CVE-2026-33780
published 2026-04-09CVE-2026-33780: A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS…
high7.1CVSS 4.0
AVAACLATNPRNUINVCNVINVAHSCNSINSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUYRXVXREMUX
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultimately leading to a Denial of Service (DoS).
In an EVPN-MPLS scenario, routes learned from remote multi-homed Provider Edge (PE) devices are programmed as ESI routes. Due to a logic issue in the l2ald memory management, memory allocated for these routes is not released when there is churn for these routes. As a result, memory leaks in the l2ald process which will ultimately lead to a crash and restart of l2ald.
Use the following command to monitor the memory consumption by l2ald:
user@device> show system process extensive | match "PID|l2ald"
This issue affects:
Junos OS:
* all versions before 22.4R3-S5,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2-S4,
* 24.2 versions before 24.2R2;
Junos OS Evolved:
* all versions before 22.4R3-S5-EVO,
* 23.2 versions before 23.2R2-S3-EVO,
* 23.4 versions before 23.4R2-S4-EVO,
* 24.2 versions before 24.2R2-EVO.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os | — | — |
| juniper_networks | junos_os | < 22.4R3-S5 | 22.4R3-S5 |
| juniper_networks | junos_os | >= 23.2 < 23.2R2-S3 | 23.2R2-S3 |
| juniper_networks | junos_os | >= 23.4 < 23.4R2-S4 | 23.4R2-S4 |
| juniper_networks | junos_os | >= 24.2 < 24.2R2 | 24.2R2 |
| juniper_networks | junos_os_evolved | >= 23.2 < 23.2R2-S3-EVO | 23.2R2-S3-EVO |
| juniper_networks | junos_os_evolved | >= 23.4 < 23.4R2-S4-EVO | 23.4R2-S4-EVO |
| juniper_networks | junos_os_evolved | >= 24.2 < 24.2R2-EVO | 24.2R2-EVO |
| juniper_networks | junos_os_evolved | >= all version prior to < 22.4R3-S5-EVO | 22.4R3-S5-EVO |