Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX running Junos software

Alert Description

Junos Software Service Release version 24.4R2-S3 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.4R2-S3 is now available.

24.4R2-S3 - List of Fixed issues

PR NumberSynopsisCategory: SRX4700 datapath related issue
1889422
Major
Flow-control configuration is now supported on SRX4700 interfaces, allowing users to enable or disable Ethernet PAUSE-based flow control dynamically through CLI.
Product-Group=junos
Severity=Major
CLI Knob for Dynamic Lossless Flow Control Configuration on SRX4700 SRX4700 platforms now support a configuration knob that allows users to dynamically enable or disable IEEE 802.3x Lossless Flow Control (Pause) from the Routing Engine (RE) CLI, with state persistence across reboots. Previously, lossless flow control was hardcoded to always remain enabled on SRX4700, limiting flexibility for deployments with asymmetric traffic profiles. This enhancement introduces a configurable mechanism that gives operators fine-grained control to disable flow control when desired, particularly in environments where asymmetric CPU utilization or uneven traffic distribution can cause unnecessary PAUSE behavior and performance degradation.
PR NumberSynopsisCategory: "agentd" software daemon
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.
PR NumberSynopsisCategory: BBE database related issues
1909540
Minor
config commit on Juniper ACX device hangs
Product-Group=junos
Severity=Minor
EVO includes an automatic cleanup mechanism that triggers when the /var/tmp partition usage exceeds 85%. The process deletes temporary files to prevent the partition from filling up completely, which could impact overall system performance or stability. Unfortunately important shared memory log files meant for subscriber management stored under /var/tmp, were deleted. Subsequently when a new configuration is being committed, subscriber management daemon pre-check fails, leading to commit failure.
PR NumberSynopsisCategory: BBE UP Session Manager related issues
1916030
Major
L2TP subscriber session failure in BNG CUPS scenario
Product-Group=junos
Severity=Major
On Junos MX platforms and Junos OS Evolved ACX platforms that support BNG CUPS ( Broadband Network Gateway Control and User Plane Separation), L2TP (Layer 2 Tunneling Protocol) subscriber sessions will fail to come up. When this happens, the subscriber session does not bind correctly and no data traffic will pass for the affected subscribers.
PR NumberSynopsisCategory: Border Gateway Protocol
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, after interface configuration rollback, sessions stay in Idle state when multiple BGP(Border Gateway Protocol) sessions exist.
1903829
Major
On platforms supporting BGP RIB sharding the rpd process crash is observed on both REs
Product-Group=junos
Severity=Major
On platforms supporting where BGP (Border Gateway Protocol) RIB (Routing Information Base) Sharding is configured the rpd process crashes on both REs (Routing Engines) due to route churns. This timing issue is caused when a particular internal function is used by multiple threads.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: CFM
1919868
Major
Enhanced Loop Detect vlan-id all option now available for EX4650 and QFX5120
Product-Group=junos
Severity=Major
With this PR fix, Enhanced Loop Detect vlan-id all option now available for EX4650 and QFX5120
PR NumberSynopsisCategory: QFX Access Control related
1923266
Major
Upgrade from release 23.4R2-S4 with persistent-cache enabled on VC can cause dot1xd to crash continuously
Product-Group=junos
Severity=Major
On all Junos devices with dual RE configured with dot1x, if the device is upgraded from release 23.4R2-S4 or there is a RE switchover and persistent-cache feature enabled it will cause dot1xd to crash. It is due to presence of some stale files on backup node.
PR NumberSynopsisCategory: Device Configuration Daemon
1824206
Minor
Device reboot will bring down the asi interfaces on all Junos platforms
Product-Group=junos
Severity=Minor
On all Junos platforms, there is a synchronization problem between the rdd daemon and the chassisd processes regarding the creation of ASI (Aggregated Inline Services) interfaces during system bootup that causes the chassisd to delete all interface-related configurations and thus delete the ASI interfaces from the system. Due to that, the ASI interface remains down, and it will affect only ASI interfaces, and other interfaces will not be affected by this issue.
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.
PR NumberSynopsisCategory: ACX platform interface issues
1887528
Minor
Optics fail to come up post reboot
Product-Group=junos
Severity=Minor
On all ACX5448 platforms, read errors are observed on 1G copper optics (SFP-T) modules during the device reboot, resulting in the 1G optics ports remaining down and impacting all services.
