Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX QFX platforms running Junos software

Alert Description

Junos Software Service Release version 23.4R2-S5 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

NOTE: Do not upgrade to JUNOS version 23.4R2-S5 if you are using the following optic modules

  • JNP-SFP-25G-SR 740-068639
  • JNP-SFP-25G-LR 740-0715262
  • SFP-25G-SR-IT 740-106769
  • SFP-25G-LR-IT 740-106770

An interface using these optic modules will stay down after upgrade.

Solution

Junos Software service Release version 23.4R2-S5 is now available.

23.4R2-S5 - List of Fixed issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1848764
Minor
IGMP snooping stops working after reboot
Product-Group=junos
Severity=Minor
On Junos EX2300 platform, IGMP(Internet Group Management Protocol) snooping stops working after a device reboot as IGMP is not programmed properly in hardware.
1862037
Major
QinQ configuration changes on one port cause traffic loss on another port with same number on EX platforms
Product-Group=junos
Severity=Major
On EX2300/EX4000 platforms with QinQ (802.1ad) or VLAN stacking configured on multiple interfaces, modifying or deleting the QinQ configuration from an interface on one PFE (Packet Forwarding Engine) may cause another interface with the same port number on a different PFE to stop forwarding traffic.
PR NumberSynopsisCategory: EX2300/3400 platform
1839618
Major
Continuous increment of tcpAttemptFails counter on Junos EX2300 and 3400
Product-Group=junos
Severity=Major
On Junos EX2300 and EX3400 platforms running on release 21.4 and above, the tcpAttemptFails counter is observed to increment continuously.
PR NumberSynopsisCategory: Junos Node Unifier
1848754
Major
Junos OS: A low-privileged user can disable an interface (CVE-2025-52963)
Product-Group=junos
Severity=Major
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Please refer to https://supportportal.juniper.net/JSA100078 [juniper.net] for more information.
PR NumberSynopsisCategory: "agentd" software daemon
1779722
Minor
The interface fails to come up after FPC reboot if the streaming server and export profile are not configured correctly
Product-Group=junos
Severity=Minor
On all Junos and Junos evolved platforms with telemetry enabled, if the streaming server and export profile for reporting-rate are not properly configured in the analytics settings, rebooting the FPC would prevent any of the interfaces from coming up.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1855477
Critical
Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset (CVE-2025-52953)
Product-Group=junos
Severity=Critical
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100059 [juniper.net] for more information.
1863551
Major
BGP route advertisement failure with as-override and peer-as configured at group level
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, BGP ( Border Gateway Protocol ) fails to advertise routes to external peers in an L3VPN ( Layer 3 Virtual Private Network ) environment when as-override is configured for a neighbor on the local device, and peer-as is applied at the group level. Since the routes are not advertised to peers, traffic matching those routes are dropped, causing service disruption.
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
Severity=Major
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".
1865114
Major
Valid BGP routes in RIB are displayed with verification state as Invalid
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, with resource public key infrastructure(RPKI ) enabled for the BGP, the valid routes are installed in the routing table with validation state invalid.However, the route is parsed by policy as a valid route.
1875144
Minor
Longer convergence is seen for a BGP neighbor having validation configured in its import policy
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platform, when any BGP peer has validation policy configured for import, it is observed that there is an extra walk to re-evaluate the routes in the loc-rib for validation even though the policy/unrelated configuration is changed for an unrelated peer.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
PR NumberSynopsisCategory: BGP BMP Software
1839288
Major
BMP soft assert due to counter reset by clear command
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when "clear bgp statistics" command is issued while one or more BMP peers are coming up the soft_assert will be hit. This issue has no impact on the traffic or services.
PR NumberSynopsisCategory: QFX Access Control related
1851299
Minor
EX3400 Dot1x Radius accounting send incorrect value to the server for Acct-Input-Gigawords/ Acct-Output-Gigawords
Product-Group=junos
Severity=Minor
With Dot1x Radius Authentication and Accounting, when the Stop Accounting (due to disconnect) is sent to the Radius server the Acct-Input-Gigawords and the Acct-Output-Gigawords contains unexpectedly large value.
1872280
Major
The l2ald process crash is observed on non L2NG Junos platforms configured with "native-vlan-id" and "bridge-domains" on an IFL
Product-Group=junos
Severity=Major
On non L2NG (Layer2 Next Generation) Junos EX, MX and SRX platforms, the l2ald (Layer 2 Address Learning Daemon) process crash is observed when an IFL (Logical Interface) configured with "native-vlan-id" and "bridge-domains" and when certain config change takes place in an IFL which maps VLAN (Virtual Local Area Network) index to NULL. The dereferencing of this NULL pointer causes the crash.
PR NumberSynopsisCategory: Device Configuration Daemon
1848768
Major
MTU configuration is not applied from the configuration group after commit and "warning" is seen
Product-Group=junos
Severity=Major
When configuring MTU on interfaces through a configuration-group and commit the changes, those are not saved on the configuration file.
PR NumberSynopsisCategory: Firewall Filter
1844796
Major
Junos OS: IPv6 firewall filter fails to match payload-protocol (CVE-2025-52951)
Product-Group=junos
Severity=Major
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to effectively bypass any firewall filtering configured on the interface. Please refer to https://supportportal.juniper.net/JSA100055 [juniper.net] for more information.
1872347
Major
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Major
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1853294
Major
Packet loss observed across multiple traffic items using SR profiles within the L3VPN
Product-Group=junos
Severity=Major
On ACX5448 and ACX710 platforms under L3VPN (Layer 3 Virtual Private Network) deployment using OSPF (Open Shortest Path First) or BGP (Border Gateway Protocol), when traffic is forwarded over SR (Segment Routing) profiles, packet loss is observed across multiple traffic items.
PR NumberSynopsisCategory: AAA, auditd issues
1862203
Minor
Radius authentication is failing when Challenge Token is entered
Product-Group=junos
Severity=Minor
