SB2026011989 - Double free in Juniper Junos OS
Published: January 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free (CVE-ID: CVE-2026-21918)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to double free error in the flow processing daemon (flowd). A remote non-authenticated attacker can cause a Denial-of-Service (DoS).
On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens.
This causes flowd to crash and the respective FPC to restart.
Remediation
Install update from vendor's website.