1896458
Minor
SFP-T port will not come up after system restart
Product-Group=junos
Severity=Minor
On Junos ACX5448 platforms, when the port with SFP-T copper optics is disabled or chassisd is restarted, Tx is disabled before the media is identified. This is a timing issue. The port will not come up even if disable is removed from the configuration. Reinserting the transceiver will resolve the issue.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1914423
Major
On-change telemetry events dropped when l2ald telemetry queue memory limit is not configured
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when l2-learning telemetry is enabled without explicitly configuring a memory limit for the l2ald (Layer 2 Address Learning Daemon) telemetry queue, the default memory limit is not applied. As a result, all on-change telemetry events are dropped.
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.
PR NumberSynopsisCategory: EVPN control plane issues
1893671
Minor
EVPN routes take longer to install into the FIB after being learned via BGP
Product-Group=junos
Severity=Minor
In large-scale Junos and Junos EVO deployments, within high-scale BGP route scenarios, EVPN routes may take up to 7 minutes to be installed into the FIB. This delay can temporarily impact traffic until the routes are fully installed.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=junos
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
PR NumberSynopsisCategory: EX interfaces issues
1909608
Minor
Auto-negotiation is not displayed in 'show interfaces' command output
Product-Group=junos
Severity=Minor
On EX3400 and EX4400-48F, when using 1G optics, the auto-negotiation information does not appear in the output of the "show interfaces" command.
1915222
Minor
Interfaces down after Virtual Chassis reboot
Product-Group=junos
Severity=Minor
On all Junos EX Series platforms, following a Virtual Chassis (VC) reboot, random interface links GE(Gigabit) and XE(10 Gigabit) intermittently appear in a down state at the Interface Descriptor (IFD) level, even though the physical link remains operational.
PR NumberSynopsisCategory: EX optics issues
1860519
Major
The 'fxpc' process utilization shows above 80% with 100G AOC/DAC or 100G optics connected on interface with FEC mode mismatch
Product-Group=junos
Severity=Major
On all Junos platforms, in QSFP28 100G port connectivity with 100G AOC (Active Optical Cable) or 100G DAC (Direct Attach Cable) or with 100G optics when an interface Ethernet FEC Mode is set to 'FEC91' and at peer side if Ethernet FEC Mode is mismatched or by setting it as "NONE" then this FEC mismatch causes link to go down and the 'fxpc' process utilization spikes are seen above 80%.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1925572
Minor
CLI stops working on Junos EX and QFX platforms post device reboot
Product-Group=junos
Severity=Minor
On Junos EX and QFX platforms, with Virtual Extensible Local Area Network (VXLAN) configured, during the reboot, after vxlan init is done, the register gets reprogrammed to the default value and hence CLI doesn't work as expected.
PR NumberSynopsisCategory: SRX1500 platform software
1910445
Major
Link status of disabled SFP-T port becomes up after rebooting on SRX1500
Product-Group=junos
Severity=Major
When an SFP-T port is disabled, it shows admin down but can be in a physical up state after a reboot.
PR NumberSynopsisCategory: Flow Module
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
Severity=Major
All Junos SRX platforms that support PMI (Power Mode IPsec) fat tunnel configuration may experience, FPC reboot in some occasional scenarios, when traffic hits FAT tunnel. The reboot is occasional in some timing scenarios and that timing is when system gets wrong data to process the traffic. Not all customer experience this, and so far a customer reported, the issue is seen every 2 weeks or more.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1907424
Major
ICD BFD sessions fail to come up after reboot in MNHA deployments
Product-Group=junos
Severity=Major
On all SRX platform that supports Multi-Node High Availability (MNHA), Inter-Chassis Dynamic (ICD) Bidirectional Forwarding Detection (BFD) sessions fail to come up after a node reboot. This occurs because the ICD process does not receive the correct routing-instance information during boot, causing the ICD link to remain down. This is a timing issue.
PR NumberSynopsisCategory: N/A:sw-jsr-kmd:
1922670
Critical
KMD process crash during RG0 failover with ADVPN shortcuts in HA cluster
Product-Group=junos
Severity=Critical
On SRX and MX platforms using the IPsec Key Management Daemon (KMD), RG0 failover or failback while Auto Discovery VPN (ADVPN) shortcuts are active may cause the KMD process to crash, temporarily disrupting ADVPN sessions.
