Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX platform series running JUNOS Software

Alert Description

Junos Software Service Release version 24.4R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.4R2-S2 is now available.

24.4R2-S2 - List of Fixed issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1900881
Major
EX2300/EX3400: TFTP installation failure
Product-Group=junos
Severity=Major
EX2300/EX3400 : TFTP install can fail with a "No device tree blob found" error
PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junos
Severity=Minor
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.
PR NumberSynopsisCategory: EX4000 Platform SW issues assignment alias
1910075
Major
EX4000: An "unknown uboot version" error may be seen sometimes during software add operation
Product-Group=junos
Severity=Major
EX4000 : "ERROR: Unknown uboot version in pkg, not saved in EFI partition during 24.4R2.25 upgrade" will be reported if any prior firmware image is not added in the device.
PR NumberSynopsisCategory: Border Gateway Protocol
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
1903829
Major
On platforms supporting BGP RIB sharding the rpd process crash is observed on both REs
Product-Group=junos
Severity=Major
On platforms supporting where BGP (Border Gateway Protocol) RIB (Routing Information Base) Sharding is configured the rpd process crashes on both REs (Routing Engines) due to route churns. This timing issue is caused when a particular internal function is used by multiple threads.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1910691
Major
Memory leak is seen during vrf add/delete when vrf-table-label is present
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with BGP sharding enabled, memory leak is observed when a vrf routing instance configured with vrf-table-label is deleted and then added back.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.
PR NumberSynopsisCategory: EX interfaces issues
1827595
Minor
Broadcom phy/EPDM SDK upgrade to version 2.3
Product-Group=junosvae
Severity=Minor
Broadcom PHY EPDM SDK has been upgraded to version 2.3 to address the port not coming up issue.
PR NumberSynopsisCategory: EX POE
1906507
Minor
False "Device Manager Failure" Alarms Observed on PoE Subsystem
Product-Group=junos
Severity=Minor
On EX2300/EX3400 platforms, The system reports false Power over Ethernet (PoE) "Device Manager failure" alarms, typically triggered by older PoE controller chips. These are not port-level or hardware issues, and connected PoE devices operate normally with correct power levels. The PoE subsystem auto-recovers, and the alarms are safe to ignore.
PR NumberSynopsisCategory: ISIS routing protocol
1906578
Minor
IS-IS FA configuration in IPv4 or IPv6 Multicast topology may cause inconsistency in routing table leading to routing loop
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms, when IS-IS IPv4 or IPv6 Multicast topology (set protocols isis topologies [ipv4-multicast | ipv6-multicast]) is configured along with IS-IS Forwarding Adjacency (FA), a separate TLV-222 is added in IS-IS LSP for each FA. This causes incorrect next-hop resolution in the routing table, potentially leading to routing loops.
PR NumberSynopsisCategory: jdhcpd daemon
1885335
Major
EX4100: irb.0 uplink network Connection lost after move the cable from fpc0 to fpc1 and remove the fpc0 from network. with fpc1 as vc new master. restart dhcpd fixed the issue after waited for 20 mins
Product-Group=junos
Severity=Major
This issue arises when the DHCP client is configured in Virtual Chassis (VC) environment, and a VC switchover is initiated by the removal of the primary FPC. MAC persistence timer feature introduces a delay in propagating the updated MAC address throughout the system. Consequently, the DHCP client continues to operate with the previous MAC address and fails to terminate and reinitialize the session using the new MAC address.
PR NumberSynopsisCategory: flow ha module
1895134
Minor
ISSU failure and process crash on primary node during HA upgrade
Product-Group=junos
Severity=Minor
On all Junos SRX platforms, performing ISSU (In-Service Software Upgrade) with the no-validate option in HA ( (High availability ) setups can cause ISSU failure and a process crash on the primary node.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1907424
Major
ICD BFD sessions fail to come up after reboot in MNHA deployments
Product-Group=junos
Severity=Major
On all SRX platform that supports Multi-Node High Availability (MNHA), Inter-Chassis Dynamic (ICD) Bidirectional Forwarding Detection (BFD) sessions fail to come up after a node reboot. This occurs because the ICD process does not receive the correct routing-instance information during boot, causing the ICD link to remain down. This is a timing issue.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1909786
Critical
EVPN traffic blackholing occurs due to incorrect ARP binding when VGA IP is used as re-ARP source
Product-Group=junos
Severity=Critical
On all Junos platforms, In Ethernet VPN (EVPN) Virtual Extensible LAN (VXLAN) deployments using Integrated Routing and Bridging (IRB) interfaces with a virtual gateway IP address and virtual gateway Media Access Control (MAC) configuration, re-ARP packets may use the virtual gateway IP as the source IP while using the IRB MAC as the source MAC. This behavior can cause connected hosts to overwrite their Address Resolution Protocol (ARP) entries, resulting in traffic being forwarded to an incorrect leaf switch in all-active Link Aggregation Group (LAG) multihoming scenarios. This may lead to intermittent or complete traffic loss for hosts connected via LAG to dual-homed leaf devices.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=junos
Severity=Minor
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1902713
Minor
The mgd process crash observed on running commit check after replace operation of groups name for apply-groups-except
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when replace operation was done on apply-groups-except object it was not clearing the entry of that object from apply-groups-info-tree, as a result 'mgd' process crash observed on commit check. There is no service impact due to this issue.

