Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

SRX345 SRX380 SRX1500 running JUNOS FIPS software

Alert Description

Junos Software Service Release version 20.2R3-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For review

Solution

Junos Software service Release version 20.2R3-S11 is now available.

20.2R3-S11 - List of Fixed issues

PR NumberSynopsisCategory: Junos Node Unifier
1848754
Major
Junos OS: A low-privileged user can disable an interface (CVE-2025-52963)
Product-Group=junos
Severity=Major
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Please refer to https://supportportal.juniper.net/JSA100078 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
PR NumberSynopsisCategory: Border Gateway Protocol
1848929
Major
Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configured causes an rpd crash (CVE-2025-30652)
Product-Group=junos
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96462 [juniper.net] for more information.
1855477
Critical
Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset (CVE-2025-52953)
Product-Group=junos
Severity=Critical
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP UPDATE packet to cause a BGP session reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100059 [juniper.net] for more information.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
PR NumberSynopsisCategory: CFM
1726141
Major
Junos OS: MX Series with MPC-BUILTIN, MPC 1 through MPC 9: Receipt and processing of a malformed packet causes one or more FPCs to crash (CVE-2025-52952)
Product-Group=junos
Severity=Major
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100058 [juniper.net] for more information.
PR NumberSynopsisCategory: Device Configuration Daemon
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
PR NumberSynopsisCategory: Firewall Filter
1872347
Major
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Major
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: EVPN control plane issues
1863170
Major
Junos OS and Junos OS Evolved: In an EVPN environment, receipt of a specifically malformed BGP update causes RPD crash (CVE-2025-52949)
Product-Group=junos
Severity=Major
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100053 [juniper.net] for more information.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1718165
Major
ARP learning issues are observed post-execution of the CLI command 'clear bridge mac-table' or 'clear ethernet-switching table' in the EVPN-MPLS over IRB environment
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, L3 (Layer 3) traffic will be impacted when ARP (Address Resolution Protocol) entries get deleted for the MAC (Media Access Control) address having a bad state post execution of the CLI 'clear bridge mac-table' or 'clear ethernet-switching table' command in the EVPN-MPLS (Ethernet VPN - Multiprotocol Label Switching) over IRB (Integrated routing and bridging) environment.
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
Severity=Major
On SRX4100 and SRX4200 platforms, the ifHCOutOctets interface counter values may sometimes incorrectly spike and exceed interface speed.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
Severity=Major
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.
PR NumberSynopsisCategory: ISIS routing protocol
1778841
Major
With protocol ISIS configured, any new LSP generation triggers SPF
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, with ISIS configured, when commit or any operation that attempts for LSP generation, an SPF is triggered.
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: Firewall Policy
1847877
Major
The mgd process crash is observed during large amount of configurations
Product-Group=junos
Severity=Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
Severity=Major
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.
PR NumberSynopsisCategory: Express Chip L3 software
1583480
Major
The egress traffic might be dropped after flapping the inet6 family from the AEx bundle
Product-Group=junos
Severity=Major
In the same AE IFL of the PTX platforms with both IPv4 and IPv6 egress traffic scenario, both IPv4 and IPv6 next-hop share the same next-hop descriptor address. If flapping the inet6 family from the AEx bundle, the IPv6 next-hop might be created as IPv4 next-hop, then the egress next-hop might not be handled properly by PFE, it might cause the egress traffic to be forwarded through the IPv4 next-hop of that AE IFL, the egress packets might be dropped.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
Severity=Major
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1809740
Critical
Junos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, the rpd crashes (CVE-2025-52984)
Product-Group=junos
Severity=Critical
A Null Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device. Please refer to https://supportportal.juniper.net/JSA100090 [juniper.net] for more information.
PR NumberSynopsisCategory: Scuba fabric software
1807812
Major
MX platforms with some MPCs could run into cm_error during ungraceful SIB or Peer-FPC power off event or due to bad fabric links
Product-Group=junos
Severity=Major
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: SRX branch platforms
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1862890
Major
Junos OS and Junos OS Evolved: Device allows login for user with expired password (CVE-2025-60010)
Product-Group=junos
Severity=Major
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Please refer to https://supportportal.juniper.net/JSA103168 [juniper.net] for more details.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1807742
Critical
Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information (CVE-2025-30654)
Product-Group=junos
Severity=Critical
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Please refer to https://supportportal.juniper.net/JSA96464 [juniper.net] for more information.
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
Severity=Major
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

 


 

Extended Solution

20.2R3-S11 - List of Known issues

PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.

Resolved In: junos:23.4R2-S4-J26 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: BBE ACI VLAN related issues
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
On all Junos MX Series platforms, when running the Broadband Network Gateway (BNG) in IP packet-trigger mode, a client re-login while the dvlan( dynamic Virtual Local Area Network) is in a deleting state causes the bbe-smgd (Broadband Edge - Subscriber Management Daemon) daemon to crash and generate a core dump.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5-J8 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading
Product-Group=junos
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X60-EVO-TO-JUNOS-HELPER evo:22.4R3-S7-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.2R3-S7 junos:22.3X60 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1709837
Critical
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-D20-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D45-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.2R3-S10 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.2X33 junos:21.2X34 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:21.4R3-S7 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.3X60 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
1754935
Major
BGP multipath route is not correctly applied after changing the IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, multipath route is not correctly applied due to this Equal-cost multi-path (ECMP) will not be formed, when Border Gateway Protocol (BGP) multipath is configured and the Interior Gateway Protocol (IGP) metric of a network is modified and subsequently reverted.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:21.2R3-S6-J26 junos:21.2R3-S7-J3 junos:21.2R3-S9 junos:21.2X34 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.3R3-S2-J2 junos:22.3X60 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1 junos:24.2R2
1756603
Major
RPD process crash is seen on high scale peering scenario where the sessions are un-configured/shutdown abruptly
Product-Group=junos
The RPD process crashes on all Junos and Junos OS Evolved platforms in a highly scaled scenario of more than 2000 BGP peers if the BGP sessions are un-configured/brought down abruptly. This leads to loss of routing information and will lead to loss of protocol traffic.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S5 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
1766960
Minor
Junos OS and Junos OS Evolved: Junos OS and Junos OS Evolved: Receipt of a specific BGP UPDATE causes an rpd crash on devices with BGP multipath configured (CVE-2025-52964)
Product-Group=junos
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100080 [juniper.net] for more information.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:22.4R3-S5-EVO evo:23.2R2-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:21.2R3-S10 junos:21.4R3-S7 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3-S5 junos:22.4X50 junos:23.2R2 junos:23.2R2-J14 junos:23.4R2 junos:24.1R1 junos:24.2R1
1793714
Major
BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=junos
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.

Resolved In: evo:22.2R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.2R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-J1 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.2R1-S2 junos:25.2R2
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:22.3X60 junos:23.2R2-S5 junos:25.2R1
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".

Resolved In: evo:22.2R3-S7-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R1-S2-J10 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-J2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: BGP BMP Software
1798164
Critical
BMP reaches a state where no data is sent out to BMP Station
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), reaches a state where no data is sent out to BMP Station. This is an unexpected behaviour.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R2-S1-J10-EVO evo:23.4R2-EVO evo:23.4R2-S2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S3-J32 junos:21.2R3-S6-J26 junos:21.2R3-S8 junos:21.4R3-S9 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3-S2-J5 junos:22.4R3-S3 junos:22.4X50 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: BGP Segment Routing
1648377
Major
The rpd process crashes when BGP-LU with the prefix-sid attribute is enabled in Segment Routing scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms supporting Border Gateway Protocol Labeled Unicast (BGP-LU), if the bgp-prefix-sid attribute is enabled in a Segment Routing (SR) scenario, when two prefixes use the same prefix-sid at the same time, the rpd process will crash.

Resolved In: evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: BBE Remote Access Server
1822300
Major
Junos OS and Junos OS Evolved: Vulnerability in the RADIUS protocol for Subscriber Management (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Improper Validation of Integrity Check Value and Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in subscriber services of Juniper Networks Junos OS and Junos OS Evolved allows an on-path attacker between a RADIUS server and the RADIUS client to bypass authentication. Please refer to https://supportportal.juniper.net/JSA100056 [juniper.net] for more information.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S1-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S10 junos:21.4R3-S11 junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:23.2R2-S6 junos:23.4R2-S5-J21 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.

Resolved In: junos:23.4R2-S2-J16 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1853294
Major
Packet loss observed across multiple traffic items using SR profiles within the L3VPN
Product-Group=junos
On ACX5448 and ACX710 platforms under L3VPN (Layer 3 Virtual Private Network) deployment using OSPF (Open Shortest Path First) or BGP (Border Gateway Protocol), when traffic is forwarded over SR (Segment Routing) profiles, packet loss is observed across multiple traffic items.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S2-J16 junos:23.4R2-S5 junos:23.4R2-S7 junos:24.2R2 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1841965
Major
RPD core-dump on 22.2R3-S4
Product-Group=junos
RPD core occurs when we have an L3 instance (instance type: VRF) and an L2 instance for EVPN (instance type: MAC-VRF) with duplicate MAC detection enabled.

