Medium [CVE-2026-21909] Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos…
This medium-severity Juniper Networks advisory covers CVE-2026-21909 affecting Junos, Junos OS, Junos OS Evolved.
Android app · Google Play
Monitor future Juniper Networks CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak.
Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition.
Memory usage can be monitored through the use of the 'show task memory detail' command. For example:
user@junos> show task memory detail | match ted-infra TED-INFRA-COOKIE 25 1072 28 1184 229
TED-INFRA-COOKIE 31 1360 34 1472 307
This issue affects:
- from 23.2 before 23.2R2,
- from 23.4 before 23.4R1-S2, 23.4R2,
- from 24.1 before 24.1R2;
This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.
Affected products named by the advisory: EX.
- 23.2
- 23.4
- 24.1
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
- 23.2R2
- 23.4R1-S2
- 24.1R2
- 23.2R2-EVO
- 23.4R1-S2-EVO
- 24.1R2-EVO
- 23.2R1
- 23.2R1-EVO
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Mitigation
Upgrade to a fixed release: 23.2R2, 23.4R1-S2, 24.1R2, 23.2R2-EVO, 23.4R1-S2-EVO, 24.1R2-EVO. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.