Database/Firmware, BMC & network fabric
Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPC
Impact
An attacker on an adjacent link that can keep micro-BFD sessions flapping enqueues up/down events faster than PFEMAN can drain them; the PFEMAN watchdog eventually expires and the FPC crashes and restarts. That is a full forwarding outage for every port on the line card, not a degraded path. Juniper notes the processing cost is worst in a Virtual-Chassis with locality-bias configured. On a fleet where an MX sits on the storage or WAN edge of the GPU pods, an FPC restart drops the traffic of everything homed behind it for the duration of the reload, and a flapping neighbour can repeat it.
Who can reach it
Unauthenticated attacker adjacent at layer 2 on a link running micro-BFD to the device - no credentials, just the ability to make those sessions flap repeatedly.
What to do
Upgrade Junos OS on MX to 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3 or 25.2R2 per JSA110075; that is a chassis software upgrade with a reboot, so it needs a maintenance window per device. Only MX FPCs up to and including MPC9, plus LC2101/2103 and LC480, are affected - MPC10/11, LC4800/9600 and MX304 are not, so inventory line cards before scheduling. Juniper's advisory does not describe a configuration-only workaround.
References
Related entries
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightCVE-2026-45856 · Linux kernel InfiniBand core (ib_uverbs post_send)High
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenCVE-2026-53187 · Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation)High
- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userCVE-2026-56088 · Dell OpenManage Enterprise (web console, SQL injection)High
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theCVE-2026-68425 · Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad)High
- HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9CVE-2019-11983 · HPE iLO 4 / iLO 5 (remote buffer overflow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.