R2-S8-EVO - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 24.2R2-EVO - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 24.4R1-S3-EVO - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 24.4R2-EVO - Upgrade
Upgrade
Junos OS Evolvedto a version that resolves this vulnerability.Fixed in 25.2R1-EVO - Compensating control
Mitigate the l2ald crash condition by restricting a low-privileged user’s ability to run the specific operational commands mentioned: 'show l2-learning' and 'show ethernet-switching' on EX Series, QFX Series, and MX Series.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57025?
The severity of CVE-2026-57025 is rated medium with a score of 6.8.
How do I fix CVE-2026-57025?
To mitigate CVE-2026-57025, it is recommended to apply the latest patches provided by Juniper Networks for the affected Junos OS variants.
What does CVE-2026-57025 affect?
CVE-2026-57025 affects Junos OS and Junos OS Evolved running on EX Series, QFX Series, and MX Series devices.
What type of vulnerability is CVE-2026-57025?
CVE-2026-57025 is a Return of Pointer Value Outside of Expected Range vulnerability that can lead to a Denial-of-Service (DoS).
Who can exploit CVE-2026-57025?
A low-privileged, local attacker can exploit CVE-2026-57025 by issuing a specific 'show l2-learning' command.