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
Severity=Major
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.
PR NumberSynopsisCategory: SRX Datapath Multicast Solution Specific to Motorola
1899131
Major
Multicast packets are getting dropped when multicast is configured in strict-ordering mode
Product-Group=junos
Severity=Major
On Junos OS SRX1600 platforms, when multicast is configured in strict-ordering mode, and certain threads are dedicated to processing multicast traffic, some multicast packets get dropped. This occurs due to the way the system handles message processing in this configuration, which can impact multicast traffic forwarding.
PR NumberSynopsisCategory: Firewall Policy
1899519
Minor
SRX and MX-SPC3: While Downgrading from 25.4/24.4R2/25.2R2/25.3R1 image with address book IPV4 range config, image installation validation is failing.
Product-Group=junos
Severity=Minor
Because of a recent regression, address-book configuration with address-range can not pass pre-ISSU (or) upgrade (or) downgrade config validation.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1901732
Major
VPN traffic stops flowing intermittently on the st0 interface on SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX platforms, Virtual Private Network (VPN) traffic stops even though the IPsec tunnel remains UP. This issue occurs when Class of Service (CoS) is configured on the secure tunnel (st0) interface. IPsec packet processing fails, and memory buffer (mbuff) resources are not freed, leading to resource exhaustion. As a result, encrypted traffic cannot be transmitted through the tunnel. The problem does not impact tunnel status or Internet Key Exchange (IKE) negotiation, but impacts the interface traffic.
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
Severity=Major
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.
PR NumberSynopsisCategory: Security platform jweb support
1725808
Critical
Junos OS: J-Web: Multiple vulnerabilities resolved in PHP software (CVE-2023-0567, CVE-2023-0662, CVE-2023-3823, CVE-2023-3824, CVE-2023-0568)
Product-Group=junos
Severity=Critical
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88120 [juniper.net] for more information.
1916722
Minor
Software upgrade via J-Web does not work on specific SRX platforms while using Upload Package option
Product-Group=junos
Severity=Minor
The Upload Package option does not work on all non-vmhost SRX platforms ( all SRX platforms except SRX5K with SRX5K-RE3, SRX1600, SRX2300, SRX4120, SRX4300) or vSRX when J-Web is used to upgrade the software release.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1905196
Minor
Stale entry in MAC-IP table affects ARP resolution
Product-Group=junos
Severity=Minor
On all Junos OS platforms, when an IP address already exists in the MAC-IP table as a remote entry and then an IRB (Integrated Routing and Bridging) interface is configured with the same IP address but a different MAC address, then the L2ALD (Layer 2 Address Learning Daemon) does not handle the update correctly, leading to incorrect ARP (Address Resolution Protocol) resolution.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1873587
Minor
[MX] "smid ../ licsubs/ bsd12/ liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" logs flood in license_flex_subs_trace.log.
Product-Group=junos
Severity=Minor
"smid ../../../../../../ src/junos/lib/libsdb/ licsubs/ bsd12/ liblicense_subs_os.c liblic_subs_total_active_licenses_in_use XXX" messages can be seen so frequent interval in license_flex_subs_trace.log.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=junos
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1923867
Major
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms with Graceful Restart and RSVP-TE (Resource Reservation Protocol - Traffic Engineering) configured, an rpd crash is observed, leading to traffic impact after a Graceful Restart if a PVC (Permanent Virtual Circuit) fails to allocate correctly during this recovery process, leaving it in an incomplete or unallocated state, and the system attempts to clean up or remove this unallocated PVC.
PR NumberSynopsisCategory: ACX Timing software
1900889
Major
[ACX710] acx-arm-feb process is 100% utilised after upgrading Junos to 23.2R2-Sx releases and enabling interfaces with PTP/ SyncE configuration.
