Description
An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).


When a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered.

Affected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE).

When this issue happens the following logs can be observed:

fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default
fpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default




This issue affects Junos OS on MX Series:


* all versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation causes the system to incorrectly calculate packet sizes for certain traffic types. When a specific packet is received from another device in the same broadcast domain—such as MAP‑T traffic or non‑IP traffic encapsulated in IP (e.g., MPLS over GRE)—the calculation overflows. The resulting failure in packet processing triggers an FPC major error, causing the FPC to reset and interrupt traffic until the hardware automatically recovers. This creates a denial‑of‑service that affects all traffic handled by the reset FPC. The weakness is classified as CWE‑1284.

Affected Systems

Juniper Networks Junos OS running on MX Series devices with software versions earlier than 23.2R2‑S6, 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S4, and 25.2R2, as well as any releases before those update milestones; the issue is specifically triggered by MAP‑T traffic or non‑IP traffic encapsulated within IP such as MPLS over GRE in the same broadcast domain.

Risk and Exploitability

The vulnerability scores 7.1 on the CVSS scale and has an EPSS score of less than 1%, indicating a low but non‑zero exploitation probability. It is not listed in CISA’s KEV catalog. The flaw requires an unauthenticated attacker adjacent to the device on the same broadcast domain, who can craft packets that trigger the faulty size calculation, causing an FPC reset and an immediate denial‑of‑service that automatically resolves after the hardware recovers.

Generated by OpenCVE AI on July 31, 2026 at 13:19 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S6, 23.4R2-S7, 24.2R2-S4, 24.4R2-S4, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Juniper Networks Junos OS on all affected MX Series devices to at least version 23.2R2‑S6, 23.4R2‑S7, 24.2R2‑S4, 24.4R2‑S4, 25.2R2, 25.4R1, or any later release.
  • Reboot the device after the upgrade to clear any residual error states and ensure the FPC resumes normal operation.
  • While an upgrade is pending, isolate the MX device from untrusted adjacent hosts by configuring VLANs or firewall rules that restrict broadcast‑domain traffic to trusted endpoints.

Generated by OpenCVE AI on July 31, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered. Affected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE). When this issue happens the following logs can be observed: fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default fpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default This issue affects Junos OS on MX Series: * all versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2.
Title Junos OS: MX Series: Specific traffic causes an FPC to reset
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T13:29:55.755Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57019

cve-icon Vulnrichment

Updated: 2026-07-10T13:29:49.623Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T22:17:06.707

Modified: 2026-07-13T20:58:26.287

Link: CVE-2026-57019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:30:17Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input