Description
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).


When a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered.

Affected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE).

When this issue happens the following logs can be observed:

fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default
fpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default




This issue affects Junos OS on MX Series:


* all versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation causes the system to incorrectly calculate packet sizes for certain traffic types. When a specific packet is received from another device in the same broadcast domain—such as MAP‑T traffic or non‑IP traffic encapsulated in IP (e.g., MPLS over GRE)—the calculation overflow. The reset interrupts all traffic until the hardware automatically recovers, effectively creating a denial‑of‑service that is limited to the affected interfaces. This weakness is classified as CWE‑1284.

Affected Systems

Juniper Networks Junos OS running on MX Series devices with software versions earlier than 23.2R2‑S6, 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S4, and 25.2R2, as well as any releases before those update milestones; the issue is specifically triggered by MAP‑T traffic or non‑IP traffic encapsulated within IP such as MPLS over GRE in the same broadcast domain.

Risk and Exploitability

The vulnerability scores 7.1 on the CVSS scale and has an EPSS score of less than 1%, indicating a low but non‑zero exploitation probability. It is not listed in CISA’s KEV catalog. The flaw requires an unauthenticated attacker adjacent to the device on the same broadcast domain, who can craft packets that trigger the faulty size calculation, causing an FPC reset and an immediate denial‑of‑service that automatically resolves after the hardware recovers.

Generated by OpenCVE AI on July 26, 2026 at 14:43 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S6, 23.4R2-S7, 24.2R2-S4, 24.4R2-S4, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS on all affected MX Series devices to at least version 23.2R2‑S6, 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S4, 25.2R2, 25.4R1, or any later release.
  • After the upgrade, validate that the FPC no longer resets by monitoring the device logs for the CMError 0x2205eb entries related to MQSS unroll tail length overflow.
  • While an upgrade is pending, isolate the MX device from untrusted adjacent hosts by configuring VLANs or firewall rules that restrict broadcast‑domain traffic to trusted endpoints.

Generated by OpenCVE AI on July 26, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered. Affected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE). When this issue happens the following logs can be observed: fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default fpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default This issue affects Junos OS on MX Series: * all versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2.
Title Junos OS: MX Series: Specific traffic causes an FPC to reset
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T13:29:55.755Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57019

cve-icon Vulnrichment

Updated: 2026-07-10T13:29:49.623Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T14:45:07Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input