CVE-2026-57029: Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).
When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.
This issue affects Junos OS Evolved on QFX Series:
all 23.2 versions, 23.4 versions before 23.4R2-S7-EVO, 24.2 versions before 24.2R2-S5-EVO, 24.4 versions before 24.4R2-S3-EVO, 25.2 versions before 25.2R2-EVO.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS Evolved (QFX Series)to a version that resolves this vulnerability.Fixed in 23.4R2-S7-EVO - Upgrade
Upgrade
Juniper Networks Junos OS Evolved (QFX Series)to a version that resolves this vulnerability.Fixed in 24.2R2-S5-EVO - Upgrade
Upgrade
Juniper Networks Junos OS Evolved (QFX Series)to a version that resolves this vulnerability.Fixed in 24.4R2-S3-EVO - Upgrade
Upgrade
Juniper Networks Junos OS Evolved (QFX Series)to a version that resolves this vulnerability.Fixed in 25.2R2-EVO - Upgrade
Upgrade
Juniper Networks Junos OS Evolved (QFX Series)to a version that resolves this vulnerability.Fixed in 25.4R1-EVO
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57029?
The severity of CVE-2026-57029 is medium with a score of 5.3.
How do I fix CVE-2026-57029?
To fix CVE-2026-57029, ensure you update your Junos OS Evolved on QFX Series to the latest patched version.
What systems are affected by CVE-2026-57029?
CVE-2026-57029 affects Juniper Networks Junos OS Evolved specifically on QFX Series hardware.
What type of vulnerability is CVE-2026-57029?
CVE-2026-57029 is classified as a Missing Synchronization vulnerability.
What impact does CVE-2026-57029 have?
The impact of CVE-2026-57029 is a Denial-of-Service (DoS) that can be triggered by an adjacent, unauthenticated attacker.