On all Junos and Evo platforms, the Radius Multi-Factor Authentication (MFA) failing for user login if the password and token were provided in two separate steps.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1864996
Major
Device sends route advertisements on a deleted interface
Product-Group=junos
Severity=Major
On the QFX5230-64CD platform running Junos Evolved 23.4X100-D30-EVO or later, disabling RA (router-advertisement) on an interface does not prevent the device from continuing to send RA messages. Furthermore, the interface status still indicates that RA is active despite the configuration change.
PR NumberSynopsisCategory: EVPN control plane issues
1846096
Critical
RPD restart immediately on EVPN Designated Forwarder PE with Graceful-restart results in 100% traffic loss for 12-15 secs
Product-Group=junos
Severity=Critical
With a EVPN PE running 24.2, 24.4 releases with Graceful restart enabled, if RPD is restarted or flaps, traffic loss for 15s could be seen to Multihomed CEs
1863170
Major
Junos OS and Junos OS Evolved: In an EVPN environment, receipt of a specifically malformed BGP update causes RPD crash (CVE-2025-52949)
Product-Group=junos
Severity=Major
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100053 [juniper.net] for more information.
1870365
Major
'TLV type 00000052 not supported on IFL gr' seen repeatedly in syslog for EVPN routing-instance configured with gr- ifls
Product-Group=junos
Severity=Major
JUNOS/EVO platforms running 23.4R2 and later software, if they have EVPN routing-instances with gr- ifls as members, continuous 'TLV not supported' messages could be seen in syslog.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1833660
Major
Stale MAC entries may remain in the MAC table of EVPN routing instances after rapid MAC-IP move scenarios
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with EVPN-MPLS (Ethernet Virtual Private Network - Multiprotocol Label Switching) setup , stale MAC entries may remain in the MAC table of the EVPN (Ethernet Virtual Private Network) routing instances during rapid MAC-IP move scenarios. This can cause MAC tables to reach their limits preventing new MAC addresses learning and user registration.
PR NumberSynopsisCategory: EX interfaces issues
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
1841117
Major
TDR test can cause a CPU hog and result in BFD flaps
Product-Group=junos
Severity=Major
On the EX4100-F-12P, EX4100-F-12T, EX4100-24MP, EX4400-24MP, and EX4400-48MP platforms, running a TDR (Time-Domain Reflectometry) test specifically on mge interface, can cause a CPU (Central Processing Unit) hog and result in BFD (Bidirectional Forwarding Detection) flaps.
1843585
Major
Traffic blockage observed with SFP-100BASE-BX10 optics in EX4400-48F
Product-Group=junos
Severity=Major
On Junos EX4400-48F platform, specific to the EX4400-48F (ports 0-35) SKU, not applicable to any other SKU (Stock Keeping Unit) , where SFP-100BASE-BX10 optics are used between two EX4400-48F ports, traffic blockage occurs. The link comes up, but no traffic (e.g., ping) passes through.
1844709
Major
EX4100 looses connectivity with the directly connected management port of QFX5120-48Y series platform
Product-Group=junos
Severity=Major
Unable to ping Management IP of QFX5120 directly connected to EX4100 (PIC2) after Power-Cycle or reboot the QFX5210 switch via CLI command : "request system reboot hypervisor"
1877524
Minor
Inserting any unsupported optics in 4x25G ULM will cause any port on the ULM to go down
Product-Group=junos
Severity=Minor
On 4x25G ULM(uplink module) any port can go down, when inserting unsupported Juniper or Non-Juniper optics in this ULM.
PR NumberSynopsisCategory: EX4400 PFE software
1817034
Major
For Junos OS platforms, the OSPF neighborship gets stuck in EXSTART state after performing NSSU
Product-Group=junos
Severity=Major
For Junos OS platforms, in a specific configuration change after NSSU (Nonstop Software Upgrade), i.e. delete and add sequence of LAG (Link Aggregation Group) bundles performed via load baseline configuration and re-apply original configuration, OSPF (Open Shortest Path First) session might get stuck in EXSTART state. This issue will impact the traffic.
1864371
Minor
STP/MSTP/RSTP/VSTP convergence issue due to BPDU drop by l2cpd
Product-Group=junos
Severity=Minor
On Junos EX4K and QFX5K platforms, STP (Spanning Tree Protocol)/MSTP (Multiple Spanning Tree Protocol) /RSTP (Rapid Multiple Spanning Tree Protocol) /VSTP (Vlan Spanning Tree Protocol) convergence issues were observed due to BPDUs (Bridge Protocol Data Units) being dropped by the l2cpd (Layer 2 Control Protocol Daemon) process. This behavior prevents STP/MSTP/RSTP/VSTP from converging successfully, impacting network stability.
1867562
Major
Default Route configured with Discard Next Hop on PFE instead of ECMP Next Hop after reboot
Product-Group=junos
Severity=Major
On all Junos EX4K (except EX4300) in a VC (Virtual Chassis) environment using LPM (Longest Prefix Match) routing, after a reboot the default route on the PFE (Packet Forwarding Engine) is incorrectly set to a "discard next-hop (NH)" instead of an ECMP (Equal-Cost Multi-Path) next-hop resulting in connectivity issues.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1847849
Major
Inter-VNI traffic drop is seen after link flap with Mscale config
Product-Group=junos
Severity=Major
On all QFX5K and EX4K platforms, link flap with Mscale configuration might result in Inter-VNI (VXLAN Network Identifier) traffic drop. The issue is seen when EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) is configured along with VPLAG (Virtual Port - Link Aggregation Group).
1859778
Minor
Traffic drops observed in EVPN-VXLAN using ARP NDP entries
Product-Group=junos
Severity=Minor
On all Junos QFX and EX platforms with EVPN-VXLAN(Ethernet VPN-Virtual Extensible LAN) using ARP(Address Resolution Protocol) NDP(Neighbour Discovery Protocol) entries, the issue is seen when the VRF (Virtual Routing and Forwarding) is renamed, on renaming multiple VRFs a large chunk of routes are reinstalled on PFE (Packet Forwarding Engine). When PFE receives an ARPND route install with a NH ID(Next-hop identifier) that was previously in-use but with new params(dmac(Destination MAC address), gport(Generic Port), vplag id(Virtual Port link Aggregation Group ID), intf(Interface)). DCPFE incorrectly assumes it is a replace and updates the existing route programmed in hardware. This results in hardware having incorrectly programmed routes resulting in packets sent to incorrect destinations. This will happen only when same hw-nh-idx/route is shared between multiple NHs and one NH receives an update.
PR NumberSynopsisCategory: EX POE
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
Severity=Major
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
Severity=Major
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms when IPv6 filter is configured that has a match condition of source/ destination address greater than 64 bits, it results in packet drops due to transient hardware parity error that occurs on the prefix table. This will only reject what is permitted, does not allow unpermitted packets unless default term is accept and is a rare issue.
