SB2026011987 - Buffer Over-read in Junos OS Evolved and Juniper Junos OS



SB2026011987 - Buffer Over-read in Junos OS Evolved and Juniper Junos OS

Published: January 19, 2026

Security Bulletin ID SB2026011987
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer Over-read (CVE-ID: CVE-2025-60003)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device receives a BGP update with a set of specific optional transitive attributes over an established peering session, rpd will crash and restart when attempting to advertise the received information to another peer.


Remediation

Install update from vendor's website.