Vulnerability Description
A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versions, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos Os Evolved | 23.2 |
| Juniper | Qfx10008 | - |
| Juniper | Qfx10016 | - |
| Juniper | Qfx5110 | - |
| Juniper | Qfx5120 | - |
| Juniper | Qfx5130 | - |
| Juniper | Qfx5140 | - |
| Juniper | Qfx5200 | - |
| Juniper | Qfx5210 | - |
| Juniper | Qfx5220 | - |
| Juniper | Qfx5230-64Cd | - |
| Juniper | Qfx5240 | - |
| Juniper | Qfx5241 | - |
| Juniper | Qfx5250 | - |
| Juniper | Qfx5700 | - |
Related Weaknesses (CWE)
References
- https://supportportal.juniper.net/JSA110089Vendor Advisory
FAQ
What is CVE-2026-57029?
CVE-2026-57029 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS)...
How severe is CVE-2026-57029?
CVE-2026-57029 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57029?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos Os Evolved, Juniper Qfx10008, Juniper Qfx10016, Juniper Qfx5110, Juniper Qfx5120.