 


 

24.4R2-S2 - List of Known issues

PR NumberSynopsisCategory: NFX Layer 3 Features Software
1882713
Critical
NFX250/NFX350 Node 0 FPC0 when rebooted node fpc0 and fpc 1 doesnt come back at all
Product-Group=junos
Restart of FPC slot 0 on either node 0 or node 1 is not supported

Resolved In:
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.

Resolved In: evo:24.2R2-S4-EVO evo:24.4X200-D10-EVO evo:24.4X200-D20-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO junos:24.2R2-S4 junos:24.2X1 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2
PR NumberSynopsisCategory: BBE UP Session Manager related issues
1890895
Major
BNG Controller: Issue with changing the IP address of an active BNG user-plane
Product-Group=junos
BNG Controller: Issue with changing the IP address of an active BNG user-plane

Resolved In:
PR NumberSynopsisCategory: MX304 Routing Engine issues
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
On all VMHost platforms, the chassisd crash can be seen, which can also lead to mastership switchover. This is mainly caused by a configuration commit (no specific configuration required) followed by a reboot.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S1-J12 junos:23.2R2-S4 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R1-S3-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1886633
Major
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.
Product-Group=junos
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.

Resolved In:
PR NumberSynopsisCategory: Device Configuration Daemon
1824206
Minor
Device reboot will bring down the asi interfaces on all Junos platforms
Product-Group=junos
On all Junos platforms, there is a synchronization problem between the rdd daemon and the chassisd processes regarding the creation of ASI (Aggregated Inline Services) interfaces during system bootup that causes the chassisd to delete all interface-related configurations and thus delete the ASI interfaces from the system. Due to that, the ASI interface remains down, and it will affect only ASI interfaces, and other interfaces will not be affected by this issue.

Resolved In: evo:25.2R1-EVO junos:23.2R2-S2-J7 junos:24.4R2-S3 junos:25.2R1
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1908196
Major
All Marvell(MX, ACX): LLDP protocol goes down when 'exclude protocol LLDP' is deleted from MACsec policy attached to IFD
Product-Group=junos
With IFD MACsec configured with exclude-protocol LLDP and LLDP protocol enabled, LLDP protocol goes down when 'exclude-protocol LLDP' is deleted from MACsec connectivity association.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.

Resolved In: evo:23.4R2-S5-J28-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S7 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EX optics issues
1864715
Major
EX4100: 10g-BASE-T didn't come up after dc-pfe restart
Product-Group=junos
After multiple iterations of dc-pfe process restart, we may see interface with 10g-base-t transceiver (part# 740-123734) will not come up.

