CVE-2026-33775 Details
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If the authentication packet-type option is configured and a received packet does not match that packet type, the memory leak occurs. When all memory available to bbe-smgd has been consumed, no new subscribers will be able to login. The memory utilization of bbe-smgd can be monitored with the following show command: user@host> show system processes extensive | match bbe-smgd The below log message can be observed when this limit has been reached: bbesmgd[<PID>]: %DAEMON-3-SMD_DPROF_RSMON_ERROR: Resource unavailability, Reason: Daemon Heap Memory exhaustion This issue affects Junos OS on MX Series: * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S5, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R2, * 25.2 versions before 25.2R2.
A memory leak vulnerability has been identified in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series. This vulnerability allows an adjacent, unauthenticated attacker to cause a denial-of-service condition. The issue arises when the authentication packet-type option is configured, and a received packet does not match the expected type, leading to a memory leak. Once the daemon's memory is exhausted, new subscribers cannot log in. This vulnerability affects all versions of Junos OS on MX Series prior to 22.4R3-S8, as well as specific versions in the 23.x and 24.x series.
Users can upgrade to Junos OS versions 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R2, or 25.4R1. For guidance on which releases vulnerabilities are fixed, refer to Juniper's KB16765.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107821 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 22.4 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper mx10004 | All versions |
CPE
Remediation
| |
| juniper mx10008 | All versions |
CPE
Remediation
| |
| juniper mx2008 | All versions |
CPE
Remediation
| |
| juniper mx2010 | All versions |
CPE
Remediation
| |
| juniper mx2020 | All versions |
CPE
Remediation
| |
| juniper mx204 | All versions |
CPE
Remediation
| |
| juniper mx240 | All versions |
CPE
Remediation
| |
| juniper mx301 | All versions |
CPE
Remediation
| |
| juniper mx304 | All versions |
CPE
Remediation
| |
| juniper mx480 | All versions |
CPE
Remediation
| |
| juniper mx960 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |