CVE-2026-57025
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M
- EPSS probability
- 0.14%
- CWE
- CWE-466
- Published
- 2026-07-09
- Last modified
- 2026-07-16
Affected products
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
Weakness type
Related vulnerabilities
- CVE-2018-25234 — SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
- CVE-2018-25227 — Valentina Studio 9.0.4 Denial of Service via Host Parameter
- CVE-2019-25599 — Backup Key Recovery 2.2.4 Denial of Service via Name Field
- CVE-2019-25586 — Deluge 1.3.15 Denial of Service via URL Field
- CVE-2019-25548 — BlueStacks 4.80.0.1060 Denial of Service via Search Field
- CVE-2024-33602 — nscd: netgroup cache assumes NSS callback uses in-buffer strings
- CVE-2024-21849 — BIG-IP Websockets vulnerability