Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX

Alert Description

Junos Software Service Release version 22.4R3-S9 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

NOTE (2026-02-09): Due to an upgrade path that exposes the issue described in TSB103739 [juniper.net] within version 22.4R3-S9, VMHOST software images for the following platforms have been recalled and removed from the Software Download site.

If you have downloaded Junos software version 22.4R3-S9, please do not upgrade your router with that software. These images can be identified by having the text "22.4R3-S9.3" in the file names.

The new release, 22.4R3-S9.6, was released on 2026-04-06

Junos platforms using VM Host system software, which are affected by TSB103739 [juniper.net]
- ACX5448
- EX9200s
- MX240, MX480, MX960
- MX2008 MX2010 and MX2020
- MX10003
- MX10004 and MX10008
- JNP304-RE - MX304
- RCBPTX - PTX3000/PTX5000
- RE-PTX-X8
- PTX1000s
- PTX10008, PTX10016 (Junos version only, not applicable to Junos Evolved platforms.)
- PTX10002-60C
- QFX10002-60C
- SRX4600
- SRX5800s

Solution

Junos Software service Release version 22.4R3-S9 is now available.

22.4R3-S9 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junos
Severity=Major
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.
PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
Severity=Major
On Junos OS EX2300, EX3400, EX4100, EX4400, EX4650, EX4000 and QFX5K platforms with software-based MAC (Media Access Control) address learning enabled through interface-level MAC-limit or MAC-move-limit, the traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa.
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
Severity=Major
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
Severity=Major
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.
PR NumberSynopsisCategory: chassisd related issues for high-end SRX platforms
1887000
Minor
SRX4600 node 1 enters hardware failure during upgrade
Product-Group=junos
Severity=Minor
On SRX4600 platforms running Junos OS and configured in High Availability (HA), a hardware alarm is triggered during Low Impact Cluster Upgrade (LICU) procedures due to incorrect alarm logic tied to control link status. This condition affects Node 1 and causes Redundancy Group 1 (RG1) to failover to Node 0, even if Node 0 interfaces are not yet active, resulting in a traffic outage.
PR NumberSynopsisCategory: A20/A40 IOC card
1883027
Minor
SRX Firewalls with IOC3 triggers a temperature alert on the FPC 2 PLX PCIe Switch Chip
Product-Group=junos
Severity=Minor
On SRX5400, SRX5600, and SRX5800 platform with MPC3-40G10G and MPC3-100G10G (IOC3) interface card, a temperature alarm is triggered when the Peripheral Component Interconnect Express (PCIe) switch chip temperature exceeds 75 Celsius degrees.
PR NumberSynopsisCategory: BBE interface related issues
1848887
Major
Routing-services enabled on PPPoE dynamic profile causes subscriber login failure for new subscribers
Product-Group=junos
Severity=Major
On MX platforms, with routing-services enabled on PPPoE (Point-to-Point over Ethernet) Dynamic Profile, subscriber login fails for new subscribers with specific stacking model.
PR NumberSynopsisCategory: Border Gateway Protocol
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1825538
Minor
At the time of RE switchover the backup RE serial and part number values are replaced by the CB0 serial and part number values
Product-Group=junos
Severity=Minor
On MX304 platform, when RE (Routing Engine) switchover takes place the serial and part number values of back up RE is replaced with the values of CB (Control Board). This is a display issue and no impact on the traffic.
PR NumberSynopsisCategory: Class of Service
1872595
Minor
CoS configured on logical interface does not work on Junos platform when CoS wildcard configurations applied using groups
Product-Group=junos
Severity=Minor
When Class of Service configurations for an Interface Device (IFD) are present both under the wildcard (applied via groups) and as specific configurations (applied directly under the class-of-service hierarchy) on Junos platform, the Interface Device (IFD) correctly takes the specific configurations as expected. However, the Interface Logical (IFL) configurations from the wildcard are not being applied via groups.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: QFX Access Control related
1896371
Major
Junos OS and Junos OS Evolved: Use after free vulnerability In 802.1X authentication daemon can cause crash of the dot1xd process (CVE-2026-21908)
Product-Group=junos
Severity=Major
A Use After Free vulnerability was identified in the 802.1X authentication daemon (dot1xd) of Juniper Networks Junos OS and Junos OS Evolved that could allow an authenticated, network-adjacent attacker flapping a port to crash the dot1xd process, leading to a Denial of Service (DoS), or potentially execute arbitrary code within the context of the process running as root. Please refer to https://supportportal.juniper.net/JSA106007 [juniper.net] for more information.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: Firewall Filter
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908719
Major
On all mx platforms chassid gets stuck and becomes unresponsive it resumes only after restarting both control units
Product-Group=junos
Severity=Major
On MX devices, the sub-linecard feature with MPC11 cards. When this feature is used, the main system process can sometimes freeze, which may lead to system crashes and error logs.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.
PR NumberSynopsisCategory: Lacp related problems and issues.
1898531
Major
AE interfaces flap during GRES following an RE reboot on all Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, Aggregate Ethernet (AE) interfaces with LACP configured will experience a flap due to a timing issue when Graceful Routing Engine Switchover (GRES) is performed after a Routing Engine (RE) reboot, resulting in traffic loss during the flap.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1848993
Major
The data plane will be out of sync when migrating to EVPN A/A stitching with Vanila VXLAN (PIM Multicast)
Product-Group=junos
Severity=Major
On MX platforms, to improve the convergence of node failures in EVPN MH interconnects with Data Plane VXLAN, migrating to an Active-Active setup may cause the data plane to become out of sync for ARP entries. The gateway learns the MAC address and advertises it to the peer gateway. However, on the peer gateway, some MAC-IP entries may remain stuck in the 'Unresolved' (Ur) state.
PR NumberSynopsisCategory: EX4100 PFE
1905783
Major
FXPC core dumps and crashes on EX switches during RA packet processing when SLAAC snooping is enabled
Product-Group=junos
Severity=Major
On EX switches, when SLAAC Snooping is enabled in certain IPv6 Router Advertisement (RA) packet, both PFE (Packet Forwarding Engine) and Routing Engine (RE) are used to free the same packet leading to double free scenario. This double packet free eventually might lead to FXPC cores and switch crashes caused by an invalid access or while freeing the packet. This impacts overall switch stability.
PR NumberSynopsisCategory: EX interfaces issues
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
Severity=Major
On EX4400, random interfaces will not be created when the device is upgraded or rebooted. Interfaces will not be listed in the device and will affect all functionalities of the optic or interface.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1847849
Critical
Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop (CVE-2026-21910)
Product-Group=junos
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA106009 [juniper.net] for more information.
PR NumberSynopsisCategory: FIPS related issues
1871858
Minor
The device is in a reboot loop when fips mode is enabled
Product-Group=junos
Severity=Minor
On all Junos platforms, after loading the image where FIPS (Federal Information Processing Standards) mode is already enabled, the FIPS self-test may fail and the device may encounter a reboot loop.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.
PR NumberSynopsisCategory: ISIS routing protocol
1906578
Minor
IS-IS FA configuration in IPv4 or IPv6 Multicast topology may cause inconsistency in routing table leading to routing loop
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms, when IS-IS IPv4 or IPv6 Multicast topology (set protocols isis topologies [ipv4-multicast | ipv6-multicast]) is configured along with IS-IS Forwarding Adjacency (FA), a separate TLV-222 is added in IS-IS LSP for each FA. This causes incorrect next-hop resolution in the routing table, potentially leading to routing loops.
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
Severity=Major
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.
PR NumberSynopsisCategory: Flow Module
1892015
Major
Junos MX/SRX flowd Crash After Tunnel Removal Leaves Stale Flows, Causing FPC Reboot
Product-Group=junos
Severity=Major
On Junos OS SRX and MX platforms, any tunnels such as GRE, IPIP, DS-Lite, or IPSEC tunnel has its configuration removed, the IKE SAs can go down causing invalid entires. These can later cause the flowd process to crash
PR NumberSynopsisCategory: flow ha module
1895134
Minor
ISSU failure and process crash on primary node during HA upgrade
Product-Group=junos
Severity=Minor
On all Junos SRX platforms, performing ISSU (In-Service Software Upgrade) with the no-validate option in HA ( (High availability ) setups can cause ISSU failure and a process crash on the primary node.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
PR NumberSynopsisCategory: IPSEC/IKE VPN
1901732
Major
VPN traffic stops flowing intermittently on the st0 interface on SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX platforms, Virtual Private Network (VPN) traffic stops even though the IPsec tunnel remains UP. This issue occurs when Class of Service (CoS) is configured on the secure tunnel (st0) interface. IPsec packet processing fails, and memory buffer (mbuff) resources are not freed, leading to resource exhaustion. As a result, encrypted traffic cannot be transmitted through the tunnel. The problem does not impact tunnel status or Internet Key Exchange (IKE) negotiation, but impacts the interface traffic.
PR NumberSynopsisCategory: lldp sw on MX platform
1900111
Major
In Fusion Provider Edge deployments, aggregator does not establish LLDP neighborship with satellite interfaces
