Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX platforms running Junos software

Alert Description

Junos Software Service Release version 24.4R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review. This SRN is specific to MX platforms running Junos Software only

Solution

Junos Software service Release version 24.4R2-S2 is now available.

24.4R2-S2 - List of Fixed issues

PR NumberSynopsisCategory: BBE CPM/UPM
1902855
Major
Deactivating or deleting "auto-configure" knob in an interface is not working properly
Product-Group=junos
Severity=Major
On all MX and ACX platforms supporting BNG Control and User Plane Separation Solution (BNG-CUPS), deactivating or deleting the "auto-configure" knob under an interface is not being handled properly.
PR NumberSynopsisCategory: Border Gateway Protocol
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
1903829
Major
On platforms supporting BGP RIB sharding the rpd process crash is observed on both REs
Product-Group=junos
Severity=Major
On platforms supporting where BGP (Border Gateway Protocol) RIB (Routing Information Base) Sharding is configured the rpd process crashes on both REs (Routing Engines) due to route churns. This timing issue is caused when a particular internal function is used by multiple threads.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1907660
Minor
Interface telemetry statistic /interfaces is not streamed correctly on Junos OS Evolved PTX platforms
Product-Group=junos
Severity=Minor
Interface telemetry statistic /interfaces may be streamed incorrectly on Junos OS Evolved PTX platforms. The counter may not be updated, or not update at regular intervals. There is no service impact except monitoring capability using telemetry.
PR NumberSynopsisCategory: MX304 Routing Engine issues
1854658
Major
The chassisd process crashes when commit command is issued multiple times
Product-Group=junos
Severity=Major
On Junos VMhost platforms, when commit command is issued 50-60 times in a minute, this leads to ssh session exhaustion and slow response which causes configuration commit delays and subsequently leads to a chassisd process crash and restart causing FPC restart.
1877895
Major
Martian logs observed on the device.
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved OS, martian logs are observed on FPC (Flexible Physical Interface Card) and on Routing Engine 0.
PR NumberSynopsisCategory: MX Platform SW - UI management
1884816
Major
MIC details not polling when SNMP MIB walk is performed after Junos OS upgrade
Product-Group=junos
Severity=Major
Post upgrading the Junos OS for MX10K platform from 21.4R3-S3.4 to higher versions, the Simple Network Management Protocol (SNMP) Management Information Base (MIB) walk is not polling Modular Interface Card (MIC) details impacting the SNMP monitoring.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1883530
Critical
FPC crash is seen on certain Junos platforms when firewall filter is configured for subscribers
Product-Group=junos
Severity=Critical
On MX platforms with MPC10E, MPC11E, LC9600 line-cards and MX304 with subscriber-management enabled, Flexible PIC Concentrator (FPC) crashes in a rare scenario and crash files are generated when filters are configured for subscribers . This will lead to traffic impact since the line-card reboots and subscribers are re-logged.
PR NumberSynopsisCategory: MX Inline Jflow
1901369
Major
Flow records not being exported correctly to the collector on specific MX platforms with default route configuration
Product-Group=junos
Severity=Major
In Impacted platforms with specific linecards running inline-jflow feature, sampling any route which can be Implicit Default Route or user configured/injected route, FPC (Flexible PIC Concentrator) is calculating it as invalid route with prefix length zero. Because of this, flow is not getting exported properly to the collector with route record lookup failures and AS (Autonomous System) Lookup Failures.
PR NumberSynopsisCategory: jdhcpd daemon
1885335
Major
irb.0 uplink network Connection lost after move the cable from fpc0 to fpc1 and remove the fpc0 from network. with fpc1 as vc new master. restart dhcpd fixed the issue after waited for 20 mins
Product-Group=junos
Severity=Major
This issue arises when the DHCP client is configured in Virtual Chassis (VC) environment, and a VC switchover is initiated by the removal of the primary FPC. MAC persistence timer feature introduces a delay in propagating the updated MAC address throughout the system. Consequently, the DHCP client continues to operate with the previous MAC address and fails to terminate and reinitialize the session using the new MAC address.
PR NumberSynopsisCategory: flow ha module
1895134
Minor
ISSU failure and process crash on primary node during HA upgrade
Product-Group=junos
Severity=Minor
On all Junos SRX platforms, performing ISSU (In-Service Software Upgrade) with the no-validate option in HA ( (High availability ) setups can cause ISSU failure and a process crash on the primary node.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1877966
Minor
Some new VPN tunnels are not coming up on SRX5K platforms with SPC3
Product-Group=junos
Severity=Minor
On SRX5K platforms with SPC3 installed, IPSec (Internet Protocol Security ) tunnels with iked which reuses the same IKE (Internet Key Exchange) gateway peer IP, could be observed not re-establishing.
1892539
Major
IKE Processing Order Causing Gateway Misconfiguration and Tunnel Failures
Product-Group=junos
Severity=Major
On SRX platforms, when both gateways, the local-address and the IFA (Interface address) are changed and if the IKE (Internet Key Exchange) configuration is processed before the IFA update, gateways lacking an explicit local-address will be misconfigured, leading to tunnel failures.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1909786
Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
Product-Group=junos
Severity=Critical
Selection of VGA-IP as source IP for RE-ARP packet causes incorrect ARP updation of VGA-IP getting bound with IRB-MAC at end-hosts
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=junos
Severity=Minor
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1897464
Major
Memory allocation failure on all FPC's with error Add failed memory allocation failure nh-id:
Product-Group=junos
Severity=Major
Memory allocation failure on all FPC's with error Add failed memory allocation failure nh-id:
PR NumberSynopsisCategory: DDos Support on MX
1860439
Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces
Product-Group=junos
Severity=Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1902713
Minor
The mgd process crash observed on running commit check after replace operation of groups name for apply-groups-except
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when replace operation was done on apply-groups-except object it was not clearing the entry of that object from apply-groups-info-tree, as a result 'mgd' process crash observed on commit check. There is no service impact due to this issue.

 


 

24.4R2-S2 - List of Known issues

PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.

Resolved In: evo:24.4X200-D10-EVO evo:24.4X200-D20-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO junos:24.2X1 junos:25.2R1-S1 junos:25.2R2
PR NumberSynopsisCategory: BBE UP Session Manager related issues
1890895
Major
BNG Controller: Issue with changing the IP address of an active BNG user-plane
Product-Group=junos
BNG Controller: Issue with changing the IP address of an active BNG user-plane

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:22.3X60 junos:23.2R2-S5 junos:25.2R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1886633
Major
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.
Product-Group=junos
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.

Resolved In:
PR NumberSynopsisCategory: Device Configuration Daemon
1824206
Minor
Device reboot will bring down the asi interfaces on all Junos platforms
Product-Group=junos
On all Junos platforms, there is a synchronization problem between the rdd daemon and the chassisd processes regarding the creation of ASI (Aggregated Inline Services) interfaces during system bootup that causes the chassisd to delete all interface-related configurations and thus delete the ASI interfaces from the system. Due to that, the ASI interface remains down, and it will affect only ASI interfaces, and other interfaces will not be affected by this issue.

Resolved In: evo:25.2R1-EVO junos:23.2R2-S2-J7 junos:25.2R1
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908719
Major
On all mx platforms chassid gets stuck and becomes unresponsive it resumes only after restarting both control units.
Product-Group=junos
On MX devices, the sub-linecard feature with MPC11 cards. When this feature is used, the main system process can sometimes freeze, which may lead to system crashes and error logs.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1908196
Major
All Marvell(MX, ACX): LLDP protocol goes down when 'exclude protocol LLDP' is deleted from MACsec policy attached to IFD
Product-Group=junos
With IFD MACsec configured with exclude-protocol LLDP and LLDP protocol enabled, LLDP protocol goes down when 'exclude-protocol LLDP' is deleted from MACsec connectivity association.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
PR NumberSynopsisCategory: ISIS routing protocol
1886347
Major
partial traffic drops seen on NSR switchover for Indirect route Going over L-ISIS transport route having "sensor-based-stats" configured under protocols isis
Product-Group=junos
On Junos and EVO platforms, After a Graceful Routing Engine Switchover (GRES), in New master, Indirect routes gets updated to the PFE and result in traffic loss when the transport is L-ISIS with telemetry traffic sensors enabled. In this scenario, Indirect routes going over L-ISIS route. Reason for Indirect route change is due to Underlying L-ISIS route next-hop getting changed. L-ISIS route next-hop getting changed due to ?Sensor-based-stats? configuration which does not support NSR functionality. Hence After Switchover, New Master Create sensors and Installed in the L-ISIS next-hop result in L-ISIS next-hop changed. Once L-ISIS routes nex-thop gets changed, Indirect routes under going for re-resolution which cause traffic impact.

