Out-of-bounds write in Junos OS and Junos OS Evolved - CVE-2026-33799
Published: July 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the SNMP daemon (snmpd) when processing specific valid SNMPv3 queries. A remote attacker can send specific valid SNMPv3 queries to cause a denial of service.
SNMPv3 must be configured for exploitation. Continuous receipt of the queries can exhaust snmpd process memory, leading to a crash and restart and impacting SNMP-based monitoring.
Affected software
Junos OS Evolved
How to mitigate CVE-2026-33799
Junos OS Evolved - addressed in versions 21.2R3-S8-EVO, 21.4R3-S7-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 23.2R2-EVO, 23.4R2-EVO, 24.2R1-EVO