Product-Group=junos
Severity=Major
In Junos Fusion Provider Edge deployment, when satellite device is rebooted and subsequently LLDP is enabled on a satellite interface, it does not transmit Link Layer Discovery Protocol (LLDP) packages on the enabled interface resulting in the LLDP neighborship not being established and LLDP-MED (Media Endpoint Discovery), an extension of LLDP, stopping working and causing any Voice over IP phones connected to the interface to lose connectivity
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=junos
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: MX10K platform
1846557
Critical
When "set chassis redundancy failover on-re-to-fpc-stale" is configured unexpected master RE switchover will be seen if backup RE reboots resulting in traffic disruption
Product-Group=junos
Severity=Critical
On Junos OS MX10008/MX10016/MX10004 platforms, When "set chassis redundancy failover on-re-fpc-stale" is configured and the backup Routing Engine (RE) is rebooted, traffic disruption will be observed. This is due to a brief loss of internal system connectivity particularly the control link between the master RE and the FPCs (Flexible PIC Concentrators). During this time, the FPC reboots and interface will go down. This issue happens while the backup RE reboots, missed keepalives cause the master RE to mistakenly assume a communication failure and briefly step down, triggering a mastership re-election and re-elects itself as master that results in a traffic disruption as FPCs reboots before recovering.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
1910534
Major
SPC3 crashes when three-color policer is attached to firewall filter
Product-Group=junos
Severity=Major
On MX platforms with SPC3, when three-color policer is configured and attached to firewall filter SPC3 crashes and flowd crash files are seen. This will cause service impact since SPC3 keeps crashing and may not come up if the configuration leading to crash is not deleted.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
Severity=Major
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
Severity=Major
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.
PR NumberSynopsisCategory: Wind River Linux Distribution issues in NG-RE
1911820
Major
Device getting stuck in boot phase during upgrade because of expired libvirt certificate
Product-Group=junos
Severity=Major
On Junos platforms running the VMHOST system, devices are getting stuck in the boot phase during an upgrade because of expired libvirt certificate. See https://kb.juniper.net/TSB103739 [juniper.net]
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
Severity=Major
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1694798
Minor
On MX Series Routers, subscriber login failures with DHCPv6 over PPPoE
Product-Group=junos
Severity=Minor
On MX series devices, subscriber login failures and scaling limitations were observed in high-scale PPPoE(Point-to-Point Protocol over Ethernet) dual-stack deployments using DHCPv6( Dynamic Host Configuration Protocol version 6). This issue occurred when subscriber sessions attempted to re-login immediately after termination, causing a flow conflict in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: PTX10K Routing Engine
1915464
Major
The VMhost memory exhaustion causes RE hang when doing upgrade
Product-Group=junos
Severity=Major
On VMhost platforms with RE that have two management interfaces, when only one management port is connected, it will cause VMhost memory over consumption and when the VMhost upgrade command is triggered leading to higher memory need and due to less availability leading to RE hang.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platform, when router-advertisement is enabled on Pseudowire Subscriber(PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, causing routing and forwarding failures.
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1807037
Major
BGP backup routes are installed as primary routes after enabling 'protect core' feature
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms when Border Gateway Protocol (BGP) multipath is enabled for Layer 3 Virtual Private Network (L3VPN) routes and 'protect core' is enabled on the Virtual Routing and Forwarding (VRF) instance, the backup BGP path is installed as primary path. The Next hop weight value is not updated correctly, it is weight 0x1 instead of weight 0x4000 for the backup.
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
Severity=Major
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.
PR NumberSynopsisCategory: Sangria Platform including chassisd, RE, CB, power managemen
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
Severity=Major
When the FPC(Flexible PIC Concentrator)online/offline button is pressed on PTX5000 and PTX3000 twice in a short period, chassisd crash will happen. it is causing all FPCs to lose connectivity with the Routing Engine while remaining in an online state. As a result, service impact happened till all FPCs become online.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1758417
Major
Packet loss is observed when switching on MX304 platform from 1x400G to channelized 100G mode
Product-Group=junos
Severity=Major
