Description
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices, multicast traffic which is received on one VC member and sent out on another member leads to a memory leak and ultimately an FPC crash and restart.

The leak can be monitored by watching the continuous increase of the buffer values in the output of:

user@host> show chassis fpc
This issue affects Junos OS on EX4100 Series and EX4400:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing release of memory after its effective lifetime in the packet forwarding engine of Junos OS leads to a memory leak. An unauthenticated adjacent attacker can trigger the flaw by sending multicast traffic through a Virtual Chassis configuration that has sFlow enabled. The accumulated leak ultimately causes the Flexible PIC Container to crash and reboot, resulting in a denial‑of‑service condition for the device.

Affected Systems

Juniper Networks Junos OS on EX4100 Series and EX4400 Series appliances. Affected releases include all versions before 23.2R2‑S7, 23.4 editions before 23.4R2‑S7, 24.2 editions before 24.2R2‑S4, and 24.4 editions before 24.4R2.

Risk and Exploitability

The CVSS score of 7.1 places the issue in the moderate‑to‑high severity range, while an EPSS score of < 1% indicates a very low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires only network adjacency and sFlow enabled in a Virtual Chassis; no authenticated access is needed. The attack path involves sending multicast packets that are forwarded between chassis members, provoking the memory leak observable by monitoring buffer values in the 'show chassis fpc' output, which eventually forces a device reboot and disrupts availability.

Generated by OpenCVE AI on July 29, 2026 at 11:51 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S7, 24.2R2-S4, 24.4R2, 25.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a patched release that includes the fix (23.2R2‑S7 or newer, 23.4R2‑S7 or newer, 24.2‑R2‑S4 or newer, 24.4R2 or newer, 25.2R1 or later).
  • Disable sFlow on all affected Virtual Chassis members to prevent the memory leak triggered by multicast traffic.
  • Use 'show chassis fpc' to watch for continuous buffer growth; if growth is detected, reboot or isolate the chassis promptly to prevent a crash.

Generated by OpenCVE AI on July 29, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices, multicast traffic which is received on one VC member and sent out on another member leads to a memory leak and ultimately an FPC crash and restart. The leak can be monitored by watching the continuous increase of the buffer values in the output of: user@host> show chassis fpc This issue affects Junos OS on EX4100 Series and EX4400: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2.
Title Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash
Weaknesses CWE-401
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:33:33.977Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57027

cve-icon Vulnrichment

Updated: 2026-07-10T14:33:30.185Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime