Time-of-check Time-of-use (TOCTOU) Race Condition in Junos OS - CVE-2026-21912

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Junos OS - CVE-2026-21912

Published: January 19, 2026


Vulnerability identifier: #VU121661
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21912
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged user executing the "show system firmware" CLI command to cause an LC480 or LC2101 line card to reset.

On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart.


Affected software

Junos OS

How to mitigate CVE-2026-21912

Install updates from vendor's website.

Junos OS - addressed in versions 21.2R3-S10, 21.4R3-S9, 22.2R3-S7, 22.4R3-S6, 23.2R2-S2, 23.4R2-S3, 24.2R2, 24.4R1

External References

Related Security Bulletins