Switch speed from 1x400G to 3x100/2x100/1x100 on MX304 platform causes packet truncation for channel 0. Other Channel works fine. It causes a traffic drop at the egress of interface.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
1913131
Major
On MX301 snmd may core in certain scenarios.
Product-Group=junos
Severity=Major
On MX301 snmd may core in certain scenarios.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
Severity=Critical
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
Severity=Major
On Junos MX platforms with MS-MPC, when new rules are added to a service-set, the configuration size increases incrementally. This growth will cause failures during the commit process, potentially leading to a kernel panic. As a result, new configurations may not be successfully applied.
PR NumberSynopsisCategory: SRX branch platforms
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
Severity=Major
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1869285
Major
Speed conversion from 10G to 1G on MX routers with MPC7E-10G does not synchronise across PFE and Kernel when adding the interface to Aggregate Ethernet (AE)
Product-Group=junos
Severity=Major
On MX Series routers with MPC7E-10G line cards when interface speed is converted to 1G and the interface is added to AE, speed change is not getting synchronised across Packet Forwarding Engine (PFE) and Kernel, leading to inconsistencies in bandwidth reporting and Class of Service (CoS) behaviour. Using 'set interfaces speed 1g', ensures proper synchronisation across all modules.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1812276
Major
Persistent link error in one fabric plane towards some PFE could causes traffic blackholing from non-native LC PFE towards that remote PFE over all fabric planes
Product-Group=junos
Severity=Major
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1886757
Minor
Alarms for high usage in /var partition are not generated
Product-Group=junos
Severity=Minor
On Junos SRX4600/SRX4700/SRX1600/SRX2300/SRX4300 platforms, alarms for high usage at /var partition storage is not reported.
1904696
Major
FPC flaps and the Ukern process will crash on certain SRX platforms when the policer action is changed from 'discard' to 'loss-priority'
Product-Group=junos
Severity=Major
On SRX4600, SRX4700, and SRX5K platforms, the Flexible PIC Concentrator (FPC) flaps and Ukern process will crash when the policer action is changed from 'discard' to 'loss-priority'. Traffic will be impacted when the FPC flaps.
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1703922
Minor
The MPC7/MX2K-MPC8E/MX2K-MPC9E line cards experience LLM XTXN idling/timeout followed by a crash due to an HMC failure
Product-Group=junos
Severity=Minor
On MX platforms with MPC7, MX2K-MPC8E, and MX2K-MPC9E line cards, when an HMC error is seen on the FPC (Flexible PIC Concentrators), it experiences a watchdog abort triggered by a ukernel thread exceeding CPU run time limits. The HMC memory part failure causes FPC crashes and thus results in traffic impact on the affected FPC.
1897464
Major
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
Severity=Major
On all affected platforms, under rare conditions involving heavy control-plane churn and a large number of interfaces within a routing instance, memory allocation failures related to Next-Hop processing will occur. This can lead to traffic drops and, in severe cases, complete service disruption across multiple FPCs.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940
Major
The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
Severity=Major
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
Severity=Major
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.
1913870
Major
GRE-over-GRE tunnel is down due to keepalive packets dropped
Product-Group=junos
Severity=Major
On Junos MX204, MX240, MX480, MX960, MX2008, MX2010, MX2020 and MX10003 platforms using a version of line cards MX2K-MPC(6/9)E, MX-MPC(2/3)E or MPC(3/5/7)E; when Generic Routing Encapsulation (GRE)-over-GRE is configured, end-to-end keepalive packets in the outer tunnel are dropped, and tunnel interface cannot pass traffic
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: Issues related to NETCONF
1906621
Major
RPC reply delayed for commit during NETCONF over SSH session on Junos TVP-based VMhost platforms
Product-Group=junos
Severity=Major
On JUNOS VM Host-based platforms, when performing NetConf "", an internal script caused its PID to be displayed in the NETCONF session during commit.
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
Severity=Major
In all Junos MX platforms acting as the AD (Aggregation Device) in a Junos Fusion deployment, a Junos software upgrade causes the smdp (Satellite Platform and Management Daemon) process to crash impacting forwarding plane services. This issue is observed when AD nodes are moved to a higher Junos version while the SD (Satellite nodes) are still running a lower version.
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
Severity=Major
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with CDR LOL support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
Severity=Critical
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