Resolved In:
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms when IPv6 filter is configured that has a match condition of source/ destination address greater than 64 bits, it results in packet drops due to transient hardware parity error that occurs on the prefix table. This will only reject what is permitted, does not allow unpermitted packets unless default term is accept and is a rare issue.

Resolved In: junos:22.3X60 junos:22.4R3-S5-J3 junos:22.4R3-S6 junos:22.4X50 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1884163
Major
IFL Memory Leak on QFX10K8/16 device
Product-Group=junos
On QFX10K8/16 , IFL memory is not freed on non-local interface of FPC during configuration changes (eg: IFL delete/deactivate) for L3IFL/L2IFL on AE/Scalar interfaces. Fix is present in common code and risky. It is a day one issue and the per IFL leak is minimal (0.00016% of total Kernel heap size) .

Resolved In: junos:22.4R3-S8 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1
PR NumberSynopsisCategory: Express ASIC interface
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
On Junos PTX5K platform with QSFP56-DD-4X100G-FR, when 15xQSFP28 PIC. Physical Coding Sublayer (PCS) error observed on the peer router side FR optics when 100G FR optics used, if more number of PCS error may possibility for network impact.

Resolved In: junos:22.3X60 junos:22.3X60-J2 junos:23.2R2-S5 junos:24.2R2-S2
PR NumberSynopsisCategory: ISIS routing protocol
1886347
Major
partial traffic drops seen on NSR switchover for Indirect route Going over L-ISIS transport route having "sensor-based-stats" configured under protocols isis
Product-Group=junos
On Junos and EVO platforms, After a Graceful Routing Engine Switchover (GRES), in New master, Indirect routes gets updated to the PFE and result in traffic loss when the transport is L-ISIS with telemetry traffic sensors enabled. In this scenario, Indirect routes going over L-ISIS route. Reason for Indirect route change is due to Underlying L-ISIS route next-hop getting changed. L-ISIS route next-hop getting changed due to ?Sensor-based-stats? configuration which does not support NSR functionality. Hence After Switchover, New Master Create sensors and Installed in the L-ISIS next-hop result in L-ISIS next-hop changed. Once L-ISIS routes nex-thop gets changed, Indirect routes under going for re-resolution which cause traffic impact.

Resolved In:
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Flow Module
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: flow ha module
1888480
Major
Backup node shows majority of sessions as active after MNHA routing restart and cold sync
Product-Group=junos
On all SRX platforms configured with Multi-Node High Availability (MNHA), a failover event triggered by ICL (Inter-Chassis) link flapping results in session state inconsistency between the nodes. During the failover, both nodes temporarily assume an Active-Active role, causing the backup node to incorrectly display a majority of sessions as active. This behavior leads to disruption of existing TCP and UDP sessions because the firewall fails to maintain correct session state during the transition.

Resolved In:
PR NumberSynopsisCategory: N/A:sw-jsr-flow-sof:
1912204
Minor
When service offload is enabled on SRX4600/SRX4700, flow sessions might keep using backup route when active route is added back
Product-Group=junos
On SRX4600/SRX4700 with service offload is enabled, flow sessions might keep using backup route when active route is added back.

Resolved In: junos:26.1R1
PR NumberSynopsisCategory: Firewall Policy
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1899519
Minor
SRX and MX-SPC3: While Downgrading from 25.4/24.4R2/25.2R2/25.3R1 image with address book IPV4 range config, image installation validation is failing.
Product-Group=junos
Because of a recent regression, address-book configuration with address-range can not pass pre-ISSU (or) upgrade (or) downgrade config validation.

Resolved In: junos:24.4R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Security platform jweb support
1916722
Minor
Software upgrade via J-Web does not work on specific SRX platforms while using Upload Package option
Product-Group=junos
The Upload Package option does not work on all non-vmhost SRX platforms ( all SRX platforms except SRX5K with SRX5K-RE3, SRX1600, SRX2300, SRX4120, SRX4300) or vSRX when J-Web is used to upgrade the software release.

