CVE-2026-21909 Details
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Memory usage can be monitored through the use of the 'show task memory detail' command. For example: user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229 user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 31 1360 34 1472 307 This issue affects: Junos OS: * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S2, 23.4R2, * from 24.1 before 24.1R2; Junos OS Evolved: * from 23.2 before 23.2R2-EVO, * from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO, * from 24.1 before 24.1R2-EVO. This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.
A memory leak vulnerability has been identified in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send specific update packets that cause a memory leak. As these packets are received and processed, the available memory is exhausted, leading to a crash of the RPD daemon and creating a denial-of-service condition. The issue affects Junos OS versions 23.2 (prior to 23.2R2), 23.4 (prior to 23.4R1-S2, 23.4R2), and 24.1 (prior to 24.1R2), as well as Junos OS Evolved versions 23.2 (prior to 23.2R2-EVO), 23.4 (prior to 23.4R1-S2-EVO, 23.4R2-EVO) and 24.1 (prior to 24.1R2-EVO). The vulnerability does not affect earlier Junos OS or Junos OS Evolved versions.
Users can upgrade to Junos OS versions 23.2R2, 23.4R1-S2, 23.4R2, 24.1R2, 24.2R1, and all subsequent releases. For Junos OS Evolved, users can upgrade to versions 23.2R2-EVO, 23.4R1-S2-EVO, 23.4R2-EVO, 24.1R2-EVO, 24.2R1-EVO, and all subsequent releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA106008 | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/JSA106008 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.4 - 23.4 r1 23.4 r1-s1 23.4 r2 24.1 - 24.1 r1 |
CPE
Remediation
| |
| juniper junos os evolved | 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.4 - 23.4 r1 23.4 r1-s1 23.4 r2 24.1 - 24.1 r1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 15, 2026 | New CVE Received | [email protected] |