Junglewise Threat Intelligence

CVE-2026-57027: Juniper Networks Junos OS memory leak in packet forwarding engine

CVE-2026-57027 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS affects specific EX Series network switches used in corporate environments. When these switches are configured in a 'Virtual Chassis' setup with sFlow monitoring enabled, certain types of network traffic can cause the device to run out of memory. This leads to a system crash and restart, potentially causing network outages and disrupting business operations.

Technical details

A 'Missing Release of Memory after Effective Lifetime' (CWE-401) vulnerability exists in the packet forwarding engine (pfe) of Juniper Networks Junos OS. The issue is triggered on EX4100 and EX4400 Series devices configured in a Virtual Chassis (VC) scenario with sFlow enabled. Specifically, multicast traffic received on one VC member and egressing through another member causes a memory leak. An unauthenticated adjacent attacker can exploit this to exhaust system memory, leading to a Flexible PIC Concentrator (FPC) crash and restart. The leak can be monitored via the 'show chassis fpc' command. Patches have been released in versions 23.2R2-S7, 23.4R2-S7, 24.2R2-S4, and 24.4R2.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2

Timeline

  • 2026-07-09: advisory: Initial publication of the advisory

References