Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

QFX platforms running JUNOS software - except QFX10000s, which have been released earlier See TSB104523 [juniper.net] for a SRN covers the rest of the platforms

Alert Description

Junos Software Service Release version 23.2R2-S5 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

Junos Software service Release version 23.2R2-S5 is now available.

23.2R2-S5 - List of Fixed issues

PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1842955
Critical
Route validation sync status remains incomplete when sharding is enabled
Product-Group=junos
Severity=Critical
On all Junos and EVO platforms, When we have No-stop routing configured on the router, and route-validation is turned on, we see route-validation sync to be in Not-started state in show task replication output.
1851205
Major
Junos OS and Junos OS Evolved: When route validation is enabled, route validation cache connection establishment leads to an rpd crash (CVE-2025-52958)
Product-Group=junos
Severity=Major
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100066 [juniper.net] for more information.
1853025
Major
Updating a source-file to load ROAs should be done by changing the name of the source file
Product-Group=junos
Severity=Major
Loading ROAs from a source-file was a feature introduced as a convenience feature and as such this only affects that feature. This feature is not in widespread use and was created to have a fallback ROA when all sessions go down. This problem scenario requires multiple reloads with the being modified back and forth to add and then delete and re-add the database configured in the import policy.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1874476
Major
Transient traffic loss for CE in an EVPN MPLS setup with Multi-Homing
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with EVPN MPLS, Multi-Homing scenarios, when there is a Multi-Homing peer node reboot, the destination route entries that were learned locally on IRB(Integrated Routing and Bridging) interface of rebooted node get deleted on other multi-homing peers without RE-ARP (Routing Engine-Address Resolution Protocol) causing transient traffic loss for CE (Customer Edge) traffic.
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The process rpd is cored while adding or removing dynamic-tunnels
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, the indexing of next hop while adding or deleting dynamic tunnels causes the rpd process to core and restart. This is a timing issue.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
Severity=Major
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.
PR NumberSynopsisCategory: Flow Module
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
Severity=Major
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
Severity=Major
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
Severity=Major
When the mcsnoopd process (use for L2 multicast) creating a new NH , our system takes a reference to it. However, if this reference is released too quickly, the old NH might be deleted before its references are fully cleared. This may cause the mcsnoopd process to restart.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=junos
Severity=Minor
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1872704
Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
Product-Group=junos
Severity=Major
NTS for NTP not working even after the Ceritficate is validated with External servers like Chrony and NTPSec
PR NumberSynopsisCategory: Protocol Independent Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.
PR NumberSynopsisCategory: QFX platform fabric mgmt for Express ASIC chip
1833086
Major
IBM | qfx10008 | 21.4R3-S5.4 | FPC 0 SIB Link Error | Link error is reported even with lower threshold
Product-Group=junos
Severity=Major
CRC errors can be seen because of the HW degrading with age. Although the CRC errors are not crossing the threshold but links report error. The patch has been added to address such event with additional logs.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
Severity=Major
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
Severity=Major
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1854481
Minor
The rpd gets struck with 100% CPU usage after enabling BGP RIB-Sharding
Product-Group=junos
Severity=Minor
On all Junos OS and Junos OS Evolved platforms , enabling the BGP RIB-Sharding causes the routing protocol daemon (rpd) leading to spike and remain at 100% CPU usage due to a background task ( such as the Route Target/User Interface (RT/UI) delete job ) entering into the continuous processing cycle and looping behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
Severity=Major
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1840338
Major
Schema.db file gets deleted when maxfile limit is reached on the system
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, the CLI ( Command Line Interface) /NETCONF session won't start if the schema.db file is deleted when the system reaches the maxfiles limit.
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
Severity=Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
1861063
Critical
Unexpected issues such as login failures or disabled interfaces observed following abrupt reboot during commit operation
Product-Group=junos
Severity=Critical
On Junos EX platforms with boot-time optimization enabled, an abrupt reboot during a commit operation can cause configuration file corruption, potentially leading to issues like login failures or disabled interfaces.
1872820
Major
The dcd process crashes when deactivating only 'swap' under ' interfaces <> unit <> output-vlan-map' with no other attributes present
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, this issue affects configurations where Virtual Local Area Network (VLAN) mapping is used, particularly in scenarios where only the swap attribute is applied under 'interfaces <> unit <> output-vlan-map'. Sequence of 'Deactivate -> Activate -> Commit' of the config hieararchy leads to crash of the device control daemon (dcd) process, potentially causing service disruption.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
Severity=Major
On all MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.
PR NumberSynopsisCategory: Virtual Private LAN Services
1797423
Major
Memory leak is observed for the VPLS CE facing interface on all Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms memory leak in task_timer block is observed for Virtual Private LAN Service (VPLS) CE facing interface. These leaks are configuration driven and can happen when VPLS instance configuration is deleted or probably when CE interface moves across VPLS instances or deleted from the VPLS instance.