Resolved In: junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S7 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: authd (AAA) library code
1860913
Major
The authd process crashes when /etc/resolv.conf file is empty
Product-Group=junos
On Junos OS Evolved ACX platforms, when DHCP (Dynamic Host Control Protocol) local server is configured without domain-name specified, the authd process crash may be observed. There will be no forwarding traffic impact due this issue, however, new DHCP client requests will not be answered.

Resolved In: evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4R2-S1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms.
Product-Group=junos
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: SW PRs for MPC10E PlatformD
1909455
Major
RADIUS interim accounting will not work for subscribers after GRES on MX platforms with MPC10 line card
Product-Group=junos
On MX platforms with MPC10, RADIUS (Remote Authentication Dial-In User Service) interim accounting will not be working for subscribers after GRES (Graceful Routing Engine Switchover).

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The em0 management interface is unreachable post switchover/rpd restart events
Product-Group=junos
On all Junos platforms with em0 disabled, the em0 port remains unreachable after performing RE switchover and re-enabling em0.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Wind River Linux Distribution issues in NG-RE
1911820
Major
Device getting stuck in boot phase during upgrade because of expired libvirt certificate
Product-Group=junos
On Junos platforms running the VMHOST system, devices are getting stuck in the boot phase during an upgrade because of expired libvirt certificate. See https://kb.juniper.net/TSB103739 [juniper.net]

Resolved In: junos:20.3X75-D442 junos:20.3X75-D46 junos:22.3X60 junos:22.3X60-J3 junos:22.3X60-J4 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:22.4X50 junos:22.4X8
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.

Resolved In: junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1849593
Major
After code upgrade to 22.4R3-S5.11 S/Ns of both the CBs are Same
Product-Group=junosvae
As part of this PR, both control boards in the router display the same serial number, which is not expected. This happened because the system was trying to read serial numbers using a specific path (0x59 address) that isn't accessible on the backup board.

Resolved In: junos:22.4R3-S5-J3 junos:22.4R3-S6 junos:22.4R3-S7 junos:22.4R3-S8 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:25.2R2 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: PTX10K platform specific fabric PRs
1870684
Major
Junos OS Evolved: OS command injection vulnerabilities fixed (CVE-2025-60006)
Product-Group=junos
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. Please refer to https://supportportal.juniper.net/JSA103163 [juniper.net] for more information.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4R2-S1-EVO evo:24.4R2-S1-J1-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MX SCBE3 specific timing and synchronization issues
1902478
Major
After the deactivation of the PTP protocol in the G.8275.1 profile configuration, SyncE remained in Holdover mode.
Product-Group=junos
In G.8275.1 Hybrid mode of operation, when PTP only is deactivated, SyncE shall not lock to the SyncE source and DPLL shall remain in Holdover state.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S7 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1806872
Critical
Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash (CVE-2025-52982)
Product-Group=junos
An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA100088 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:22.2R3-S6 junos:22.4R3-S6
PR NumberSynopsisCategory: SRX branch platforms
1895644
Minor
On Branch SRX platforms, Power button and Reset Config button do not work as expected
Product-Group=junos
On Branch SRX platforms (SRX300, SRX320, SRX340, SRX345 and SRX380), Power button and Reset Config button do not work as expected.

Resolved In: junos:24.4R2-S3 junos:25.2R2 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1704583
Major
Change in firewall filter triggers transient traffic drops in FPC
Product-Group=junos
On all Junos MX platforms with MPC10E/MPC11E/LC9600 line cards and on MX304, change or modification in Firewall filters will trigger transient packet drops.

Resolved In: evo:23.1R1-EVO evo:23.2R1-EVO junos:22.2R3-S3 junos:22.4R3 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1843602
Major
TCP session between syslog server and device remains in closed state
Product-Group=junos
On all Junos platforms, a TCP (Transmission Control Protocol) connection issue occurs between the device and syslog server after an idle period exceeding 2 hours. The session gets terminated and remains in a closed state without initiating any new session until the syslog server configuration is deleted and added again. This impacts disruption in log forwarding to the remote syslog server.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:

 

Modification History

First publication 2025-12-19