SB2026011987 - Buffer Over-read in Junos OS Evolved and Juniper Junos OS
Published: January 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer Over-read (CVE-ID: CVE-2025-60003)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer.
Remediation
Install update from vendor's website.