Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved Software

Alert Description

Junos Software Service Release version 22.2R3-S7-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review.

Solution

Junos Software service Release version 22.2R3-S7-EVO is now available.

22.2R3-S7-EVO - List of Fixed issues 

PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=evo
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1826685
Minor
Unexpected behaviour after BGP sessions reset for catastrophic BGP configuration changes
Product-Group=evo
Severity=Minor
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).
1848939
Major
The CPU for the rpd stuck at 100% on Junos platforms
Product-Group=evo
Severity=Major
On Junos platforms, where BGP import policy is running on a BGP multipath setup and BMP post-policy exclude-non-eligible knob is configured. In such cases when the route change from usable to non-usable state and vice-versa, the route is moved to the end of the peer gateway route list for BMP to process it latter. At the same time, BGP stop_rt cursor (used by BGP import policy) is moved to the end of the peer gateway route list. With some network churn and on-going multipath evaluations, the stop_rt cursor keeps moving to the end of the list for ever. This causes BGP import policy to never converge and CPU remains high for a long time.
1864676
Major
The rpd process will crash due to memory leak
Product-Group=evo
Severity=Major
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".
PR NumberSynopsisCategory: BGP BMP Software
1843374
Major
The BMP rib-in-post route withdraw feed is not being generated towards the BMP station when an import policy is configured
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, the BMP rib-in-post route withdraw feed is not being generated towards the BMP station when an import policy is configured.
PR NumberSynopsisCategory: PFE COS features on BT based platforms
1879439
Minor
Rare evo-cda-bt crash in PTX10008 Junos OS Evolved with multiple FPCs when one FPC fails
Product-Group=evo
Severity=Minor
On all Junos Evolved PTX10008 platforms, the failure of one FPC (Flexible PIC Concentrator) can cause a rare evo-cda-bt crash on another FPC, resulting in a reboot.
PR NumberSynopsisCategory: QFX Access Control related
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=evo
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1820712
Minor
Traffic loss is observed after configuration addition or baseline configuration override with static VXLAN or EVPN-VXLAN configuration
Product-Group=evo
Severity=Minor
On all QFX/EX/PTX /ACX platforms, when the configuration addition or baseline configuration override happens with static VXLAN (Virtual Extensible Local Area Network) or EVPN-VXLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) configuration, forwarding traffic is impacted as the next-hop is not resolved in correct order of configuration events.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1841071
Major
Incorrect routing seen for VRF traffic after changing packet-forwarding options from hw-db-profile to balanced-exem
Product-Group=evo
Severity=Major
On all ACX Evolved platforms the packet-forwarding options hw-db-profiles "balanced-exem" and "l3-xl" causes routing issues for traffic coming in a VRF (Virtual routing and forwarding) and forwarded using the default route leading to traffic impact.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1859501
Minor
Interfaces with the same outer VLAN ID but different inner vlans or inner-lists/ranges are reporting a commit error
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms, When an interface configured with the same outer VLAN ID but with different inner vlans or inner-lists/ranges, reports a commit error.
1867231
Major
Transit multicast traffic is getting blackhole due to peer interface flap
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when peer interface flaps which connected to AE (Aggregated Ethernet) interface leading to synchronization of the interface up events with PFE (Packet Forwarding Engine) gets delayed. This issue results in the transit multicast traffic getting blackhole.
1867603
Major
Coredump during LAG disable
Product-Group=evo
Severity=Major
Pre-conditions are: 1. Aggregate Ethernet interface is configured with/without lacp 2. Aggregate Ethernet interface is configured with BFD configs. Trigger is: 3. With the specified configuration, if any config change is issued on AE IFL then it results in aggd core. 4. One such example is [edit interfaces ae2301 unit 0] + disable; There is no work-around, so none is mentined.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1853879
Major
The IRB VGA is not shown after deleting one of the IRB interfaces with the same VGA address configured
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, when two different IP addresses under an IRB interface are configured with the same virtual-gateway-address (VGA), and one of the IP addresses is deleted, the VGA IP address gets cleaned up in the router/switch resulting in traffic loss in the remaining address entry.
PR NumberSynopsisCategory: AAA, auditd issues
1809994
Major
Audit core dump seen when tacplus accounting is configured
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, the auditd process may core when sending Tacplus accounting records over a WAN (Wide Area Network) interface. There is no traffic loss and the process will come back up automatically.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=evo
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: lldp sw on MX platform
1811545
Major
The LLDP neighborship does not recover on AE interfaces
Product-Group=evo
Severity=Major
When LLDP is configured on interface all and there are AE interfaces configured, to disable LLDP on one of the AE "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, AE is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
PR NumberSynopsisCategory: mc-ae interface
1850316
Major
Routing instance knob for ICCP backup liveness detection
Product-Group=evo
Severity=Major
added new config knob "set protocols iccp peer backup-liveness-detection routing-instance ", to configure routing instance name on which "backup-peer-ip" is reachable if it is other than default routing instance, currently it supports only mgmt_junos
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1802447
Major
failed to copy file '//var/etc/if_alias_map+' to 're1' error when user authenticated via tacacs comitting netconf configuration change
Product-Group=evo
Severity=Major
Commit error issue via netconf session
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1861451
Major
BGP PIC failover is taking longer than expected when IS-IS as an IGP enabled with LFA
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, in a BGP-L3VPN (Border Gateway Protocol - Layer 3 Virtual Private Network) setup when configured with BGP PIC (Prefix-Independent Convergence) on an ingress PE's (Provider Edge) VRF (Virtual Routing and Forwarding) routing-instance and having IS-IS (Intermediate System-to-Intermediate System) as an IGP (Interior Gateway Protocol) which if enabled with LFA (Loop Free Alternative), BGP PIC failover is taking loger time than expected due to lag in the route change for the BGP path to be used. This is causing traffic loss until global convergence.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1825447
Major
The SNMP performance degrade is observed while querying interface counters
Product-Group=evo
Severity=Major
On all Junos platforms, SNMP (Simple Network Management Protocol) performance issues will be seen while querying interface counters for more than 1000 interfaces, which results in SNMP timeouts and throttle drops however there is no impact to the traffic.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1829031
Minor
An authentication failure occurs when the TACACS+ server detects an error in sending authentication response
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved products configured with TACACS+(Terminal Access Controller Access Control System Plus) authentication method, authentication seems to fail when TACACS+ server detects an error in sending authentication response to the host device. This impacts authentication and user cannot login into the device.