 

Extended Solution

22.4R3-S9 - List of Known issues

PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junosvae
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4B1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1785231
Minor
PE Routers continue to drop prefixes in a L3 VPN scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured as a Provider Edge (PE) in an L3VPN scenario peering with a route-reflector (RR) as a client, when there are no external BGP peers configured with a static route-target-filter as `local`, VPNv4 prefixes advertised by RR is being dropped which is as per design and expected behavior. However, when an external BGP session is established on the PE, because 'advertise-from-main-vpn-tables' is configured, the PE doesn't flap all existing BGP sessions, and the refresh of prefixes advertised by RR does not happen. As a result, prefixes advertised by RR continue to be dropped at PE.

Resolved In: evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO junos:21.2R3-S9 junos:23.4R2 junos:24.1R2 junos:24.2R1
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-J1 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.2R1-S2 junos:25.2R2
1826685
Minor
Unexpected behaviour after BGP sessions reset for catastrophic BGP configuration changes
Product-Group=junos
On Junos and Junos Evolved platforms, when a catastrophic Border Gateway Protocol (BGP) configuration change occurs, creating a new peer structure due to this configuration change, the BGP state transitions from open-sent to established multiple times (until the local device finishes cleaning the old BGP session). This results in traffic impact as the peer is reset multiple times (until a new peer connection is established).

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:22.2R3-S7 junos:22.4R3-S6-J11 junos:22.4R3-S7-J1 junos:22.4X8 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=junos
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO evo:24.2R2-S1-EVO evo:24.4R1-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S10 junos:23.2R2-S4 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
1859020
Minor
Incorrect subcode NOTIFICATION is sent when local interface is disabled for which multihop is configured for directly connected peer
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when 'multihop' is configured on a directly connected interface towards a peer and the session goes in IDLE state due to no local interface (interface is disabled or down), the log messages shows 'subcode 6 'Other Configuration Change'' instead of 'subcode 9 'Hard Reset''.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".

Resolved In: evo:22.2R3-S7-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1889749
Major
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.

Resolved In: evo:23.2R2-S6-EVO evo:24.4R2-S2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-J2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: BGP BMP Software
1908215
Minor
BMP traces continues to fill the trace file even after removing BMP traceoptions configuration
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, enabling BMP(BGP Monitoring Protocol) tracing with local-rib monitoring continues to fill the trace file even after removing BMP trace option Configuration it is still running this on a cRPD instance, this creates a risk of the space exhaustion on a host that contains other production cRPDs.

