NULL pointer dereference in Junos OS - CVE-2025-60007

 

NULL pointer dereference in Junos OS - CVE-2025-60007

Published: January 20, 2026


Vulnerability identifier: #VU121684
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-60007
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to null pointer dereference error in the chassis daemon (chassisd). A local user can cause a Denial-of-Service (DoS).

When a user executes the 'show chassis' command with specifically crafted options, chassisd will crash and restart.

Due to this all components but the Routing Engine (RE) in the chassis are reinitialized, which leads to a complete service outage, which the system automatically recovers from.


Affected software

Junos OS

How to mitigate CVE-2025-60007

Install updates from vendor's website.

Junos OS - addressed in versions 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1

External References

Related Security Bulletins