CVE-2025-52986
Severity
6.8MEDIUM
EPSS
0.0%
top 92.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Description
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device.
When RIB sharding is enabled and a user executes one of several routing related 'show' commands, a certain amount of memory is leaked. When all available memory has been consumed rpd will crash and restart.
The leak can be monitored with the CLI command:…
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Affected Packages4 packages
🔴Vulnerability Details
2CVEList▶
Junos OS and Junos OS Evolved: When RIB sharding is configured each time a show command is executed RPD memory leaks↗2025-07-11
GHSA▶
GHSA-mfrf-wpm5-gv78: A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evol↗2025-07-11
📋Vendor Advisories
1Juniper▶
CVE-2025-52986: A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evol↗2025-07-11