Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 25.2R1-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 25.2R1-S2 is now available.

25.2R1-S2 - List of Fixed issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1900881
Major
EX2300/EX3400: TFTP installation failure
Product-Group=junos
Severity=Major
EX2300/EX3400 : TFTP install can fail with a "No device tree blob found" error
PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junos
Severity=Minor
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.
PR NumberSynopsisCategory: ISSU
1900759
Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
Product-Group=junos
Severity=Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
Severity=Major
On Junos OS EX2300, EX3400, EX4100, EX4400, EX4650, EX4000 and QFX5K platforms with software-based MAC (Media Access Control) address learning enabled through interface-level MAC-limit or MAC-move-limit, the traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa.
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
Severity=Major
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.
PR NumberSynopsisCategory: Border Gateway Protocol
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
Severity=Major
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1909599
Major
BGP prefixes get stuck in output queue forever, with BGP delay-route-advertisements and route-ack-converge feature enabled
Product-Group=junos
Severity=Major
BGP(Border Gateway Protocol) prefixes doesn't get advertise and stuck forever in the output queue, with BGP delay-route-advertisements and route-ack-converge feature enabled.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: Firewall Filter
1903047
Minor
Intermittent traffic loss after pfe reset due to FLT filters
Product-Group=junos
Severity=Minor
On all Junos MX platforms with line cards MPC7/8/9 (EA Asic) , if any PFE restarts as part of any encountered CM Error defects, then fast-lookup-table filters will not work properly and traffic black holing will be seen.
PR NumberSynopsisCategory: CoS support on DNX
1897336
Major
ARP resolution and device discovery failure is observed due to unexpected VLAN tags on ARP replies
Product-Group=junos
Severity=Major
On ACX710 and ACX5448 platforms, due to VLAN edit profile remapping and VLAN translation, all the packets are getting VLAN-tagged. The RE ( Routing Engine ) drops ARP ( Address Resolution Protocol ) reply packets that contain VLAN ( Virtual Local Area Network ) tags, if the interface encapsulation was set to ethernet-ccc and VLAN configuration was removed. As a result, ARP resolution fails, leading to ping and device discovery failure.
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908719
Major
On all mx platforms chassid gets stuck and becomes unresponsive it resumes only after restarting both control units
Product-Group=junos
Severity=Major
On MX devices, the sub-linecard feature with MPC11 cards. When this feature is used, the main system process can sometimes freeze, which may lead to system crashes and error logs.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.
1914423
Major
On-change telemetry events dropped when l2ald telemetry queue memory limit is not configured
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when l2-learning telemetry is enabled without explicitly configuring a memory limit for the l2ald (Layer 2 Address Learning Daemon) telemetry queue, the default memory limit is not applied. As a result, all on-change telemetry events are dropped.
PR NumberSynopsisCategory: Lacp related problems and issues.
1898531
Major
AE interfaces flap during GRES following an RE reboot on all Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, Aggregate Ethernet (AE) interfaces with LACP configured will experience a flap due to a timing issue when Graceful Routing Engine Switchover (GRES) is performed after a Routing Engine (RE) reboot, resulting in traffic loss during the flap.
PR NumberSynopsisCategory: eventd, syslog infra issues
1909267
Minor
Enable syslogging of all shells under Evo (feature parity with Junos)
Product-Group=junos
Severity=Minor
To improve our security posture, Junos Evo will now send all interactive shell commands to syslog for auditing purposes. This is to maintain feature parity with Junos. The syslogs will go to LOG_INTERACTIVE facility with LOG_INFO level. This is similar to how all CLI commands are logged as well.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1884781
Major
Slow configuration commit observed on devices with a single Routing Engine (RE)
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms with single RE and the system type is cluster, a commit delay is observed when operating with a single RE. This occurs because the system attempts to synchronize with the second RE by default, but since it's not present, the process waits and causes the delay in commit.
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
PR NumberSynopsisCategory: EX4100 PFE
1905783
Major
FXPC core dumps and crashes on EX switches during RA packet processing when SLAAC snooping is enabled
Product-Group=junos
Severity=Major
On EX switches, when SLAAC Snooping is enabled in certain IPv6 Router Advertisement (RA) packet, both PFE (Packet Forwarding Engine) and Routing Engine (RE) are used to free the same packet leading to double free scenario. This double packet free eventually might lead to FXPC cores and switch crashes caused by an invalid access or while freeing the packet. This impacts overall switch stability.
PR NumberSynopsisCategory: EX optics issues
1858986
Major
EX4400: Error message 'Failed to read eeprom' intermittently on SFP-T
Product-Group=junos
Severity=Major
On EX4400, error message 'Failed to read eeprom' is seen intermittently on SFP-T.
1860519
Major
The 'fxpc' process utilization shows above 80% with 100G AOC/DAC or 100G optics connected on interface with FEC mode mismatch
Product-Group=junos
Severity=Major
On all Junos platforms, in QSFP28 100G port connectivity with 100G AOC (Active Optical Cable) or 100G DAC (Direct Attach Cable) or with 100G optics when an interface Ethernet FEC Mode is set to 'FEC91' and at peer side if Ethernet FEC Mode is mismatched or by setting it as "NONE" then this FEC mismatch causes link to go down and the 'fxpc' process utilization spikes are seen above 80%.
PR NumberSynopsisCategory: SRX1500 platform software
1896794
Major
On SRX1500 platforms, after PFE crash, FPC cannot come online
Product-Group=junosvae
Severity=Major
On SRX1500 platforms, when transit packets get stuck, PFE crash and PFE core-dump is generated. FPC remains 'present' state until reboot, all the services running on that FPC will be impacted.
1910445
Major
Link status of disabled SFP-T port becomes up after rebooting on SRX1500
Product-Group=junos
Severity=Major
When an SFP-T port is disabled, it shows admin down but can be in a physical up state after a reboot.
PR NumberSynopsisCategory: MX MIC-3D-10GE-SFP-X driver
1906675
Major
Link failure due to auto-negotiation state getting stuck on MX platforms having Junos OS
Product-Group=junos
Severity=Major
On all Junos OS MX platforms that support MPC2E-NG, MPC2E-3D-NG-Q, MPC3E-NG and MPC3E-3D-NG-Q, the Auto-Negotiation (AN) process on certain PHY interfaces of the MIC (MIC-3D-10GE-SFP-E) may intermittently get stuck, preventing link establishment and causing traffic loss. This issue can be triggered by reinserting an SFP-T module, multiple times restarting the mic or by interface driver resets, which lead to inconsistent enable/disable sequences during Auto-Negotiation.
PR NumberSynopsisCategory: Flow Module
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
Severity=Major
All Junos SRX platforms that support PMI (Power Mode IPsec) experiences FPC reboot due to traffic hitting the FAT (flow aware transport) IPSec tunnel configuration.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after all FPCs reset due to SPC crash files in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of all FPCs. Following the crash and FPC resets, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform flowd process is generating crash files.
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1867811
Major
L2ald memory usage increased up to100MB
Product-Group=junos
Severity=Major
On all Junos, the memory usage of the Layer 2 Address Learning Daemon (L2ALD) can increase rapidly due to the context history maintained by the Layer 2 Address Learning Manager (L2ALM), which can grow up to 100MB.
1909786
Critical
EVPN traffic blackholing occurs due to incorrect ARP binding when VGA IP is used as re-ARP source
Product-Group=junos
Severity=Critical
On all Junos platforms, In Ethernet VPN (EVPN) Virtual Extensible LAN (VXLAN) deployments using Integrated Routing and Bridging (IRB) interfaces with a virtual gateway IP address and virtual gateway Media Access Control (MAC) configuration, re-ARP packets may use the virtual gateway IP as the source IP while using the IRB MAC as the source MAC. This behavior can cause connected hosts to overwrite their Address Resolution Protocol (ARP) entries, resulting in traffic being forwarded to an incorrect leaf switch in all-active Link Aggregation Group (LAG) multihoming scenarios. This may lead to intermittent or complete traffic loss for hosts connected via LAG to dual-homed leaf devices.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=junos
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: MX10K RCB
1909435
Major
Suppress humidity sensor CLI command and corresponding code in McLaren MX
Product-Group=junosvae
Severity=Major
Humidity Sensor CLI command is not applicable in McLaren RCB. The command has been suppressed in later releases
PR NumberSynopsisCategory: Multiprotocol Label Switching
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
Severity=Major
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.
PR NumberSynopsisCategory: Multicast for L3VPNs
1902405
Major
The rpd process crash is observed with MVPN and RIB sharding enabled
Product-Group=junos
Severity=Major
On Junos MX and Junos Evolved PTX platforms , with RIB sharding enabled and if either IPv4 or IPv6 address family is disabled in MVPN (multicast virtual private network), the unicast route flow from shard tries to access MVPN data structures without validation leading to rpd (Routing Protocol Daemon) process crash.
PR NumberSynopsisCategory: Odin Timing software
1900889
Major
[ACX710] acx-arm-feb process is 100% utilised after upgrading Junos to 23.2R2-Sx releases and enabling interfaces with PTP/ SyncE configuration.
Product-Group=junos
Severity=Major
After upgrading Junos on ACX710 to a 23.2R2-Sx release, the acx-arm-feb process may run at 100 percent utilization if PTP/SyncE is operational and the associated interfaces are up. The condition persists even when the affected interfaces are disabled and the system is rebooted.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
Severity=Major
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1758400
Major
JUNOS_REG: QFX51200-48YM: Fan status output was not same after/before device vc-switch over.
Product-Group=junos
Severity=Major
In a QFX51200-48YM-8C VC setup, after a a mastership switch over fan tray of linecard may not be displayed in show chassis hardware and show chassis environment. There is no functional impact
PR NumberSynopsisCategory: Resource Reservation Protocol
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
Severity=Major
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
Severity=Major
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: SRX branch platforms
1859188
Minor
Branch SRX unstable NTP issue
Product-Group=junos
Severity=Minor
On Branch SRX platforms (SRX300, SRX320, SRX340, SRX345 and SRX380), NTP time reset message is often seen due to SRX NTP issue
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1904696
Major
FPC flaps when the policer action is changed from 'discard' to 'loss-priority'
Product-Group=junos
Severity=Major
On SRX4600, SRX4700, and SRX5K platforms, the FPC flaps when the policer action is changed from 'discard' to 'loss-priority'. This issue also triggers a Ukern process crash, and traffic will be impacted during the FPC flap.
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1897464
Major
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
Severity=Major
On all affected platforms, under rare conditions involving heavy control-plane churn and a large number of interfaces within a routing instance, memory allocation failures related to Next-Hop processing will occur. This can lead to traffic drops and, in severe cases, complete service disruption across multiple FPCs.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1798178
Minor
IS-IS Level 2 disabled after upgrade due to OpenConfig YANG model change
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved platforms that support OpenConfig IS-IS configuration, upgrading to a release where the enabled leaf under the IS-IS levels hierarchy (levels/level/config/enabled) has been deprecated may cause IS-IS Level 2 adjacencies to be disabled during configuration load via load override. This behavior is due to the deprecated YANG model leaf being processed incorrectly during load operations, resulting in Level 2 being automatically disabled and impacting inter-area routing. Configurations applied using manual set commands are not affected.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1863354
Minor
Command line freezes when Ctrl+Z is used
Product-Group=junos
Severity=Minor
In Junos OS Releases 24.2 and later(BSD 15), pressing Ctrl+Z in the Command Line Interface CLI suspends the process and causes it to become unresponsive. This behaviour is observed on systems using the and Berkeley Software Distribution BSD15 platform.
1878430
Major
The mgd process crash is seen on all Junos and Junos Evolved platforms when FQDN is configured along with ephemeral database
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, Fully Qualified Domain Name(FQDN) configured in static database in presence of ephemeral database instances results in the mgd process crash. As a result, mgd session gets terminated and commit fails. There is no traffic impact due to this issue. The issue is seen with FQDNs that resolve to multiple IP addresses.
1902713
Minor
The mgd process crash observed on running commit check after replace operation of groups name for apply-groups-except
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when replace operation was done on apply-groups-except object it was not clearing the entry of that object from apply-groups-info-tree, as a result 'mgd' process crash observed on commit check. There is no service impact due to this issue.
PR NumberSynopsisCategory: Issues related to NETCONF
1852868
Major
commit confirmed rpc request displays closing tag without opening tag in private mode
Product-Group=junos
Severity=Major
1906621
Major
RPC reply delayed for commit during NETCONF over SSH session on Junos TVP-based VMhost platforms
Product-Group=junos
Severity=Major
On JUNOS VM Host-based platforms, when performing NetConf "", an internal script caused its PID to be displayed in the NETCONF session during commit.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
Severity=Minor
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
Severity=Major
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

 


 

25.2R1-S2 - List of Known issues

PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junosvae
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.

Resolved In: junos:22.4R3-S11 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1857029
Major
zeroize command not working
Product-Group=junos
zeroize command not working

Resolved In:
PR NumberSynopsisCategory: Firewall Filter
1903874
Minor
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EX4100 PFE
1887725
Major
Observed hog messages during reboot test
Product-Group=junos
During bootup of the switch hog messages can be observed in /var/log/messages without any functional impact.

Resolved In:
1890822
Major
Special characters observed in syslog messages for DHCP failures.
Product-Group=junos
The issue is specific to the arm based platforms(EX4100, EX4000). This log is triggered under certain scenarios of DHCP failure events such as AS_PKT_DAI_FAILED, AS_PKT_DHCP_DROPPED, etc. As a workaround, we enabled one more log with the proper values under system events. For now, user can consider the log with proper values.

Resolved In:
PR NumberSynopsisCategory: EX interfaces issues
1870962
Major
In EX4400 devices with 4x25G or 1x100g ULM, when we perform PIC online, CPU hog by CMQFX thread may be seen
Product-Group=junos
In EX4400 devices with 4x25G or 1x100g ULM, when we perform PIC online, CPU hog by CMQFX thread may be seen for as much as 3.5seconds

Resolved In:
PR NumberSynopsisCategory: EX optics issues
1864715
Major
EX4100: 10g-BASE-T didn't come up after dc-pfe restart
Product-Group=junos
After multiple iterations of dc-pfe process restart, we may see interface with 10g-base-t transceiver (part# 740-123734) will not come up.

Resolved In:
1887303
Minor
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
1890164
Major
On some EX or QFX platforms, 25G interfaces remain down with a default FEC(Forward Error Correction) 74 value when peer device has default FEC as None
Product-Group=junos
When establish a physical connection between EX4650/QFX5120-48Y and EX4100/EX4400 using 10G/25G dual-rate SFP28 LR /SR optics over the 4x25G uplink ports, 25G interfaces remain down with a default FEC 74 value instead of FEC None when peer device has default FEC as None for this 25G LR /SR optics.

Resolved In: junos:23.4R2-S5-J24 junos:23.4R2-S5-J26 junos:23.4R2-S6 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EX POE
1881788
Major
PoE:24.4R2_Hardening: with Fast poe enabled by default , Non PoE member as master , poe status shows disabled while PDs are powered up
Product-Group=junos
When a non-PoE SKU is configured as the master and PoE SKUs are configured as members, the PoE status will be "disabled" in cli even though PDs are powered up. However, if the device is rebooted while in this state, PoE functionality will not resume afterward.

Resolved In:
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1865354
Major
Traffic to anycast IPv6 destination addresses dropped when using ECMP routes
Product-Group=junos
On QFX10002-60C platforms when ECMP is required to get multiple-path to multiple hosts connected, and with IPV6 address configured as a destination address, the destination MAC rewrite process fails, due to the unilist nexthop for IPv6 destination is getting overwritten. This leads the IPv6 packets to the host, to get dropped over the ECMP routes.