Resolved In: junos:20.3X75-D442 junos:26.1R1
PR NumberSynopsisCategory: Firewall Filter
1903047
Minor
Intermittent traffic loss after pfe reset due to FLT filters
Product-Group=junos
On all Junos MX platforms with line cards MPC7/8/9 (EA Asic) , if any PFE restarts as part of any encountered CM Error defects, then fast-lookup-table filters will not work properly and traffic black holing will be seen.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:23.2R2-J22 junos:24.2R2-J11 junos:24.2R2-S2-J12 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1903874
Minor
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:22.4X8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.2X1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.

Resolved In: evo:23.4R2-S5-J28-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: EX4000 PFE issues
1847159
Major
Reachability issues are seen on interfaces that are aggregated without address-family
Product-Group=junos
On Junos platforms, specifically on EX and QFX series aggregated interfaces configured without address-family results in reachability issues.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S7 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R1 junos:24.4R1-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EX interfaces issues
1909608
Minor
Auto-negotiation is not displayed in 'show interfaces' command output
Product-Group=junos
On EX3400 and EX4400-48F, when using 1G optics, the auto-negotiation information does not appear in the output of the "show interfaces" command.

Resolved In: junos:24.2R2-S4 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: MX MIC-3D-10GE-SFP-X driver
1906675
Major
Link failure due to auto-negotiation state getting stuck on MX platforms having Junos OS
Product-Group=junos
On all Junos OS MX platforms that support MPC2E-NG, MPC2E-3D-NG-Q, MPC3E-NG and MPC3E-3D-NG-Q, the Auto-Negotiation (AN) process on certain PHY interfaces of the MIC (MIC-3D-10GE-SFP-E) may intermittently get stuck, preventing link establishment and causing traffic loss. This issue can be triggered by reinserting an SFP-T module, multiple times restarting the mic or by interface driver resets, which lead to inconsistent enable/disable sequences during Auto-Negotiation.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:26.1R1
PR NumberSynopsisCategory: Flow Module
1832547
Minor
The flowd process crash is observed on certain SRX platforms
Product-Group=junos
On certain Junos SRX devices upon initiation of session scan, flowd process might crash due to session getting deleted/re-routed. This could result switchover of redundancy group in case of high availability.

Resolved In: junos:23.4R2-S4-J26 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1 junos:25.3R1
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
All Junos SRX platforms that support PMI (Power Mode IPsec) experiences FPC reboot due to traffic hitting the FAT (flow aware transport) IPSec tunnel configuration.

Resolved In: junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
On Junos OS SRX platforms with Generic Routing Encapsulation (GRE) over a Secure Interface Tunnel (st0) is configured, if the st0 interface flaps, the GRE tunnel comes up before the st0 interface(which is due to a timing issue), results in a mismatch in the hash values between session packets and the GRE tunnel, which will cause traffic drop.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1
1884150
Major
Policy match failure for VXLAN EVPN type-5 cross vrf traffic
Product-Group=junos
On all SRX platforms, Ethernet Virtual Private Network (EVPN) Type-5 Virtual Extensible LAN (VXLAN) cross-Virtual Routing and Forwarding (VRF) traffic fails to match security policies when the ingress and egress VRFs are mapped to different VRF groups.

Resolved In: junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: l2 flow module
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.

Resolved In: junos:21.4R3-S12 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.

Resolved In: evo:24.2R2-S4-EVO junos:21.4R3-S12 junos:22.2R3-S7 junos:23.2R2-S6 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.

Resolved In: junos:24.4R2-S2-J1 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Layer 2 Circuit issues
1863228
Major
IFL configured on the LAG interface goes down when the VLAN operation is changed
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, when EVPN is configured with the 'df-election-granularity per-esi' feature, any change in VLAN operation causes the IFL (logical interface) configured on the LAG (Link Aggregation Group) interface to go down, impacting all services associated with that interface.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S1-J15 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Label Distribution Protocol
1789663
Major
Unexpected rpd crash when huge amount of telemetry data is being streamed
Product-Group=junos
On Junos and Junos Evolved platforms with telemetry enabled, in escenarios where huge amount of data is being streamed, when streaming data crosses the limit (i.e size based defer limit is at 15kb and time-based defer limit 100 ms) there will be a defer and continue. If configuration changes occur during this deffering state that affected the last streamed XPath (the specific data path being monitored), it will cause rpd (routing protocol deamon) to crash causing traffic drop and core file will be generated. No workaroung is provided, rpd will restart automatically.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.4R2-S6 junos:24.2R1 junos:24.2R2 junos:24.3R1
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1807410
Critical
SFB power off/unplug followed by ungraceful SPMB restart leads to SPMB crash
Product-Group=junos
On MX2020 and MX2010 platforms, during fabric link training, if the SFB (Switch Fabric Board) suddenly shuts down due to a power off or being unplugged at a specific moment, a SPMB (Switch Processor Mezzanine Board) crash can be seen. It is a timing issue

Resolved In: junos:21.2R3-S8-J6 junos:21.2R3-S9 junos:21.2X35 junos:21.4R3-S7-J4 junos:23.2R2-S3 junos:23.4R2-S3-J6 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1812046
Minor
On MX2K, offline manually SFB2 or SFB3 or Plane to recover from a fabric link training failure, fabric mananger is not able to turn off the fabric links on a neighbor slot FPC
Product-Group=junos
Once SFB2 or SFB3 or plane is manually offline in an attempt to recover from a Fabric Training Failure of one FPC, the neighbor slot FPC is not be able to stop the high speed link and is ending up with training failure as well.

Resolved In: junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S3-J3 junos:22.4X4 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1793982
Minor
Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash (CVE-2026-21909)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA106008 [juniper.net] for more information.

Resolved In: evo:23.2R2-EVO evo:23.4R1-S1-J5-EVO evo:23.4R1-S1-J7-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.2R2 junos:23.2R2-J14 junos:23.4R1-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.

Resolved In: evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Multicast Routing
1876458
Major
MX960 mcsnoopd core dump during rt_mcnh_nh_release
Product-Group=junos
When the mcsnoopd process (use for L2 multicast) creating a new NH , our system takes a reference to it. However, if this reference is released too quickly, the old NH might be deleted before its references are fully cleared. This may cause the mcsnoopd process to restart.

Resolved In: evo:22.4R3-S8-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1902405
Major
The rpd process crash is observed with MVPN and RIB sharding enabled
Product-Group=junos
On Junos MX and Junos Evolved PTX platforms , with RIB sharding enabled and if either IPv4 or IPv6 address family is disabled in MVPN (multicast virtual private network), the unicast route flow from shard tries to access MVPN data structures without validation leading to rpd (Routing Protocol Daemon) process crash.

Resolved In: evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2-J2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Odin Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface like em0/me0/fxp0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.

Resolved In: evo:23.4R2-S7-EVO evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.2R3-S10 junos:21.2R3-S9-J5 junos:23.4R2-S5-J23 junos:23.4R2-S6-J2 junos:23.4R2-S7 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1698894
Major
The communication between primary and backup Routing Engines breaks in the event of scale network churn
Product-Group=junos
On PTX Series routers and QFX Series switches with dual Routing Engines running Junos OS, high host-bound traffic can cause a memory issue. Because of low memory, the Address Resolution Protocol (ARP) entry add can fail. Due to this, the communication between the primary Routing Engine and backup Routing Engine breaks, causing redundancy failure in high network churn and GRES-enabled scenario.

Resolved In: junos:20.3X75-D50 junos:21.2R3-S5 junos:22.2R3-S3 junos:22.4R3-S6-J12 junos:22.4R3-S7-J1 junos:22.4X8 junos:23.1R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1810740
Major
Link wont come up on bounce of fec91 on QFX5120 platform
Product-Group=junos
On QFX5120-48T, Interface links are not coming up at DUT after restoring the FEC configuration from mistmatched FEC configuration at non-dut.