Resolved In:
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.3R1
PR NumberSynopsisCategory: Flow Module
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: flow ha module
1888480
Major
24.4R1 : Moneypenny : MNHA SRX4700 : After restart routing on the ACTIVE MNHA SRX1A & when cold sync is Complete on both the nodes, the backup node shows majority of the sessions as ACTIVE
Product-Group=junos
Restart routing will cause almost of update wing to warm RTO lost when it's not retransmission by default due to failover CPU usage consideration, and then session state will be broken. Suggest to disable preemption and configure "set security flow high-availability rto-retransmission" to work around it with a little high CPU usage during failover.

Resolved In:
PR NumberSynopsisCategory: Firewall Policy
1899519
Major
SRX and MX-SPC3: While Downgrading from 25.4/24.4R2/25.2R2/25.3R1 image with address book IPV4 range config, image installation validation is failing.
Product-Group=junos
Because of a recent regression, address-book configuration with address-range can not pass pre-ISSU (or) upgrade (or) downgrade config validation.

Resolved In: junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: authd (AAA) library code
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1909013
Major
EAPOL: Interface should be deleted only after deleting MACsec on the interface in question. Applies to MPC3E only
Product-Group=junos
On MPC3, delete MACsec provisioning before deleting interface

Resolved In: evo:26.1R1-EVO
1911538
Major
Show command execution failure for show system macsec license on MX platforms.
Product-Group=junos
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SW PRs for MPC10E PlatformD
1909455
Major
RADIUS interim accounting will not work for subscribers after GRES on MX platforms with MPC10 line card
Product-Group=junos
On MX platforms with MPC10, RADIUS (Remote Authentication Dial-In User Service) interim accounting will not be working for subscribers after GRES (Graceful Routing Engine Switchover).

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:24.2R2-S2-EVO evo:25.2R1-EVO junos:22.3X60 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Category for tracking SPC3-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.

Resolved In: evo:23.2R2-S6-EVO evo:24.2R2-S4-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: PTX10K Routing Engine
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
PR NumberSynopsisCategory: KRT Queue issues within RPD
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
PR NumberSynopsisCategory: PTX10K platform-specific fabric PRs
PR NumberSynopsisCategory: MX SCBE3 specific timing and synchronization issues
1902478
Major
[Clocking Solution:MX480]:SyncE stuck in Holdover after PTP protocol alone deactivated from the G.8275.1 profile config
Product-Group=junos
In G.8275.1 Hybrid mode of operation, when PTP only is deactivated, SyncE shall not lock to the SyncE source and DPLL shall remain in Holdover state.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1806872
Critical
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash (CVE-2025-52982)
Product-Group=junos
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA100088 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S6
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1704583
Major
Change in firewall filter triggers transient traffic drops in FPC
Product-Group=junos
On all Junos MX platforms with MPC10E/MPC11E/LC9600 line cards and on MX304, change or modification in Firewall filters will trigger transient packet drops.

Resolved In: evo:23.1R1-EVO evo:23.2R1-EVO junos:22.2R3-S3 junos:22.4R3 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1887866
Minor
Incorrect uSID handling in SRv6-TE will impact the traffic path
Product-Group=junos
On MXxxx platforms with FPCs such as MPC7E/MPC8E/MPC9E/MPC10E/MPC11E/LC9600/LC480/LC4800/LC2101/LC2103 and with SRv6-TE (Segment Routing IPv6-Traffic Engineering) configured, the uSID (micro SID(Segment Identifier)) will incorrectly replace the entire last container segment instead of only the last SID. When this happens, packets will not follow the configured SRv6-TE path, which will lead to issues like missing hops in the path or packet loss.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:23.2R2-S5 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1851232
Major
JUNOS_REG:QFX10008: While performing ZTP from 24.4 "24.4I-20241124.0.2259" to "24.2R1.17", ZTP upgrade fails and unable to connect device.
Product-Group=junos
ZTP upgrade in dual RE fails if the image name has special characters.

Resolved In:
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:20.2R3-S11 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1

 

Modification History

2025-11-20 - correction. This SRN is for MX platforms only. Removed other platforms' information

First publication 2025-11-14