PR NumberSynopsisCategory: Signature Database
1822319
Minor
Not able to update IDP signature DB when using Proxy server
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, the IDP signature download issue is seen with squid proxy server of a specific version like 6.6 is installed.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1846294
Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
Product-Group=junos
Severity=Major
Memory Leak: Memory leak is detected with rpd task blocks "rpd-trace"
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
PR NumberSynopsisCategory: IoT data filtering/streaming
1830246
Major
The PFE crash is observed on SRX platforms on dynamic-filter configuration
Product-Group=junos
Severity=Major
On SRX platforms when the dynamic filter is configured, the packet forwarding engine (PFE) crashes, impacting traffic.
PR NumberSynopsisCategory: ISIS routing protocol
PR NumberSynopsisCategory: jdhcpd daemon
1808289
Minor
Switch provisioned via ZTP going unreachable due to DHCP misbehaviour on upgrading to 21.4R3-S6
Product-Group=junos
Severity=Minor
All IRB (Integrated Bridging and Routing) interfaces of EX3400-48P switches which pull initial configuration from Dynamic Host Configuration Protocol (DHCP) server via zero touch provisioning (ZTP) process, upon upgrade to 21.4R3-S6 do not send DHCPdiscover packet to obtain a new IP address after sending DHCPrelease packet resulting in interface not able to obtain IP address until rebooted.
1843596
Minor
DHCPv6 Renew from a dual-stack CPE may be ignored if DHCP server is using DUID type 3 (DUID-LL) and DHCPv6 binding doesn't exist
Product-Group=junos
Severity=Minor
DHCPv6 Renew packets from dual-stack CPE could be silently ignored by MX configured as DHCPv6 local server if such DHCPv6 binding doesn't exist.
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
Severity=Major
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1817417
Minor
Commit error is observed on Junos platforms with MS-MPC or SPC3 when last octet of source-ip of jflow-log collector is above 223
Product-Group=junos
Severity=Minor
Configuration is not committed and shows commit error on Junos platforms with MS-MPC or SPC3 when last octet of source-ip of jflow-log collector is higher than 223.
PR NumberSynopsisCategory: Flow Module
1807505
Major
On SRX5000 series and SRX4600, the setting "apply-to-half-close-state" for TCP sessions is not taking effect.
Product-Group=junos
Severity=Major
On SRX5000 series and SRX4600, the setting "set security flow tcp-session time-wait-state apply-to-half-close-state" is not taking effect for sessions that are using express path (services-offload). This may lead to an increased number of sessions compared to earlier Junos releases which did not have an express path enabled by default.
1849530
Major
Failover took longer than expected to recover when service offload was enabled
Product-Group=junos
Severity=Major
On the Junos SRX 4600 chassis cluster, when a RG(redundancy group) failover occurred to the backup node, the recovery process had taken longer than the normal duration.
1859163
Minor
Security forwarding process crash may occur when multicast traffic triggers a route resolution request that needs to be processed for a pending session
Product-Group=junos
Severity=Minor
When multicast traffic triggers a route resolution request for a pending session, and the route is subsequently resolved, a race condition may occur if that pending session is terminated by a different thread before processing can continue. This can result in a crash of the flowd (security forwarding process). However, the control plane remains online and unaffected.
1872613
Major
PFE crash is observed when PFE processes the traffic passing through the dedicated fabric link
Product-Group=junos
Severity=Major
On the Junos OS SRX4600 platform, when PFE (Packet Forwarding Engine) processes the IPv4/IPv6 traffic passes through the dedicated fabric link, PFE crash is observed. This issue happens when PMI (PowerMode IPsec) is enabled (by default) and flow session accessing stale values.
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: N/A:sw-jsr-flow-mcast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Severity=Major
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1850967
Major
L3MNHA with SRG1 IPSEC : MNHA ICL ipsec encryption link went down permanently after rebooting connected router through which ICL was established before. During this state IKE process got stuck at ~70% on MNHA Active node.
Product-Group=junos
Severity=Major
Generic MNHA issue not specific to CSDS
PR NumberSynopsisCategory: l2 flow module
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
Severity=Major
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.
PR NumberSynopsisCategory: all logging related bugs on srx platforms
1860597
Major
Security log report messages w.r.t logical system is not generated
Product-Group=junos
Severity=Major
show security log report cli command for logical systems is not working for 24.2R2, 24.4R1-S2, if log report is disabled under root system. Work around is available for this issue.
PR NumberSynopsisCategory: Layer 2 VPN related issues
1867040
Minor
Type 5 EVPN traffic is dropped on SRX when PMI is disabled or not supported
Product-Group=junos
Severity=Minor
On all SRX platforms, in an EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) environment, when PMI (Power Mode IPSec) is disabled or not supported, type 5 EVPN traffic gets dropped. The issue occurs due to flow context being cleared incorrectly, causing the overlay JEXEC nexthop to be pushed after the underlay one. This leads to the packet being treated as multicast and subsequently dropped.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1873674
Major
In EVPN IPv6 route learning for MAC address fails if mac pinning is enabled on the interface
Product-Group=junos
Severity=Major
On Junos platforms, when mac-pinning is enabled on Ethernet Virtual Private Network (EVPN) bridge domain and activate mac-pinning will cause MAC learning will for IPv6 EVPN route.
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1820329
Minor
License-service subsystem crash is observed when license keys are modified
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, upon adding invalid license keys, the license-check application crash is observed. There is no traffic impact observed due to this issue.
1845079
Minor
Unnecessary trace log files related to licenses are generated
Product-Group=junos
Severity=Minor
On Junos platforms agile-licensing infra, when upgrading to 23.4R1 and above, unnecessary trace log files related to licenses are generated. This issue has no impact on traffic.
1855728
Minor
License is Missed Post System Reboot
Product-Group=junos
Severity=Minor
On all Junos platforms, the license is lost after a reboot if it was installed using the 'set system license' method.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1850387
Minor
The dot1xd crash on MACsec enabled ports due to key length limit
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms supporting MACsec (Media Access Control security), when secret key-chain with more than 64 character is configured, it results in crash for dot1xd service causing traffic impact on all MACsec enabled ports.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
PR NumberSynopsisCategory: Multicast for L3VPNs
1861726
Major
The MVPN traffic forwarding is affected when BGP PIC is enabled
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, enabling BGP-PIC (Border Gateway Protocol-Prefix Independent Convergence) is causing the issues with forwarding MVPN (Multicast Virtual Private Network) traffic.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=junos
Severity=Minor
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.
PR NumberSynopsisCategory: build tools
1874525
Major
FTP default mode changed from active to passive on 24.2R2
Product-Group=junos
Severity=Major
An upgrade to libfetch caused the default FTP mode to move from active to passive. This PR corrects this as customers more than likely expect the previous active FTP functionality on their networks.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: Path computation client daemon
1823220
Minor
Authentication failure will be seen for routing protocols when MD5 is configured for routing protocols and PCEP on Junos OS Evolved platforms post reboot
Product-Group=junos
Severity=Minor
When MD5 is configured for PCEP (Path Computation Element Protocol) on Junos OS Evolved platforms, MD5 will not work for other protocols after reboot. Authentication failure will be seen and it causes a connectivity issue or a service impact.
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1811521
Major
PHC gets initiated and sends DNS request to Juniper server "redirect.juniper.net" even when device is supposed to get provisioned using ZTP with vendor specific option 43
Product-Group=junos
Severity=Major
Rarely, on all Junos platforms, PHC (Phone Home Client) is signaled to attempt bootstrapping by AIU (Auto Image Upgrade) when legacy ZTP (Zero Touch Provisioning) fails if vendor specific options (option 43 is sent by DHCP server) are not valid. This is followed by PHC sending DNS request to resolve "redirect.juniper.net" which is the redirect Juniper Server even if DHCP is released by ZTP and no IP is expected to be present.
1871802
Critical
High memory and CPU usage due to unintended phone-home client activation
Product-Group=junos
Severity=Critical
On Junos OS Evolved platforms, high memory and CPU usage may occur if the phone-home client (PHC) is unintentionally triggered, such as when the device boots with factory default settings or when phone-home is manually configured. This can lead to system slowness, crashes, and eventual device reboots.
PR NumberSynopsisCategory: Protocol Independant Multicast
1826383
Major
Rapid increment of "Hardware input drops" on command output "show pfe statistics traffic" due to PFE trapcode "dlu.ucode.ip_mc_iif_mismatch"
Product-Group=junos
Severity=Major
The issue is due to the PIM Join-load-balance feature. When the router has multiple ECMP paths to reach the multicast source and is configured for PIM Join-load-balance, Load balancing of Join will be done creating an active upstream path and a standby upstream path. When multicast streams are received on the standby upstream path, an IIF_MISMATCH is generated, consequently Standby path gets converted into Active path & PIM Prune will be sent on old active path and periodic joins will be cancelled on old Active path. However, in this case, protocol PIM prematurely removes the old active path without sending a prune on that path and removing the periodic old active joins. There can be another scenario where there is transition from one standby path to another standby path. In that case also old standby path needs to be pruned and periodic joins needs to be cancelled.
PR NumberSynopsisCategory: Issues related to PKI daemon
1767584
Minor
Self-signed certificates created with ECDSA and SHA256 defaults to ECDSA and SHA128
Product-Group=junos
Severity=Minor
On all Junos platforms when a self-signed certificate is created with the combination of ciphers ECDSA (Elliptic Curve Digital Signature Algorithm) with digest SHA-256 (Secure Hash Algorithm) the resulting certificate defaults to ECDSA and SHA-128 instead of the specified SHA-256, This can cause issues on any application in which the expected combination of ciphers is ECDSA - SHA-256 (for eg: the JWEB application, as JWEB expects SHA-256, the platform turns inaccessible as long as the certificate remains configured)
PR NumberSynopsisCategory: DHCP related Issues
1818909
Minor
An error log message is seen for every DHCP transaction
Product-Group=junos
Severity=Minor
On the QFX5120, QFX5110, EX4400, EX4100 and EX4300-48MP platforms, the "Error, DHCP packet re-insert failed" error log message is seen on every DHCP transaction.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1876359
Minor
ON QFX5K and EX4K platforms a log is required for route leaking when destination table hits a platform limitation
Product-Group=junos
Severity=Minor
On Junos QFX5K and Junos EX4K switches, route leaking for IPv4 requires a minimum route mask of /16, and the leak destination table must have a prefix length longer than or equal to that of the leak prefix for proper routing. When this doesn't occur, traffic forwarding is affected, and there is no log associated with this event
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
1866130
Minor
Command "show pfe vxlan" is not supported on QFX5200 devices
Product-Group=junosvae
Severity=Minor
Support added for "show pfe vxlan" CLI command on QFX 5200 devices
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1833154
Minor
FPC crashed with "Last Reboot Reason: CPU Watchdog Reset"
Product-Group=junosvae
Severity=Minor
On all Junos QFX10008, QFX10016 platforms, the FPC (Flexible PIC Concentrator) crashed with the reboot reason CPU Watchdog Reset due to the system placing the PCI (Peripheral Component Interconnect) bridge port into a low-power state.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
Severity=Major
The port interface on the 100G optics of the QFX5120-48T platform is incorrectly configured
1856855
Minor
Enabling FIPS, committing the config, with performing a reboot triggers a boot loop
Product-Group=junos
Severity=Minor
On Junos OS QFX5120-48YM platforms, enabling FIPS (Federal Information Processing Standards), committing the config, with performing a reboot results in a continuous reboot cycle (it only stays in CLI for a minute before rebooting automatically).
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
Severity=Major
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.
1847904
Major
CTLE Values mismatch for 100G-BASE-SR4/100G-BASE-SR4-T2 in QFX5120-48T
Product-Group=junosvae
Severity=Major
The CTLE for 100G-BASE-SR4/100G-BASE-SR4-T2 is set wrong value on QFX5120-48T platform.
PR NumberSynopsisCategory: RPD Interfaces related issues
1842546
Major
Memory leak is detected when interfaces are configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, 72-byte size memory leak is seen when interface configuration is added. But there is no traffic impact due to this issue.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1861451
Major
BGP PIC failover is taking longer than expected when IS-IS as an IGP enabled with LFA
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, in a BGP-L3VPN (Border Gateway Protocol - Layer 3 Virtual Private Network) setup when configured with BGP PIC (Prefix-Independent Convergence) on an ingress PE's (Provider Edge) VRF (Virtual Routing and Forwarding) routing-instance and having IS-IS (Intermediate System-to-Intermediate System) as an IGP (Interior Gateway Protocol) which if enabled with LFA (Loop Free Alternative), BGP PIC failover is taking loger time than expected due to lag in the route change for the BGP path to be used. This is causing traffic loss until global convergence.
1863248
Major
On all Junos OS Evolved platforms, traffic loss will be seen after switching the LSP from SRTE to L-ISIS
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms with Segment Routing Traffic-Engineering (SRTE) and Labeled- Intermediate System- Intermediate System (L-ISIS) configuration, when a service route is resolved over SRTE route in inet6color.0 and if the SRTE path in inet6color.0 is deactivated/goes down, the SRTE route is deleted and service route starts resolving over L-ISIS. However traffic loss for 20 minutes or more is seen after switching the Label Switched path (LSP) from SRTE to L-ISIS path.
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1858032
Major
The rpd process crashes when generate routes are configured in a rib-sharding scenario
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crash is seen when Border Gateway Protocol (BGP) rib-sharding is enabled and generate routes are configured. This occurs due to issue in route resolution, the rpd crash impacts routing and rpd will restart when this issue occurs.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.
1817450
Minor
Route on backup shard is not resolved under certain conditions
Product-Group=junos
Severity=Minor
after protocol BGP is deactivated, the resolution tables __raass_ at backup RPD are marked as deleted, and not resurrected post commit sync.
1845425
Major
Traffic blackhole is observed for IPv4 /32 LDP prefixes advertised over BGP-LU when BGP sharding is configured
Product-Group=junos
Severity=Major
On Junos OS MX and Junos OS Evolved PTX platforms with MPLS (Multiprotocol Label Switching) and BGP (Border Gateway Protocol) sharding configured, the route is not resolved as the resolver does not request PNH (Protocol Next Hop) information from RaaS (Routing as a Service) server although BGP added the route resolution in the inet.3 table. This issue leads to IPv4 /32 LDP (Label Distribution Protocol) prefixes advertised over BGP-LU (BGP Label Unicast) not being installed in the mpls.0 table i.e. corresponding labels being marked as hidden in the MPLS routing table (mpls.0), preventing proper traffic forwarding, leading to a traffic blackhole.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1847811
Minor
The rpd crash on commit when configuring router-advertisement with DNS search label under 3 characters
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, committing a configuration under protocols router-advertisement with a dns-search-list containing a domain label shorter than 3 characters causes the rpd (Routing Protocol Daemon) process crashes and restart. This results in configuration commit failure and temporary disruption to routing protocols.
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
PR NumberSynopsisCategory: Resource Reservation Protocol
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
Severity=Major
On all JUNOS and JUNOS evolved Operating Systems, if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
Severity=Critical
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. Please refer to https://supportportal.juniper.net/JSA100096 [juniper.net] for more information.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1829886
Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
Product-Group=junos
Severity=Major
Commit error check-out failed does not get triggered when a complete bridge-domain is configured in instance-type vrf.
1839362
Minor
The commit error is seen in backup RE on MX platforms
Product-Group=junos
Severity=Minor
On all MX platforms, the commit fails in Backup RE during configuration commit where "fast-synchronise" and "graceful-switchover" are being committed together.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1854070
Minor
cli coredump genarated when the size of buffer area (user input) increased to 1GB
Product-Group=junos
Severity=Minor
Cli coredump genarated when the size of buffer area (user input) increased to 1GB.
1861063
Critical
Unexpected issues such as login failures or disabled interfaces observed following abrupt reboot during commit operation
Product-Group=junos
Severity=Critical
On Junos EX platforms with boot-time optimization enabled, an abrupt reboot during a commit operation can cause configuration file corruption, potentially leading to issues like login failures or disabled interfaces.
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1831811
Minor
CLI crashes for "show log | display json | no-more" execution if the log size is more than the process max stack size limit
Product-Group=junos
Severity=Minor
CLI crashes for "show log | display json | no-more" execution if the log size is more than the process max stack size limit
PR NumberSynopsisCategory: PTX/QFX100002/8/16 interface software
1817562
Major
DFE tuning stuck due to configuration error preventing interface from coming up
Product-Group=junos
Severity=Major
On Junos PTX10008, PTX10016 and PTX platforms with FPC3-PTX, after a router reboot or FPC (Flexible PIC Concentrator) restart, DFE (Decision Feedback Equalisation) tuning is initiated on all active interfaces. If a tuning failure occurs due to a FEC (Forward Error Correction) mismatch, the process gets stuck. Even after correcting the error, the interface remains down as the system cannot initiate a new DFE tuning until the previous attempt completes.
PR NumberSynopsisCategory: VMHOST platforms software
1856565
Minor
High memory consumption in VMhost causes FPC reboot
Product-Group=junosvae
Severity=Minor
On all VMhost based platforms, excessive file accumulation in the /var/tmp directory of the host side triggers FPC reboots, resulting in network traffic disruption. This condition occurs when available space falls below 65% (usage exceeds 35%).