Resolved In: junos:23.2R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1801382
Minor
Memory Leak in the rpd Process During Protocol Deactivation/Activation
Product-Group=junos
On all Junos and Junos Evolved platforms, A memory leak occurs during protocol, routing instance, or interface deactivation/activation, linked to improper IPv6 Interface Address (IFA) reference handling in the " ifx_dist_msg " process. This can lead to rpd crashes and service disruptions.

Resolved In: evo:21.4R3-S10-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:22.4R3-S7-J1 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S3-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:23.4R2-S5-EVO evo:24.2R2-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S3-EVO evo:25.1R1-EVO junos:22.2R3-S7 junos:22.3X60 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.2X1 junos:24.4R2-S2 junos:25.1R1
1868085
Major
The rpd process crashes and asserts are seen due to memory leak
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crashes and asserts are seen due to a memory leak when BGP sharding is enabled and 'show route' is performed continuously.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S3 junos:25.2R2 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1771344
Minor
Leaked routes via BGP rib-group remains in hidden state even though "loops" is configured with any value greater than one
Product-Group=junos
On all Junos and Junos Evolved platforms having BGP (Border Gateway protocol) configured, when route is leaked via rib-group from one routing instance to another having the same AS (Autonomous System) number and one of the routing-instances has BGP configured with local-as, it is observed that even after configuring "loops" with any value greater than one as the number of loops option, the route still remains hidden instead of being active which results in traffic drop.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
1815837
Minor
Configure low file size in traceoptions while logging volume is high will lead to high CPU and RPD scheduler slips causing operational impact
Product-Group=junos
If the file size is too small and the amount of traceoptions volume is too high it can cause scheduler slips and operational impact.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: PTX10K platform specific fabric PRs
1900242
Critical
Traffic loss seen due to SIB init failures on PTX10016 and PTX10008 platforms
Product-Group=junos
On Junos OS Evolved based PTX10K8 and PTX10K16 platforms, Switch Interface Board (SIB) init failures are observed after system reboot. Traffic loss is seen as SIBs are impacted.

Resolved In: evo:23.2R2-S4-EVO evo:23.2R2-S5-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:JUNOS_232_R2_S4_EVO_BRANCH
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SRX branch platforms
1897579
Minor
Packet drops are observed on SRX380 platforms in packet mode
Product-Group=junos
On Junos OS SRX380 (cluster/standalone) platforms in packet mode, when L2 (Layer 2) encapsulation is configured on an ingress interface of the PE (Provider-Edge) device, the incoming packets are dropped because these packets are identified as L2 unknown unicast packets. This issue happens due to the default drop ACL (Access Control List) applied for L2 unknown unicast packets.

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S6 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
On all Junos platforms, FPC (Flexible PIC Concentrator) crashes due to panic caused by incorrect handling of an application. This causes service impact since the card restarts after crash.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J23 junos:23.4R2-S4-J30 junos:23.4R2-S6 junos:25.2R2
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1902358
Minor
RPC crash when non-ASCII character is included in XML data result
Product-Group=junos
RPC calls fail when non-ASCII characters (i.e. UTF-8 encoded characters) are included in XML data results.

Resolved In:
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:26.1R1
PR NumberSynopsisCategory: Issues related to NETCONF
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=junos
On ACX7024, ACX710032C, and ACX7348 platforms running Junos OS Evolved, enabling netconf notifications with the command "set system services netconf notification" may cause a memory leak. This results in a control plane crash (vmcore). Forwarding plane remains unaffected.

Resolved In: evo:24.2R2-S4-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: web filterig issues
1876037
Critical
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash (CVE-2026-21917)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA105996 [juniper.net] for more information.

Resolved In: junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S2 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: usf url filtering related issue
1814701
Major
, URL filtering sessions are bypassed on MX platform with SPC3
Product-Group=junos
On MX platform with SPC3, the packets matched under the URL-filtering configuration are bypassed rather than the action mentioned in the rule.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.2R2-S4 junos:23.4R2-S7 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:20.2R3-S11 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1

 

Modification History

First publication 2026-01-16