 


 

23.2R2-S5 - List of Known issues

PR NumberSynopsisCategory: ISSU
1898501
Major
EX4650/QFX5120-48Y: ISSU incompatibility with previous releases
Product-Group=junos
EX4650/QFX5120-48Y: Older releases (that do not contain the 1882472 fix) are ISSU incompatible with current releases that have 1882472 fix.

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1760356
Major
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-21598)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75739 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:23.4R2-S3-EVO evo:24.1R1-EVO junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S4-J27 junos:21.2R3-S4-J30 junos:21.2R3-S4-J37 junos:21.2R3-S7 junos:21.2X33 junos:21.2X34 junos:21.2X8 junos:21.3R3-S5 junos:21.4R3-S5 junos:21.4R3-S5-X1 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S1 junos:22.3X60 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.2R2-S4 junos:23.3R1 junos:23.3R2 junos:23.4B1 junos:23.4R1 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1839955
Major
On Junos OS Evolved platforms, HTTPS download fails when HTTPS URL is present in the configuration
Product-Group=junos
On Junos OS Evolved platforms, when HTTPS URL is present as a part of file or mentioned explicitly in the configuration, and when there is a download attempted through this file the download fails. However, this is will not impact the forwarding traffic only the download through HTTPS will fail.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S3-C1-EVO evo:23.4X100-D30-EVO evo:24.2R2-S1-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:23.2R2-S3-C21 junos:23.4R2-S4 junos:23.4X1 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R2-S1 junos:24.2X1 junos:24.4R1-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1766275
Major
EVPN CRB traffic drops after the FPC restart
Product-Group=junos
On all Junos platforms, in Ethernet Virtual Private Network - Multiprotocol Label Switching (EVPN-MPLS) setup, with high scale and churn caused in the system by local Flexible PIC Concentrators (FPCs) restart, indirect next hop creation will fail for EVPN Centrally-Routed Bridging (CRB) instances and EVPN CRB traffic will be forwarded as Broadcast, Unknown Unicast, and Multicast (BUM) traffic. If there is any filter configured to drop BUM traffic explicitly, then traffic drop will be seen. Otherwise, the impact will be a traffic flood which will not cause traffic loss.

Resolved In: evo:23.4R2-EVO evo:24.1R1-EVO junos:23.4R2 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: Flow Module
1834338
Major
GRE traffic is getting blocked due to a software programming issue and MTU going below minimum value
Product-Group=junos
On Junos OS SRX platforms with GRE (Generic Routing Encapsulation) configured, due to a software programming issue, some threads have incomplete information while processing the data and even if "no-path-mtu-discovery" or "no-gre-path-mtu-discovery" is configured, the MTU going below minimum value (IPv4- 578, IPv6 1280) resulting in the GRE traffic being blocked i.e. complete traffic impact.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Firewall Policy
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: TCP/UDP transport layer
1864027
Minor
TCP listening sockets are not displayed correctly
Product-Group=junos
On Junos OS platforms, TCP (Transmission Control Protocol) listening sockets may be absent from command outputs due to NULL values in netstat application.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX L2 PFE
1715477
Minor
Untagged packets get dropped while adding a layer 3 logical unit to an interface with native vlan configured
Product-Group=junos
On all Junos platforms, adding a logical layer3 unit to an interface with native vlan configured causes the untagged packets to get dropped.

Resolved In: junos:20.3X75-D44 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.

Resolved In: junos:21.2R3-S10 junos:21.4R3-S12 junos:22.4R3-S9 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.

Resolved In: junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover,
1782934
Major
vmcore on device with evpn-vxlan configs
Product-Group=junos
Graceful Routing Engine Switchover (GRES) not supporting the configuration of a private route, such as fxp0 , when imported into a non-default instance or logical system. Please see KB https://kb.juniper.net/InfoCenter/index?page=content&id=KB26616 [juniper.net] resolution rib policy is required to apply as a work-around

Resolved In:
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
1854481
Minor
The rpd gets struck with 100% CPU usage after enabling BGP RIB-Sharding
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms , enabling the BGP RIB-Sharding causes the routing protocol daemon (rpd) leading to spike and remain at 100% CPU usage due to a background task ( such as the Route Target/User Interface (RT/UI) delete job ) entering into the continuous processing cycle and looping behaviour.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S4-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.2R2-S4 junos:23.4R2-S4 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1812124
Minor
The rpd process crash is observed when the label received exceeds the configured maximum-labels 16
Product-Group=junos
On Junos and Junos Evolved platforms, the rpd process crash is observed on both REs (Routing Engines) and RE switchover was triggered when maximum-labels under MPLS(Multi Protocol Label System) address family is configured as 16 and an extra label is received.

Resolved In: evo:21.4X9-EVO evo:22.4R3-S5-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:19.4R3-S14 junos:21.2R3-S9 junos:21.4X10 junos:22.3X60 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In: