#VU121664 Double free in Juniper Junos OS - CVE-2026-21918
Published: January 19, 2026
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to double free error in the flow processing daemon (flowd). A remote non-authenticated attacker can cause a Denial-of-Service (DoS).
On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of packets is encountered a double free happens.
This causes flowd to crash and the respective FPC to restart.