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1894803
Major
Inconsistency is observed between the ARP table and Mac-IP-table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming failover scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby), the ARP (Address Resolution Protocol) and MAC-IP tables on Provider Edge (PE) devices may not update simultaneously during a failover event. This timing discrepancy can result in temporary traffic disruption until the tables are refreshed.

Resolved In: evo:23.4R2-S5-J28-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1802464
Major
VXLAN/EVPN ip-address for mac-address in forwarding table in hold state
Product-Group=junos
Once receiving the same route as Type 2 and Type 5, the address entry might be stuck in hold state once remote peer restarts. The recovery is simply to clear the mac-ip table on the remote side with 'clear ethernet-switching mac-ip-table or bounce the BGP peer. This race condition is corrected.

Resolved In: evo:22.2R3-S4-EVO evo:22.4R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S8 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: ISIS routing protocol
1696598
Major
Wrong SRTE Secondary path weight makes the secondary path active in forwarding table
Product-Group=junos
On all Junos and Junos Evolved platforms, SRTE (Segment Routing Traffic Engineering) Secondary LSP (Label Switched Path) should be only on standby in the forwarding table however it is also active and forwarding traffic due to the wrong metric calculation.

Resolved In: evo:21.2R3-S5-EVO evo:21.4R3-S3-EVO evo:22.2R3-EVO evo:22.3R2-EVO evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S3 junos:22.1R3-S1 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:22.4R3-S8 junos:23.1R1
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4X3 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.3R1
PR NumberSynopsisCategory: Flow Module
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: SRX PFE side multicast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
On Junos OS SRX platforms with Generic Routing Encapsulation (GRE) over a Secure Interface Tunnel (st0) is configured, if the st0 interface flaps, the GRE tunnel comes up before the st0 interface(which is due to a timing issue), results in a mismatch in the hash values between session packets and the GRE tunnel, which will cause traffic drop.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.

Resolved In: junos:21.4R3-S12 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform flowd process is generating crash files.
Product-Group=junos
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.

Resolved In: junos:21.4R3-S12 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.4R1 junos:25.1R1
1841364
Major
The kmd process crash is seen on random number generation by the third-party library API
Product-Group=junos
On Junos and Junos evolved platforms on rare circumstances when device is busy kmd process crash is seen on random number generation used for VPN negotiation by the third-party library API.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.4R1 junos:25.1R1
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.

Resolved In: junos:21.4R3-S12 junos:22.2R3-S7 junos:23.2R2-S6 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: Layer 2 Circuit issues
1863228
Major
IFL configured on the LAG interface goes down when the VLAN operation is changed
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, when EVPN is configured with the 'df-election-granularity per-esi' feature, any change in VLAN operation causes the IFL (logical interface) configured on the LAG (Link Aggregation Group) interface to go down, impacting all services associated with that interface.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S1-J15 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1607372
Critical
The fxpc process might crash and generate a core file
Product-Group=junos
On EX and QFX Series switches (which use Broadcom chips), the fxpc process might crash and generate a core file (or dump file) due to Layer 2 Address Learning Manager (L2ALM) parallel processing.

Resolved In: evo:21.2R2-EVO evo:21.3R1-EVO evo:21.4R1-EVO junos:20.3R3-S4 junos:20.3X75-D40 junos:20.4R3 junos:20.4R3-S5 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1789663
Major
Unexpected rpd crash when huge amount of telemetry data is being streamed
Product-Group=junos
On Junos and Junos Evolved platforms with telemetry enabled, in escenarios where huge amount of data is being streamed, when streaming data crosses the limit (i.e size based defer limit is at 15kb and time-based defer limit 100 ms) there will be a defer and continue. If configuration changes occur during this deffering state that affected the last streamed XPath (the specific data path being monitored), it will cause rpd (routing protocol deamon) to crash causing traffic drop and core file will be generated. No workaroung is provided, rpd will restart automatically.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2-S6 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1678431
Major
Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash (CVE-2024-21613)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75754 [juniper.net] for more information.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3B1-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.4R3-S13 junos:20.3X75-D35 junos:20.3X75-D42 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S3 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:24.2R2-S2-EVO evo:25.2R1-EVO junos:22.3X60 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.

Resolved In: evo:22.3X50-EVO evo:23.2R2-S4-J2-EVO evo:23.2R2-S5-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.2R3-J10 junos:22.4R3-S7-J1 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
In stressful conditions, FPC crash observed and core file generated when PKID (public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured.

Resolved In: junos:21.4R3-S12 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X9 junos:24.2R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1694798
Minor
On MX Series Routers, subscriber login failures with DHCPv6 over PPPoE
Product-Group=junos
On MX series devices, subscriber login failures and scaling limitations were observed in high-scale PPPoE(Point-to-Point Protocol over Ethernet) dual-stack deployments using DHCPv6( Dynamic Host Configuration Protocol version 6). This issue occurred when subscriber sessions attempted to re-login immediately after termination, causing a flow conflict in the Packet Forwarding Engine (PFE).

Resolved In: evo:23.2R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J15 junos:22.4R3-S9 junos:23.2R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring EVPN PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
On Junos OS and Junos OS Evolved platform, Ethernet Virtual Private Network (EVPN) pseudowire (PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, potentially causing routing and forwarding failures.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S9 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667
Major
The rpd process and chassisd process crash is seen
Product-Group=junos
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S2-J2 junos:22.3R3-S3 junos:22.3X60 junos:22.3X80-D45-JUNOS-TO-EVO-HELPER junos:22.4R3-J6 junos:22.4R3-S1 junos:22.4R3-S7 junos:22.4X50 junos:23.2R1-S1-J7 junos:23.2R2 junos:23.2R2-J14 junos:23.2R2-S4 junos:23.4R1 junos:23.4R2 junos:23.4R2-S4 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1842654
Major
RPD process crash observed with dynamic tunnel configuration with overlap in destination networks under APP based and NHB mode and rollback
Product-Group=junos
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) process will crash when dynamic tunnels are configured with overlap in destination networks under APP (Application-based tunnels) based and NHB (Next Hop Based) mode and rollback after some time.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:21.4R3-S3-J16 junos:22.4R2-S2-J9 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.

Resolved In: evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:25.2R1 junos:25.3R1
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4R2-S1-J1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:20.3X75-D441 junos:20.3X75-D442 junos:20.3X75-D52 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth may be admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
If Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: all ipv6 flow bugs on srx platforms
1807541
Major
SRX4600 with SOF is observed to continue sending ipv6 traffic out a downed member link.
Product-Group=junos
If a bundled member link is removed either physically (cable disconnection) or by configuration (admin down), it may be observed that ipv6 traffic is continuing to send out that downed link.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1 junos:25.3R1
PR NumberSynopsisCategory: security-intelligence feature on SRX
1607810
Major
SecIntel Intelligence process crashes when the traffic source IP or destination IP hits Blacklist IP
Product-Group=junos
On SRX platforms, a SecIntel Intelligence process restarts unexpectedly results in traffic impact when the traffic source IP or destination IP hits Whitelist IP / Blacklist IP /CC IP / Infected host IP. The issue happens when SecIntel Intelligence is configured, and Whitelist IP / Blacklist IP /CC IP / Infected host IP feed entries are present.

Resolved In: junos:19.4R3-S13 junos:20.4R3-S9 junos:21.1R3 junos:21.2R3 junos:21.2R3-S6 junos:21.2X32 junos:21.3R1 junos:21.3R2 junos:21.4R1 junos:22.1R3-S4
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1897579
Minor
Packet drops are observed on SRX380 platforms in packet mode
Product-Group=junos
On Junos OS SRX380 (cluster/standalone) platforms in packet mode, when L2 (Layer 2) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. Please refer to https://supportportal.juniper.net/JSA100096 [juniper.net] for more information.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S5-EVO evo:23.4X100-D31-EVO evo:24.2R2-S1-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2X42 junos:20.3X75-D36 junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:21.2R3-S10 junos:21.2X32-D30 junos:21.4R3-S11 junos:21.4R3-S11-X1 junos:21.4X12 junos:21.4X12-X1 junos:22.2R3-S7 junos:22.3X60 junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:22.4X50 junos:23.2R2-S3-C21 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R2-S1 junos:24.2X1 junos:24.4R1-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1514927
Critical
Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor (CVE-2025-59957)
Product-Group=junos
An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system. Please refer to https://supportportal.juniper.net/JSA103146 [juniper.net] for more information.

Resolved In: evo:22.3R1-EVO junos:20.3X75-D441 junos:21.4R3 junos:21.4R3-S6 junos:22.2R3-S3 junos:22.3R1 junos:23.4R2 junos:24.2R2 junos:24.3R1
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:23.2R2-S5-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S3-J23 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: usf ipsec related issues
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1

 

Modification History

First publication 2025-11-19