CVE-2025-52986 Details
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a user executes one of several routing related 'show' commands, a certain amount of memory is leaked. When all available memory has been consumed rpd will crash and restart. The leak can be monitored with the CLI command: show task memory detail | match task_shard_mgmt_cookie where the allocated memory in bytes can be seen to continuously increase with each exploitation. This issue affects: Junos OS: * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S11, * 22.2 versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.2R3-S7-EVO * 22.4-EVO versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S4-EVO, * 24.2-EVO versions before 24.2R2-EVO, * 24.4-EVO versions before 24.4R2-EVO.
A memory leak vulnerability has been identified in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows a local, low-privileged user to impact the device's availability. The issue arises when RIB sharding is enabled and certain routing-related 'show' commands are executed, leading to a gradual increase in memory usage. Once the available memory is exhausted, rpd crashes and restarts. The memory leak can be monitored using a specific CLI command.
Users can update to Junos OS versions 21.2R3-S9, 21.4R3-S11, 22.2R3-S7, 22.4R3-S7, 23.2R2-S4, 23.4R2-S4, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1, and all subsequent releases. For Junos OS Evolved, users can update to versions 22.2R3-S7-EVO, 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S4-EVO, 24.2R2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA100092 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 21.2 21.2 - 21.2 r1 21.2 r1-s1 21.2 r1-s2 21.2 r2 21.2 r2-s1 21.2 r2-s2 21.2 r3 21.2 r3-s1 21.2 r3-s2 21.2 r3-s3 21.2 r3-s4 21.2 r3-s5 21.2 r3-s6 21.2 r3-s7 21.2 r3-s8 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 21.4 r2-s2 21.4 r3 21.4 r3-s1 21.4 r3-s10 21.4 r3-s2 21.4 r3-s3 21.4 r3-s4 21.4 r3-s5 21.4 r3-s6 21.4 r3-s7 21.4 r3-s8 21.4 r3-s9 22.2 - 22.2 r1 22.2 r1-s1 22.2 r1-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.2 r3-s1 22.2 r3-s2 22.2 r3-s3 22.2 r3-s4 22.2 r3-s5 22.2 r3-s6 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.4 - 24.4 r1 24.4 r2 |
CPE
Remediation
| |
| juniper junos os evolved | < 22.2 22.2 - 22.2 r1 22.2 r1-s1 22.2 r1-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.2 r3-s1 22.2 r3-s2 22.2 r3-s3 22.2 r3-s4 22.2 r3-s5 22.2 r3-s6 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 24.2 - 24.2 r1 24.2 r1-s2 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | Reanalysis | [email protected] |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jul 11, 2025 | New CVE Received | [email protected] |