 


 

Extended Solution

23.4R2-S5 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1878355
Minor
dhcp-snoop routes are not installed when IPSG group is full
Product-Group=junos
dhcp-snoop routes are not installed when IPSG group is full when IPv4/v6 source guard is enabled along with DAI/NDI. When dhcp snooping binding entries exceed 512, even new bindings show up in the binding table, the dhcp-snoop route is not installed in HW. New bindings will be dropped due to DAI/NDI. This behavior is expected. As we are running out of space of FP entries in HW, routes are NOT installed beyond the scale. IPv4 and IPv6 uses the same VFP in HW. switch> request pfe execute command "show filter hw groups" target fpc0 Unit:0 Group Information: > VFP groups: Dynamic group id: 1. Pipe: 0 Entries: 1 Total_available: 512 Pri: 0 Def Entries: 0 VFP group for COS id: 143. Pipe: 0 Entries: 7 Total_available: 512 Pri: 2 Def Entries: 0 VFP group for DYN IPSG group id: 391. Pipe: 0 Entries: 512 Total_available: 512 Pri: 3 Def Entries: 0 <--- full group with 512 entries

Resolved In:
PR NumberSynopsisCategory: NFX Series Platform Software
1850987
Major
INSIGHTD messages logged every 5 seconds on NFX 250
Product-Group=junos
INSIGHTD messages logged every 5 seconds on NFX 250, these are harmless and can be hidden from syslog. jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40005 jinsightd[19158]: JINSIGHTD_SENSOR_RESUBSCRIPTION: RetrySubscription: Triggering Re-subscription. retry_count 40006

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SRX Fleming L2NG platform support
1868103
Minor
CoS shaping is not functional on IRB interfaces when the SRX1600 is in switching mode
Product-Group=junos
On SRX1600 platform, Class of Service (CoS) shaping does not work on IRB (Integrated Routing and Bridging) interfaces.

Resolved In: junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: "agentd" software daemon
1873990
Major
EX9208: Syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' every 5 sec
Product-Group=junos
On EX9200 series switch, syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' is seen every 5 sec

Resolved In: evo:23.4R2-S6-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:25.2R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1887911
Major
[MX304] RPD crash with bgp_uioth_process_rto_msg and bgp_uioth_handle_ms2io_msg post BGP related config commit
Product-Group=junos
RPD crash when "group-split-size" is configured while using BGP-RIB sharding and later when route-advertisement tuple for the non-negotiated NLRI targeted towards other BGP peers (that have the NLRI negotiated) of the group is received in this update-thread

Resolved In: evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: OpenSSH and related subsystems
1872685
Minor
vmhost software upgrade failure if [ssh hostkey-algorithm-list ecdsa-sha2-nistp<>" is configured
Product-Group=junos
With respect to the VMHOST platforms while upgrading between the JUNOS releases, please always ensure that one of the hostkey-algorithms exist in the configuration if [ssh hostkey-algorithm-list] has to be used: rsa-sha2-512, rsa-sha2-256, ssh-rsa, ecdsa-sha2-nistp256, ssh-ed25519. Note: If this knob has not been configured at all, then that case is also fine.

Resolved In:
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP Scenarios
Product-Group=junos


Resolved In: junos:23.4R2-S2-J16 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1887864
Major
LC480 - retransmissions seen on NON-JNPR SFP-T when close to IGP recommendations
Product-Group=junos
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J8 junos:22.4R3-S8 junos:23.2R2-J22 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EVPN control plane issues
1796532
Major
EVPN mac-ip entry flag "Duplicate-Not-Best" not updated after deleting duplicated IRB IP in EVPN_VXLAN MAC-VRF
Product-Group=junos
On all Junos and Junos Evolved platforms, duplicate mac-ip detection for IRB IP is not working since the IP move is not triggered after adding an IP address to the IRB interface.

Resolved In: evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2-S4 junos:24.2R1 junos:24.3R1
1816672
Minor
[Junos OS Evolved] LACP on non-DF ACX router comes out of "out-of-sync" state by deactivating one of the EVPN instances, causing CE device to move to Collecting distributing
Product-Group=junos
There are multiple EVPN instances each having separate IFL of AE IFD. AE is configured with per-esi lacp-oos-on-ndf on the AE IFD. On deactivating one of the instances, LACP on non-DF router comes out of "out-of-sync" state, causing CE device to move to Collecting distributing.

Resolved In: evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.2R3-J14 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S7 junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EX4100 Interface, Optics, MacSec, POE
1657766
Minor
On EX4100 in an interoperability scenario when using 1G SFP Optic on PIC-2, auto-negotiation should be disabled on the peer
Product-Group=junos
EX4100-24mp, 48mp, 24p/t, 48p/t, F-24p/t, F-48-p/t: In an interop scenario, when using 1G SFP Optic on PIC-2, auto-negotiation should be disabled on the peer

Resolved In:
PR NumberSynopsisCategory: EX interfaces issues
1580560
Major
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.
Product-Group=junos
On EX2300, EX3400, :EX4300-48MP and EX4300 , Pause frames counters does not get incremented when pause frames are sent.

Resolved In:
1833177
Major
EX2300/EX3400 : The status LED of uplink port is not working properly
Product-Group=junos
On EX2300 and EX3400, the status LED of uplink port always displays green regardless of the status of the link.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EX4400 platform
1814463
Minor
EX4400: MIST: Wrong PSU state is updating in the mist
Product-Group=junos
Unsupported PEM/PSU is shown as online (green)in the MIST Dashboard and the output of "show chassis environment" for that PSU shows the status as present/OK. No functional impact.

Resolved In: junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Express PFE CoS Features
1719956
Major
Convergence delay is seen when FPC is offlined under heavy traffic and scaled scenario
Product-Group=junos
On Junos PTX3000, PTX5000, PTX10008, and PTX10016 routers, when the Flexible PIC Concentrator (FPC) is offlined with scale configuration and heavy traffic, a delay in convergence (into tens of minutes) is seen on all the live FPCs in the chassis other than the offlined one. This impacts traffic.

Resolved In: evo:22.1R3-S3-EVO evo:22.3R3-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:18.2X75-D67 junos:20.3X75-D36 junos:20.3X75-D51 junos:21.2R3-S5-J4 junos:21.2R3-S5-J5 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Express PFE FW Features
1885906
Major
Unable to add the filter secondarymatch to the hardware
Product-Group=junos
On QFX10K platform, only 4 secondary filter matches are supported per term. Ranged ttl match conditions can be configured, however, it takes up more resources as it needs to create entry for the range to match as well as the range to not match. For example, the filter installation in PFE will fail if there are 3 ranged ttl conditions in a single term. set firewall family inet filter FIREWALL_FILTER term TTL_INVALID from ttl 1-32 set firewall family inet filter FIREWALL_FILTER term TTL_INVALID from ttl 64-96 set firewall family inet filter FIREWALL_FILTER term TTL_INVALID from ttl 128-254 With only 2 ranged ttl conditions, there will be no problem with PFE filter installation.

Resolved In:
PR NumberSynopsisCategory: SRX1500 platform software
1831955
Major
The SRX1500 drops the packet if MTU matches the MRU of the receiving device
Product-Group=junos
On SRX1500 platforms, if the Maximum Transmission Unit (MTU) is configured to match the Maximum Receive Unit (MRU) of the receiving device, packet drops occur. This occurs because additional processing overhead increases the packet size beyond the MRU limit, causing the receiving device to drop the packets.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: jdhcpd daemon
1714260
Major
The DHCPv4 relay will send two option-82 to the server and the DHCP session will not be established
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when Dynamic Host Configuration Protocol (DHCPv4) Relay is configured with forward-only mode along with "trust-option-82", DHCP-relay should not add another option 82 to the packet sent to the DHCP server. The DHCP server upon receiving the packet with two option-82 will respond only with 1st header of option-82 which might get dropped by the relay, thus the packet is not forwarded to the DHCP client and the DHCP session won't get established.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-EVO evo:22.2R3-S1-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.4R2-S4-EVO junos:21.2R3-S5 junos:21.2X4 junos:21.3R3-S4 junos:21.4R3-S2-J10 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
1769598
Major
The jdhcpd prcoess crash will be observed due to double free of memory allocation when DHCP ALQ is configured
Product-Group=junos
On MX platforms , when DHCP ALQ ( Dynamic Host Configuration Protocol Active Lease Query ) is configured and subscriber management is enabled, the jdhcpd process crash will be observed due to double free of memory allocation. The DHCP services will be down and it will restore once jdhcpd process is restarted.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S6 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Juniper Device Manager VM Mgmt and infrastructure function
1774177
Critical
Performance degradation on NFX platform running WRL LTS19
Product-Group=junos
Degradation on all NFX platform running Wind River Linux (WRL) Long Term Support (LTS) 19, due to several components in LTS19 taking up more CPU/memory and reducing performance.

Resolved In:
PR NumberSynopsisCategory: Flow Module
1847419
Minor
Type 5 VXLAN traffic drops are observed when SRX run as L3-VNI gateway and the ingress and egress traffic goes to the same Type-5 VXLAN peer
Product-Group=junos
On Junos OS SRX platforms running as L3-VNI (Layer 3 - Virtual Network Identifier) gateway in EVPN-VxLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) scenario, traffic drops will be observed if traffic passes through two VxLAN tunnels and traffic fails to cross the two VxLAN tunnels when the PFE (Packet Forwarding Engine) is processing the packet having same remote IPs for two VXLAN tunnels.

Resolved In: junos:23.2R2-S2-J8 junos:23.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.

Resolved In: junos:23.2R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.

Resolved In: junos:22.4R3-S8 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1885185
Major
Macsec: AE interface is down with macsec exclude-protocol lldp
Product-Group=junos
When exclude protocol is configured with MACsec on IFD/IFL, a delete interface can cause the exclude protocol filters to not clean up. When MACsec is reconfigured on the same link with AE, AE goes down.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: SW PRs for MPC10E PMB
1731258
Major
MPC10 and MPC11 line cards experiencing unexpected reboots
Product-Group=junos
Line cards such as MPC10 and MPC11 experience unexpected reboots because of CPU C-states which are enabled by default thus impacting the customer production traffic.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D46 junos:20.3X75-D52 junos:21.4R3-S7 junos:22.2R3-S4 junos:22.2R3-S5 junos:22.4R3 junos:22.4R3-S1 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: MPC10E timing and synchronization
1878254
Major
1PPS measurement failed for class-B over 100GE to 100GE port combinations using SR4 optics
Product-Group=junos
On Junos MX240, MX480, and MX960 platforms, when using SR4 100 G (Short Reach 4-lane 100 Gigabit Ethernet) optics with FEC91 (Forward Error Correction) mode enabled, additional delays are introduced in the optics that fails class-B mask on PTP (Precision Time Protocol) on the particular interface.

Resolved In: junos:23.4R2-S6 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
The root cause is, when the system comes up after reboot, in MCSNOOPD (/usr/sbin/mcsnoopd used for L2 multicast), the lsi interfaces are learned. In MCSNOOPD, when there are 4 lsi interfaces learned, we create a nexthop(assume VE NH1) with all these 4 lsi as members and we use it in the routes for forwarding the traffic. When MCSNOOPD learns 5th lsi interface, as per internal NH(nexthop) allocation logic, we allocate a new nh(assume VE NH2) containing all these 5 lsi interfaces and free the old NH(VE NH1). The old freed NH(VE NH1) is accessed and tried to be freed again in another part of the code flow which is causing MCSNOOPD core(/usr/sbin/mcsnoopd). The fix is to free the old NH(VE NH1) in a common place instead of freeing in multiple places.

Resolved In: evo:22.4R3-S8-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1801129
Major
IP routes can get added to a deleted routing table
Product-Group=junos
On all Junos platforms routes can get added to deleted routing tables.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: OSPF routing protocol
1827435
Major
OSPF LSA flooding is impacted after database recovers from 'ignore' state when 'database-protection' is triggered
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when the LSA (Link State Advertisement) count exceeds the maximum number configured under 'database-protection' feature in OSPFV2 (Open Shortest Path First Version 2), the OSPF database (DB) enters into 'ignore' state. When the DB is recovered, OSPF LSA flooding is stopped on some interfaces.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.2R3-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1867979
Critical
cuc_3617: Qfx5120-48y-VC: After performing split and make of VC , BUM traffic on FPC1 is getting replicated more than expected .
Product-Group=junos
Problem: Performing VC split and Merge operation causes traffic to be affected for Broadcast, Unknown-unicast and Multicast traffic. RCA: When the Link is Brought down, each FPC will try to re-synchronize the IFDs, in addition resources are busy with updating for the new role. This can cause some synchronization issues with for IFDs/IFLs and other such lists. Test: This can be seen by the VTY command "show ifd brief" and "show ifl brief" for all the FPCs Workaround: It is recommended to wait at least 240 seconds after Splitting the VC ad merging it back again. This ensures that the system can get enough time to synchronize the IFDs/IFLs etc. from the kernel.

Resolved In:
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact

Resolved In:
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1851629
Minor
Next-hop APIs to support LDP stitching cases over BGP routes pointing to list of indirects
Product-Group=junos
On all Junos and Junos Evolved platforms this is an enhancement for Nexthop APIs to support LDP stitching cases over BGP routes pointing to list of indirects next-hops.

Resolved In: evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.2R2
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1840635
Major
Vmhost upgrade fails due to vrf instance validation error
Product-Group=junos
During vmhost image upgrades on Junos PTX10008/PTX10016 routers running Junos 22.4R3 and above versions, when more than two VRF(Virtual Routing and Forwarding) instances are configured, the configuration validation fails with the "RT Instance: Maximum 2 vrf instances are supported" error. This impacts the vmhost image upgrade on the device. via CLI when using the "request vmhost software add  reboot" command.

Resolved In: junos:20.3X75-D36
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1757389
Minor
"show route detail" shows "State: " for routes when route-record is enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms with route-record enabled, some routes will be seen in State: due to race condition. There is no functionality issue, this is a display issue.

Resolved In: evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:24.1R1-EVO evo:24.4R2-EVO junos:23.2R1-S2 junos:23.2R2-J14 junos:23.4R1-S1 junos:24.1R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1840503
Major
Tactical Traffic Engineered load sharing utilization displays incorrect percentage on MX platforms
Product-Group=junos
On MX platforms is configured with SRv6 (Segment Routing) along that Tactical Traffic Engineered(TTE) load sharing is enabled for SRv6, in some circumstances, TTE value displays percentage in 10 digit ( example 8889140224.00% ) when executing "show congestion-protection interface detail". It does not cause any traffic impact.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1830281
Major
Sourceport-ID comparison resulting in higher value for MPC7E compared to MPC5E for distributed PTP architecture
Product-Group=junos
SourcePort-ID comparison across line cards between MPC7E and MPC5E/6E/3E-NG/2E-NG shall result in selecting MPC5E/6E/3E-NG/2E-NG compared to MPC7E/8E/9E/10E.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: DDos Support on MX
1733477
Minor
Harmless logs "DDOS : Failed to insert flow to lkup map for proto: 3c00" observed in syslog
Product-Group=junos
"Failed to insert flow to lkup map for proto: 3c00" messages reported repeatedly in the syslog/messages file without any functional impact.

Resolved In: evo:21.4R3-S6-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S7 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
TFTP server crashes when configuration to limit connections are not reflected
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values and server crashes.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1878430
Major
The mgd process crash is seen on all Junos and Junos Evolved platforms when FQDN is configured along with ephemeral database
Product-Group=junos
On all Junos and Junos Evolved platforms configured with Fully Qualified Domain Name in presence of ephemeral database instances, the mgd process crash is observed. As a result, mgd session gets terminated and commit fails. There is no traffic impact due to this issue. The issue is seen only with FQDNs that resolve to multiple IP addresses.

Resolved In: evo:24.4R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: MX10K linecard
1784824
Major
LC480 line card crashed with reference to posix_interface_abort () at ../src/pfe/platform/linux/posix_interface.c:2729
Product-Group=junos
LC480 may restart unexpectedly during boot up.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: VMHOST platforms software
1787608
Critical
The chassisd crashes at first boot up after reboot
Product-Group=junos
Additional logging has been added to the primry Routing Engine. This is to help narrow down the issue which chassisd process restarted unexpectedly at snmp_init_oids( ) function on the primary Routing Engine while booting up.

Resolved In:
1795506
Minor
A non service impacting warning message 'Failed to set 'memory.limit' will be observed
Product-Group=junos
On all Junos OS Evolved platforms a warning message "Failed to set 'memory.limit_in_bytes' attribute on '/user.slice' to '-1': Invalid argument" would be observed.

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:24.2R1-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.4R1

 

Modification History

First publication 2025-07-29