CVE-2026-57029 Details
Description
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
A missing synchronization vulnerability has been identified in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series. This vulnerability allows an adjacent, unauthenticated attacker to cause a denial-of-service condition. The issue arises when the reachability of an sFlow collector changes, prompting an update to the corresponding next-hop entry. If this update coincides with the sFlow thread accessing the next-hop data—an aspect outside the attacker's control—it can cause the evo-pfemand process to crash. This disruption impacts all traffic forwarding until the process is automatically restarted. The vulnerability affects all 23.2 versions, 23.4 versions prior to 23.4R2-S7-EVO, 24.2 versions prior to 24.2R2-S5-EVO, 24.4 versions prior to 24.4R2-S3-EVO, and 25.2 versions prior to 25.2R2-EVO.
Users can upgrade to Junos OS Evolved versions 23.4R2-S7-EVO, 24.2R2-S5-EVO, 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, or any subsequent release. Instructions for upgrading can be found on the Juniper Networks Customer Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110089 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-820 | Missing Synchronization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos os evolved | 23.2 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 24.2 - 24.2 r1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.2 r2-s4 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper qfx10008 | All versions |
CPE
Remediation
| |
| juniper qfx10016 | All versions |
CPE
Remediation
| |
| juniper qfx5110 | All versions |
CPE
Remediation
| |
| juniper qfx5120 | All versions |
CPE
Remediation
| |
| juniper qfx5130 | All versions |
CPE
Remediation
| |
| juniper qfx5140 | All versions |
CPE
Remediation
| |
| juniper qfx5200 | All versions |
CPE
Remediation
| |
| juniper qfx5210 | All versions |
CPE
Remediation
| |
| juniper qfx5220 | All versions |
CPE
Remediation
| |
| juniper qfx5230-64cd | All versions |
CPE
Remediation
| |
| juniper qfx5240 | All versions |
CPE
Remediation
| |
| juniper qfx5241 | All versions |
CPE
Remediation
| |
| juniper qfx5250 | All versions |
CPE
Remediation
| |
| juniper qfx5700 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |