CVE-2026-33775: Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bbe-smgd
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
If the authentication packet-type option is configured and a received packet does not match that packet type, the memory leak occurs. When all memory
available to bbe-smgd has been consumed, no new subscribers will be able to login.
The memory utilization of bbe-smgd can be monitored with the following show command:
user@host> show system processes extensive | match bbe-smgd
The below log message can be observed when this limit has been reached:
bbesmgd[<PID>]: %DAEMON-3-SMDDPROFRSMONERROR: Resource unavailability, Reason: Daemon Heap Memory exhaustion
This issue affects Junos OS on MX Series: all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S5, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R2, 25.2 versions before 25.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33775?
CVE-2026-33775 has been classified as a medium severity vulnerability affecting Junos OS on MX Series.
How do I fix CVE-2026-33775?
To mitigate CVE-2026-33775, upgrade your Junos OS to the latest patched version as advised by Juniper Networks.
What issues does CVE-2026-33775 cause?
CVE-2026-33775 can lead to a memory leak in the BroadBand Edge subscriber management daemon, potentially degrading system performance.
Which versions of Junos OS are affected by CVE-2026-33775?
CVE-2026-33775 affects various versions of Junos OS including 22.4R3-S8 and specific ranges up to 25.2.
Is CVE-2026-33775 exploitable by remote attackers?
Yes, CVE-2026-33775 is exploitable by adjacent, unauthenticated attackers who can exploit the mismatch between configured and received packet types.