Resolved In: junos:22.2R3-S3-J20 junos:22.2R3-S5-J2 junos:22.2R3-S6-J1 junos:22.2R3-S7 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.4R2
PR NumberSynopsisCategory: Express ASIC interface
1793344
Major
The 10g channelized Interface doesn't come up after router reboot on the PTX5000 platform
Product-Group=junos
On Junos PTX5K platforms running 22.3X60 configured with FPC3-PTX-U2 and FPC3-PTX-U3, the 10g channelized Interface port doesn't come up after router reboot. In rare conditions, the interface might remain down when firmware attempts to configure the line-side lane configuration during the firmware mode set process.

Resolved In: junos:22.3X60 junos:22.4R3-S5
PR NumberSynopsisCategory: IDP attack detection in the subscriber qmodules
1853515
Major
Accuracy Failures Observed in ARM-based cSRX platform
Product-Group=junos
For cSRX/ARM platform, the below three attacks need to be configured outside the attack groups for proper detection. SHELLCODE:X86:AVD-UTF8TLWR-STC SHELLCODE:PHP:BASE64-STC HTTP:NNMRPTCONFIG-EXE-RCE

Resolved In:
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S5-J2 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
PR NumberSynopsisCategory: Security platform jweb support
1725808
Critical
Junos OS: J-Web: Multiple vulnerabilities resolved in PHP software (CVE-2023-0567, CVE-2023-0662, CVE-2023-3823, CVE-2023-3824, CVE-2023-0568)
Product-Group=junos
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88120 [juniper.net] for more information.

Resolved In: evo:23.3R2-EVO junos:21.4A3 junos:21.4R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R1-S2 junos:23.2R2 junos:23.2R2-S2 junos:23.3R2 junos:23.4R1 junos:23.4R1-S2 junos:23.4R2 junos:23.4R2-S7 junos:24.1R1 junos:24.2R1 junos:24.3R1 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: MX10K RCB
1916094
Major
POL current/power values in CLI may not match actual readings
Product-Group=junosvae
On McLaren RCB, display-only issue in Junos CLI show chassis environment : current/power for some of the POLs are shown as 0, observed in 25.2R1-S1. Fixed in later releases.

Resolved In: junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover,
1782934
Major
vmcore on device with evpn-vxlan configs
Product-Group=junos
Graceful Routing Engine Switchover (GRES) not supporting the configuration of a private route, such as fxp0 , when imported into a non-default instance or logical system. Please see KB https://kb.juniper.net/InfoCenter/index?page=content&id=KB26616 [juniper.net] resolution rib policy is required to apply as a work-around

Resolved In:
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Sangria Platform including chassisd, RE, CB, power managemen
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
When the FPC(Flexible PIC Concentrator)online/offline button is pressed on PTX5000 and PTX3000 twice in a short period, chassisd crash will happen. it is causing all FPCs to lose connectivity with the Routing Engine while remaining in an online state. As a result, service impact happened till all FPCs become online.

Resolved In: junos:22.4R3-S9
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1913131
Major
On MX301 snmd may core in certain scenarios.
Product-Group=junos
On MX301 snmd may core in certain scenarios.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5 junos:22.4R3-S9
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
On Junos MX platforms with MS-MPC, when new rules are added to a service-set, the configuration size increases incrementally. This growth will cause failures during the commit process, potentially leading to a kernel panic. As a result, new configurations may not be successfully applied.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: SRX branch platforms
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S2 junos:25.2R2
PR NumberSynopsisCategory: DDos Support on MX
1897237
Major
Traffic flow display not accurate when SCFD is enabled
Product-Group=junos
On MX platforms with MPC10/MPC11/LC9600/LC4800 linecards and MX304/MX301 platforms, if SCFD (Suspicious Control Flow Detection) is enabled and lot of flow are tracked on the device, error logs may be reported when the table overflows. This is purely a display issue.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J36 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
In all Junos MX platforms acting as the AD (Aggregation Device) in a Junos Fusion deployment, a Junos software upgrade causes the smdp (Satellite Platform and Management Daemon) process to crash impacting forwarding plane services. This issue is observed when AD nodes are moved to a higher Junos version while the SD (Satellite nodes) are still running a lower version.

Resolved In: junos:22.4R3-S7-J7 junos:22.4R3-S9 junos:23.2R2-S6
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with CDR LOL support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S9

 


 

Modification History

First publication 2026-01-09