CVE-2026-57029
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M
- EPSS probability
- 0.19%
- CWE
- CWE-820
- Published
- 2026-07-09
- Last modified
- 2026-07-10
Affected products
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
- Juniper Networks Junos OS Evolved
Weakness type
Related vulnerabilities
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2026-22163 — GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
- CVE-2022-50238 — The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online...
- CVE-2025-49751 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47999 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list...
- CVE-2025-1445 — A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the...