#VU121661 Time-of-check Time-of-use (TOCTOU) Race Condition in Juniper Junos OS - CVE-2026-21912

 

#VU121661 Time-of-check Time-of-use (TOCTOU) Race Condition in Juniper Junos OS - CVE-2026-21912

Published: January 19, 2026


Vulnerability identifier: #VU121661
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-21912
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Juniper Junos OS
Software vendor:
Juniper Networks, Inc.

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged user executing the "show system firmware" CLI command to cause an LC480 or LC2101 line card to reset.

On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart.


Remediation

Install updates from vendor's website.

External links