Executive brief
A vulnerability in Juniper Networks Junos OS affects specific EX Series network switches used in corporate environments. When these switches are configured in a 'Virtual Chassis' setup with sFlow monitoring enabled, certain types of network traffic can cause the device to run out of memory. This leads to a system crash and restart, potentially causing network outages and disrupting business operations.
Technical details
A 'Missing Release of Memory after Effective Lifetime' (CWE-401) vulnerability exists in the packet forwarding engine (pfe) of Juniper Networks Junos OS. The issue is triggered on EX4100 and EX4400 Series devices configured in a Virtual Chassis (VC) scenario with sFlow enabled. Specifically, multicast traffic received on one VC member and egressing through another member causes a memory leak. An unauthenticated adjacent attacker can exploit this to exhaust system memory, leading to a Flexible PIC Concentrator (FPC) crash and restart. The leak can be monitored via the 'show chassis fpc' command. Patches have been released in versions 23.2R2-S7, 23.4R2-S7, 24.2R2-S4, and 24.4R2.
Affected products
- Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2
Timeline
- 2026-07-09: advisory: Initial publication of the advisory