SB2026011986 - Local denial of service in Junos OS MX10k Series



SB2026011986 - Local denial of service in Junos OS MX10k Series

Published: January 19, 2026

Security Bulletin ID SB2026011986
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-21912)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged user executing the "show system firmware" CLI command to cause an LC480 or LC2101 line card to reset.

On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart.


Remediation

Install update from vendor's website.