 


 

22.2R3-S7-EVO - List of Known issues 

PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1824753
Minor
The Junos-Evolved OS does not encode special/multi-byte characters properly in CLI/RPC XML output
Product-Group=evo
In all Junos-Evolved Operating Systems (OS), special characters entered in the description field of the set interfaces command in the Command Line Interface (CLI) may not be correctly encoded in XML outputs. This is a cosmetic issue.

Resolved In: evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:25.1R1
1875917
Major
Disabling a single AE IFL in a MAC-VRF can bring the entire AE interface down
Product-Group=evo
On all Junos Evolved platforms, under MAC-VRF routing configurations, when any Layer 3 IFL is deactivated, it causes the associated AE interface to go administratively down, leading to complete traffic disruption across the AE bundle.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1852152
Major
The l2ald-agent process crashes when the scale of IFBDs within a single VLAN exceeds the capacity of the Rx rtsock buffer, causing an overflow
Product-Group=evo
On all Junos OS Evolved platforms, scaling of IFBDs (Interface Family Bridge Domain) within a single VLAN(Virtual Local Area Network) will result in the formation of rtsock messages that exceed the Rx size of the rtsock buffer (8192 bytes). This will cause the l2ald-agent (Layer 2 Address Learning Daemon) process to crash. There will be no traffic impact.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO evo:23.4X100-D40-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1809091
Minor
ACX7024 sees a vmcore and restarts or potentially hangs on reboot
Product-Group=evo
ACX7024 sees a vmcore and restarts or potentially hangs on reboot

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R1-EVO junos:24.2R2-S2 junos:24.4R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100
Minor
Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.1R1-EVO junos:20.3X75-D46 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.1R1 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1827261
Major
Junos OS: MX Series with MPC10/MPC11/LC9600 line card and MX304: Subscriber login/logout activity will lead to a memory leak (CVE-2025-30647)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/MPC11/LC9600 line card and MX304 allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA96457 [juniper.net] for more information.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R2-S1-J8 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1

 

Modification History

First publication 2025-07-07