CVE-2026-57030 Details
Description
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds: user@host> show security flow session | match timeout Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary': user@host> show security flow session summary | match invalid Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot. This issue affects Junos OS on SRX Series: * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S1, 24.4R2-S2, * 25.2 versions before 25.2R1-S2, 25.2R2. This issue does not affect releases earlier than 24.2R1;
A race condition vulnerability has been identified in the packet forwarding engine of Juniper Networks Junos OS on SRX Series devices. This vulnerability allows an unauthenticated, network-based attacker to cause a denial-of-service condition. The issue arises during stateful traffic processing, where flow sessions are established and removed as needed. When a flow is terminated, its timeout should be set to 3 seconds. However, due to the race condition, the timeout can be incorrectly set to a value exceeding 10,000 seconds. This misconfiguration leads to an accumulation of inactive flow sessions, which cannot be manually cleared, causing network traffic to be disrupted. The problem requires a manual reboot to restore normal operation. The vulnerability affects Junos OS versions 24.2 (prior to 24.2R2-S3), 24.4 (prior to 24.4R2-S1 and 24.4R2-S2), and 25.2 (prior to 25.2R1-S2 and 25.2R2).
Users can upgrade to Junos OS versions 24.2R2-S3, 24.4R2-S1, 25.2R1-S2, 25.2R2, 25.4R1, or any subsequent release to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110090 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 25.2 - 25.2 r1 25.2 r1-s1 |
CPE
Remediation
| |
| juniper srx1500 | All versions |
CPE
Remediation
| |
| juniper srx1600 | All versions |
CPE
Remediation
| |
| juniper srx2300 | All versions |
CPE
Remediation
| |
| juniper srx300 | All versions |
CPE
Remediation
| |
| juniper srx320 | All versions |
CPE
Remediation
| |
| juniper srx340 | All versions |
CPE
Remediation
| |
| juniper srx345 | All versions |
CPE
Remediation
| |
| juniper srx380 | All versions |
CPE
Remediation
| |
| juniper srx400 | All versions |
CPE
Remediation
| |
| juniper srx4100 | All versions |
CPE
Remediation
| |
| juniper srx4120 | All versions |
CPE
Remediation
| |
| juniper srx4200 | All versions |
CPE
Remediation
| |
| juniper srx4300 | All versions |
CPE
Remediation
| |
| juniper srx440 | All versions |
CPE
Remediation
| |
| juniper srx4600 | All versions |
CPE
Remediation
| |
| juniper srx4700 | All versions |
CPE
Remediation
| |
| juniper srx5400 | All versions |
CPE
Remediation
| |
| juniper srx5600 | All versions |
CPE
Remediation
| |
| juniper srx5800 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |