Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX4300 SRX5000s

Alert Description

Junos Software Service Release version 21.4R3-S12 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review

Solution

Junos Software service Release version 21.4R3-S12 is now available.

21.4R3-S12 - List of Fixed issues

PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: MX YT-ZF Linecards Timing software
1644984
Major
Duplicate data elements reported in 'show chassis synchronization clock-module' xml command.
Product-Group=junos
Severity=Major
XML tag details are modified
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
Severity=Major
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading
Product-Group=junos
Severity=Major
RPD might crash when upgrading and NOT using no-validate. Use no-validate to avoid the crash.
PR NumberSynopsisCategory: Border Gateway Protocol
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
Severity=Major
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the CLI (Command Line Interface) command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: CFM
1726141
Major
Junos OS: MX Series with MPC-BUILTIN, MPC 1 through MPC 9: Receipt and processing of a malformed packet causes one or more FPCs to crash (CVE-2025-52952)
Product-Group=junos
Severity=Major
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100058 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Filter
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
1872347
Major
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Major
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
Severity=Major
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1874476
Major
Transient traffic loss for CE in an EVPN MPLS setup with Multi-Homing
Product-Group=junos
Severity=Major
On Junos and Junos Evolved platforms with EVPN MPLS, Multi-Homing scenarios, when there is a Multi-Homing peer node reboot, the destination route entries that were learned locally on IRB(Integrated Routing and Bridging) interface of rebooted node get deleted on other multi-homing peers without RE-ARP (Routing Engine-Address Resolution Protocol) causing transient traffic loss for CE (Customer Edge) traffic.
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*
PR NumberSynopsisCategory: EX interfaces issues
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
PR NumberSynopsisCategory: EX4400 PFE software
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
Severity=Major
On QFX5000 series and EX4000 series platforms running Junos Operating System (OS), during normal operation, the fxpc process crashes due to a routing entry continues to reference a HOLD next-hop after the associated topology neighbor has already been removed by the system causing the Flexible Physical Interface Card (PIC) Concentrator (FPC) to reboot and generate a crash file.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
Severity=Major
On SRX4100 and SRX4200 platforms, the ifHCOutOctets interface counter values may sometimes incorrectly spike and exceed interface speed.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
Severity=Major
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.
PR NumberSynopsisCategory: Flow Module
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
Severity=Major
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.
PR NumberSynopsisCategory: SRX PFE side multicast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Severity=Major
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
Severity=Major
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
Severity=Major
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.
PR NumberSynopsisCategory: Firewall Policy
1847877
Major
The mgd process crash is observed during large amount of configurations
Product-Group=junos
Severity=Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1895686
Minor
License installation failure when adding license using agile licensing infra on EX4300 platforms
Product-Group=junos
Severity=Minor
On EX4300 platforms, error messages are seen and license will not be installed when license is added using agile licensing infra. The features based on this license will not be enabled when license installation fails.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1727066
Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
Product-Group=junos
Severity=Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1849296
Minor
The self-generated traffic on Junos platforms use the incorrect source IP with ECMP configuration
Product-Group=junos
Severity=Minor
On all Junos platforms configured with Equal-Cost Multi-Path (ECMP) routing, self-generated traffic selects an incorrect source (Internet Protocol) IP address. As a result, the peer device lacks the relevant route information, causing self-generated traffic to be dropped. This issue is specific to ECMP configurations and does not impact data traffic.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Express Chip L3 software
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
Severity=Major
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1694798
Minor
On MX Series Routers, subscriber login failures with DHCPv6 over PPPoE
Product-Group=junos
Severity=Minor
On MX series devices, subscriber login failures and scaling limitations were observed in high-scale PPPoE(Point-to-Point Protocol over Ethernet) dual-stack deployments using DHCPv6( Dynamic Host Configuration Protocol version 6). This issue occurred when subscriber sessions attempted to re-login immediately after termination, causing a flow conflict in the Packet Forwarding Engine (PFE).
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
Severity=Major
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.
PR NumberSynopsisCategory: QFX L2 PFE
1850203
Minor
Duplication of DHCP request packets when unicast to VRRP gateway
Product-Group=junos
Severity=Minor
On Junos QFX5100, QFX5110, QFX5120, QFX5200, QFX5210, EX4100, EX4000, EX4400 and EX4300-48MP platforms, when a client sends a single DHCP (Dynamic Host Configuration Protocol) request, the switch generates and forwards two DHCP request messages to the VRRP (Virtual Router Redundancy Protocol) gateway. This behaviour causes the client to fail to renew its IP address, resulting in a loss of network connectivity.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
Severity=Major
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
Severity=Major
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
Severity=Major
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1847904
Major
CTLE Values mismatch for 100G-BASE-SR4/100G-BASE-SR4-T2 in QFX5120-48T
Product-Group=junosvae
Severity=Major
The CTLE for 100G-BASE-SR4/100G-BASE-SR4-T2 is set wrong value on QFX5120-48T platform.
PR NumberSynopsisCategory: RPD Interfaces related issues
1842546
Major
Memory leak is detected when interfaces are configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, 72-byte size memory leak is seen when interface configuration is added. But there is no traffic impact due to this issue.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1810622
Major
Junos OS and Junos OS Evolved: With traceoptions enabled, receipt of malformed AS PATH causes RPD crash (CVE-2025-52946)
Product-Group=junos
Severity=Major
A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BGP update with a specifically malformed AS PATH to cause rpd to crash, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100050 [juniper.net] for more information.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
Severity=Major
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.
PR NumberSynopsisCategory: Scuba fabric software
1807812
Major
MX platforms with some MPCs could run into cm_error during ungraceful SIB or Peer-FPC power off event or due to bad fabric links
Product-Group=junos
Severity=Major
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: all ipv6 flow bugs on srx platforms
1807541
Major
SRX4600 with SOF is observed to continue sending ipv6 traffic out a downed member link.
Product-Group=junos
Severity=Major
If a bundled member link is removed either physically (cable disconnection) or by configuration (admin down), it may be observed that ipv6 traffic is continuing to send out that downed link.
PR NumberSynopsisCategory: SRX branch platforms
1877428
Major
Stale user session displayed in "show system users" after ssh session disconnected.
Product-Group=junos
Severity=Major
On all platforms running FreeBSD6, such as the SRX3xx or QFX5100 series, once an SSH session is disconnected, the stale user entry may still be displayed in "show system users" or still counted in hrSystemNumUsers OID.
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
Severity=Major
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
Severity=Major
On all Junos MX with MPC10, MPC11, MX304 and EX92K platforms, when Integrated routing and bridging (IRB) interface is configured over Aggregate Ethernet (AE), the packet is received on an l3 IRB which is processed through a filter based forwarding (FBF) which forwards the traffic over an IRB which has an underlay as L2 AE interface. When the packet is forwarded over the l2 AE, the packet gets dropped because the egress PFE calculation is incorrect resulting in a traffic drop.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1771132
Major
Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed (CVE-2025-59980)
Product-Group=junos
Severity=Major
An Authentication Bypass by Primary Weakness in the File Transfer Protocal (FTP) server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. Please refer to https://supportportal.juniper.net/JSA103167 [juniper.net] for more details.
1842518
Major
The device become unresponsive in a race condition due to maximum process (maxproc) limit
Product-Group=junos
Severity=Major
On all Junos/Junos OS Evolved platforms, the device becomes unresponsive due to management (mgd) processes being stuck in a deadlock. This leads to the piling up of mgd processes, which eventually exhausts the maximum process limit (maxproc) on the device. The impact is that the device will become unusable due to the maxproc limit being reached.
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
Severity=Major
On all MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.

 

Extended Solution

21.4R3-S12 - List of Known issues

PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junosvae
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4B1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junosvae
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.

Resolved In: junos:22.4R3-S11 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
User traffic drops are observed on the CVLAN interfaces
Product-Group=junos
On Junos OS EX and QFX5K platforms with software-based MAC address learning enabled through interface-level MAC-limit or MAC-move-limit, user traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa due to changes in the Class of MAC Learning (CML) flag values.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: NFX Layer 3 Features Software
1776216
Major
IPsec Tunnel behind NAT stops passing traffic when the NAT port Number or IP address changes
Product-Group=junos
On Junos SRX and NFX series platforms, when the peer device located behind a Network address translation (NAT) device, experiences a change in the NAT port number or Internet Protocol (IP) address, the next Dead Peer Detection (DPD) or rekey process fails to update the port number in the existing tunnel NAT Traversal (NAT-T) flow session if the DPD "always-send" is being configured. This leads to communication failure over the Internet Protocol Security (IPsec) tunnel.

Resolved In: junos:22.4R3-S2 junos:23.2R2-S6 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1688613
Major
Telemetry sensor will not stream data if using key value as wildcard '*' character for gNMI in the PFE supported sensor
Product-Group=junos
On MX platforms, when key value as wildcard '*' character for gNMI (gRPC Network Management Interface) in the PFE supported sensor is used, the telemetry sensor will not stream any data.

Resolved In: evo:22.3X80-D30-EVO evo:22.3X80-D45-EVO evo:23.1R1-EVO junos:22.4R3-S8 junos:23.1R1
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.

Resolved In: junos:23.4R2-S4-J26 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: BBE ACI VLAN related issues
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
On all Junos MX Series platforms, when running the Broadband Network Gateway (BNG) in IP packet-trigger mode, a client re-login while the dvlan( dynamic Virtual Local Area Network) is in a deleting state causes the bbe-smgd (Broadband Edge - Subscriber Management Daemon) daemon to crash and generate a core dump.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5-J8 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1756603
Major
RPD process crash is seen on high scale peering scenario where the sessions are un-configured/shutdown abruptly
Product-Group=junos
The RPD process crashes on all Junos and Junos OS Evolved platforms in a highly scaled scenario of more than 2000 BGP peers if the BGP sessions are un-configured/brought down abruptly. This leads to loss of routing information and will lead to loss of protocol traffic.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S5 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
1793714
Major
BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=junos
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.

Resolved In: evo:22.2R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:22.2R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-J1 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.2R1-S2 junos:25.2R2
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".

Resolved In: evo:22.2R3-S7-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.

Resolved In: evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R1-S2-J10 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.

Resolved In: evo:23.2R2-S6-EVO evo:24.4R2-S2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-J2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1909599
Major
Bgp prefixes get stuck in output queue forever, with bgp delay-route-advertisements and route-ack-converge feature enabled
Product-Group=junos
bgp prefixes doesn't get advertise and stuck forever in the output queue, with bgp delay-route-advertisements and route-ack-converge feature enabled

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1854658
Major
The chassisd process crashes when commit command is issued multiple times
Product-Group=junos
On Junos VMhost platforms, when commit command is issued 50-60 times in a minute, this leads to ssh session exhaustion and slow response which causes configuration commit delays and subsequently leads to a chassisd process crash and restart causing FPC restart.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S5 junos:24.2R2-S1 junos:24.2R2-S3 junos:24.4R1-S3-J1 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
On all VMHost platforms, the chassisd crash can be seen, which can also lead to mastership switchover. This is mainly caused by a configuration commit (no specific configuration required) followed by a reboot.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S1-J12 junos:23.2R2-S4 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R1-S3-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:23.2R2-S6 junos:23.4R2-S5-J21 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.

Resolved In: junos:23.4R2-S2-J16 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1853294
Major
Packet loss observed across multiple traffic items using SR profiles within the L3VPN
Product-Group=junos
On ACX5448 and ACX710 platforms under L3VPN (Layer 3 Virtual Private Network) deployment using OSPF (Open Shortest Path First) or BGP (Border Gateway Protocol), when traffic is forwarded over SR (Segment Routing) profiles, packet loss is observed across multiple traffic items.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S2-J16 junos:23.4R2-S5 junos:23.4R2-S7 junos:24.2R2 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.

Resolved In: evo:23.4R2-S5-J28-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EX interfaces issues
1789999
Major
[interfaces]:Ex-Hardening:Local/Remote fault insertion from TG is failing
Product-Group=junos
Ex-Hardening:Local/Remote fault insertion from TG is failing

Resolved In:
PR NumberSynopsisCategory: EX POE
1876675
Major
On EX4100/EX4400s platforms PoE powered devices connected do not come up when adding a second power supply unit
Product-Group=junos
On EX4100/EX4400s platforms using Perpetual PoE and Fast PoE, if power is lost due to one PSU (Power Supply Unit) being removed and the system shuts down, the PoE-powered devices will not automatically power back on when the system is restarted using the other PSU (e.g., switching from slot 0 to slot 1 or vice versa).

Resolved In: junos:22.4R3-S8 junos:23.2R2-S6 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms when IPv6 filter is configured that has a match condition of source/ destination address greater than 64 bits, it results in packet drops due to transient hardware parity error that occurs on the prefix table. This will only reject what is permitted, does not allow unpermitted packets unless default term is accept and is a rare issue.

Resolved In: junos:22.3X60 junos:22.4R3-S5-J3 junos:22.4R3-S6 junos:22.4X50 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Express ASIC interface
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
On Junos PTX5K platform with QSFP56-DD-4X100G-FR, when 15xQSFP28 PIC. Physical Coding Sublayer (PCS) error observed on the peer router side FR optics when 100G FR optics used, if more number of PCS error may possibility for network impact.

Resolved In: junos:22.3X60 junos:22.3X60-J2 junos:23.2R2-S5 junos:24.2R2-S2
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S1-J8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ISIS routing protocol
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.

Resolved In: junos:22.4R3-S10 junos:22.4R3-S9 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.3R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
On Junos OS SRX platforms with Generic Routing Encapsulation (GRE) over a Secure Interface Tunnel (st0) is configured, if the st0 interface flaps, the GRE tunnel comes up before the st0 interface(which is due to a timing issue), results in a mismatch in the hash values between session packets and the GRE tunnel, which will cause traffic drop.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform flowd process is generating crash files.
Product-Group=junos
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1889298
Major
On SRX devices running Multi-Node High Availability (MNHA), the iked process crashed due to repeated negotiation failures, which led to a VPN outage.
Product-Group=junos
On SRX devices running Multi-Node High Availability (MNHA) and IPSec, the IKED process may crash due to a high number of unsuccessful VPN negotiations. To restore the VPN environment, the active node must be rebooted.

Resolved In: junos:22.4R3-S5-J6 junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1789663
Major
Unexpected rpd crash when huge amount of telemetry data is being streamed
Product-Group=junos
On Junos and Junos Evolved platforms with telemetry enabled, in escenarios where huge amount of data is being streamed, when streaming data crosses the limit (i.e size based defer limit is at 15kb and time-based defer limit 100 ms) there will be a defer and continue. If configuration changes occur during this deffering state that affected the last streamed XPath (the specific data path being monitored), it will cause rpd (routing protocol deamon) to crash causing traffic drop and core file will be generated. No workaroung is provided, rpd will restart automatically.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2-S6 junos:24.2R1 junos:24.2R2 junos:24.3R1
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms.
Product-Group=junos
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Odin Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
em0 mgmt port is unreachable after RE switchover
Product-Group=junos
On MX10008 with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.2R3-S10 junos:21.2R3-S9-J5 junos:23.4R2-S5-J23 junos:23.4R2-S6-J2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1698894
Major
The communication between primary and backup Routing Engines breaks in the event of scale network churn
Product-Group=junos
On PTX Series routers and QFX Series switches with dual Routing Engines running Junos OS, high host-bound traffic can cause a memory issue. Because of low memory, the Address Resolution Protocol (ARP) entry add can fail. Due to this, the communication between the primary Routing Engine and backup Routing Engine breaks, causing redundancy failure in high network churn and GRES-enabled scenario.

Resolved In: junos:20.3X75-D50 junos:21.2R3-S5 junos:22.2R3-S3 junos:22.4R3-S6-J12 junos:22.4R3-S7-J1 junos:22.4X8 junos:23.1R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1841548
Minor
The "show system core-dumps | display json" OR "get-system-core-dumps" will give an invalid JSON output
Product-Group=junos
On all Junos platforms, "show system core-dumps | display json" or "get-system-core-dumps" will give an invalid JSON output. The crash files will not be displayed in JSON format.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1 junos:25.1R1
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.

Resolved In: junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
On Junos OS and Junos OS Evolved platform, when router-advertisement is enabled on Pseudowire Subscriber(PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, causing routing and forwarding failures.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S9 junos:24.2R2 junos:24.4R1 junos:25.1R1
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1807037
Major
BGP backup routes are installed as primary routes after enabling 'protect core' feature
Product-Group=junos
On all Junos and Junos OS Evolved platforms when Border Gateway Protocol (BGP) multipath is enabled for Layer 3 Virtual Private Network (L3VPN) routes and 'protect core' is enabled on the Virtual Routing and Forwarding (VRF) instance, the backup BGP path is installed as primary path. The Next hop weight value is not updated correctly, it is weight 0x1 instead of weight 0x4000 for the backup.

Resolved In: evo:22.4R3-S9-EVO evo:23.4R2-S1-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:23.2R2-S6 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Scuba fabric software
1811474
Major
In Junos MX platforms specifically MX2010 and MX2020 with SFB2 Fabric installed replacing MPC9E linecards with MPC6E linecards results in all SFB2 fabric get into check state and FPCs becomes destination error and offline
Product-Group=junos
On Junos MX platforms specifically MX2010 and MX2020 with SFB2 (Switch Fabric Board) Fabric installed, after inserting and powering on a new MPC6E in slot (swapping specifically with MPC9E linecard), fabric get into check state and all FPCs goes as unreachable destinations and gets offlined. Due to this, traffic loss can occur.

Resolved In: junos:20.3X75-D46 junos:21.2R3-S9 junos:22.2R3-J11 junos:22.2R3-J9 junos:22.4X4 junos:23.2R2-S2-J2 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1869450
Major
Subscribers failed to establish DS-Lite softwires due to stale softwire entries
Product-Group=junos
On Junos MX Series platforms using MS-MPC or MX-SPC3 line cards with DS-Lite softwires subscriber services and the session-limit-per-prefix option enabled, the softwire extension reference count will not be properly decremented during subscriber session teardown. These stale softwire entries cause traffic failures when the same subscriber connects to a different AFTR (Address Family Transition Router). This will not impact new subscriber sessions with any AFTR, nor will it affect existing subscriber sessions with the same AFTR.

Resolved In: junos:22.4R3-S7-J2 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SRX branch platforms
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S4 junos:24.4R2-S2 junos:25.2R2
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1812276
Major
Persistent link error in one fabric plane towards some PFE could causes traffic blackholing from non-native LC PFE towards that remote PFE over all fabric planes
Product-Group=junos
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D46 junos:22.2R3-S3-J3 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S9 junos:22.4X4 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
On MX304 routers acting as LNS, an FPC restart and aftd-trio core may occur if a MIC is offlined (LMIC OIR) while the service-device pool of SI interfaces spans both MICs on the same FPC. This may result in transient loss of subscriber sessions and service impact.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1897464
Major
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
On all Junos OS platforms, the Cassis-alloc memory allocator fails to allocate memory in rare cases. This issue occurs when the system rounds up memory requests (for example, from 256 units to 512), but the allocation failure handling logic only considers the original requested size. Although extremely uncommon, this mismatch leads to repeated allocation failures on most of the FPCs, which leads to traffic drops and complete service impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:21.2R3-S10 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/ EX9200/EX9204/EX9208/ EX9214/ EX9251/EX9253/ SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S6-J2 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe multicast software
1686068
Major
Disabling PFE triggers the memory leak which may cause FPC to crash
Product-Group=junos
On Junos MX platforms with specific line cards, when PFE (Packet Forwarding Engine) is disabled, scenarios like multicast receiver join/leave that result in allocation and de-allocation of memory on disabled PFE can cause a memory leak. This is because memory is allocated on the disabled PFE, but not freed.

Resolved In: evo:22.4R3-EVO evo:23.2R1-EVO junos:20.3X75-D52 junos:21.2R3-S5 junos:22.2R3-S3 junos:22.4R3 junos:23.2R1
PR NumberSynopsisCategory: Trio ASICXMCHIP Software
1804710
Minor
Ungraceful power off of an FPC in a system having more than one FPC results in PFE disable due to self-ping timeout
Product-Group=junos
On MXxxx/SRXxx/EXxx platforms with more than one FPC ((Flexible PIC (Physical Interface Cards) Concentrators)) slot and equipped with certain FPCs such as MPC3E/MPC4E/MPC2E-3D-NG/MPC3E-3D-NG/MPC5E/MPC6E/EX9200-4QS/EX9200-2C-8XS/EX9200-MPC/EX9200-32XS/EX9200-6QS/SRX5K-SPC-4-15-320/SRX5K-MPC3-100G10G/SRX5K-MPC3-40G10G/SRX5K-MPC, one or more PFEs (Packet Forwarding Engine) are disabled due to fabric self ping timeout when a peer FPC goes down ungracefully (for e.g. due to power/voltage or board fault or because of removal without first being offlined). As a result, there is traffic impact until the traffic is re-routed to an alternate path (PFE disable results in all WAN (Wide Area Network) interfaces going down).

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S3-J3 junos:22.4R3-S5 junos:22.4X4 junos:23.2R2-S4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:20.2R3-S11 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:23.2R2-S5-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: VMHOST platforms software
1819412
Major
Junos OS: After removing SSH public key authentication root can still log in (CVE-2025-52983)
Product-Group=junos
A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device. Please refer to https://supportportal.juniper.net/JSA100089 [juniper.net] for more information.

Resolved In: evo:22.2R3-S7-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO junos:22.2R3-S7 junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S3 junos:23.4X30-D30 junos:24.2R1-S2 junos:24.2R2 junos:24.2X1 junos:24.4R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1844731
Critical
High heap memory caused MX-SPC3 PIC to go offline
Product-Group=junos
On Junos platforms, specifically MX240, MX480 and MX960 supporting MX-SPC3 service cards, if inline-jflow is configured with huge scaled routes (~4M routes) resulting in kernel memory exhaustion that is high Heap Memory and SPC3 Pic goes offline.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S6 junos:23.2R2-S4 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

Resolved In: junos:22.4R3-S8 junos:22.4X6 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

Resolved In: evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S5-J32 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1

 

Modification History

First publication 2025-12-05