Product-Group=junos
Severity=Major
After upgrading Junos on ACX710 to a 23.2R2-Sx release, the acx-arm-feb process may run at 100 percent utilization if PTP/SyncE is operational and the associated interfaces are up. The condition persists even when the affected interfaces are disabled and the system is rebooted.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
PR NumberSynopsisCategory: JUNOS Network App Infrastructure (for ping, traceroute, etc)
1876690
Major
ntp process may restart when issue the "show system ntp threshold" command
Product-Group=junos
Severity=Major
The ntp (or xntpd) process is initialized when the "show system ntp threshold" command is issued. This has no impact to system operation.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
1912250
Major
BFD sessions will not come up on Junos OS and Junos OS Evolved platforms due to keychain names overlapping
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms, where BFD with authentication key chain names are overlapping due to which BFD (Bidirectional Forwarding Detection) sessions will not come up in few scenarios like restart bfdd, restart ppmd, restart FPC.
PR NumberSynopsisCategory: L2NG PVLAN feature
1916610
Minor
Primary VLAN mapping causes MAC learning failure on PVLAN inner port
Product-Group=junos
Severity=Minor
On EX2300 platform, A Private VLAN (PVLAN) issue occurs where Media Access Control (MAC) learning works correctly for Isolated and Community Virtual Local Area Network (VLAN) access ports, but when the Primary VLAN is assigned to an inner VLAN port, the switch stops forwarding traffic and no Media Access Control addresses are learned after committing the configuration. This issue impacts services on interfaces configured with PVLAN.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1897459
Minor
qfx5120-48y-8c/23.4R2-S3.9/Flooding back GARP BUM traffic towards source.
Product-Group=junos
Severity=Minor
When EVPN is configured on Broadcom-based platforms, GARP reply packets are flooded and may be sent back toward the source device. With this fix, GARP reply packets will be terminated rather than flooded.
PR NumberSynopsisCategory: RPD Interfaces related issues
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1830588
Critical
The rpd process crashes on all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms when recursively resolved routes are changed or deleted, route churn will potentially lead to the rpd process crash.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1879698
Minor
Post Upgrade Junos no longer shows logical system name on show commands followed by logical-system all
Product-Group=junos
Severity=Minor
The output for all show commands with prefix "logical-system all" is changed and now it doesn't show the logical-system name. there are different ways with which it can be seen again: show route logical-system all | display xml show route logical-system
PR NumberSynopsisCategory: MX SCBE3 specific timing and synchronization issues
1902478
Major
After the deactivation of the PTP protocol in the G.8275.1 profile configuration, SyncE remained in Holdover mode.
Product-Group=junos
Severity=Major
In G.8275.1 Hybrid mode of operation, when PTP only is deactivated, SyncE shall not lock to the SyncE source and DPLL shall remain in Holdover state.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
Severity=Major
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.
1895644
Minor
On Branch SRX platforms, Power button and Reset Config button do not work as expected
Product-Group=junos
Severity=Minor
On Branch SRX platforms (SRX300, SRX320, SRX340, SRX345 and SRX380), Power button and Reset Config button do not work as expected.
PR NumberSynopsisCategory: SRX-1RU platfom datapath SW defects
1916367
Minor
High CPU utilization in packet forwarding engine caused by firewall filter count action
Product-Group=junos
Severity=Minor
On all SRX, vSRX and MX platforms with MX-SPC3, configuring a firewall filter term with the count action will cause high CPU utilization in the Packet Forwarding Engine (pfe) process. Frequent packet matches to a 'count' introduce additional packet-processing overhead in the forwarding data plane and under high-rate traffic this will lead to performance degradation, reduced throughput, and potential traffic loss.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1899826
Major
Macsec traffic stops working after performing a LMIC reboot
Product-Group=junos
Severity=Major
On MX304 when performing an OFFLINE/ONLINE operation on the LMIC (Line-Card Module Interface Card), in scale scenarios the MACsec traffic becomes stuck, resulting in traffic impact.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1909930
Major
24.4R2-S1:JUNOS:MACSEC: When connectivity-association properties mka eapol-address is set to unicast address, then MKA session stays in in-progress
Product-Group=junos
Severity=Major
When AE interface (member links) are configured with MACsec, the MKA session establishes successfully when the default standard MAC address is used. However, when a custom unicast MAC address is configured, the MKA session does not come up. This is not a common use case, but the workaround is to allow the MKA session to operate with the default MAC address instead of a custom unicast MAC address.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1901312
Major
Firewall filter not processing traffic with flex offset configuration is enabled
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platform in applicable MX series and EX92xx, when firewall filter with flex-offset is configured and if there is term to match less than 4 bytes offset towards end of the packet, then filter drops the packet and user can see traffic drop for that particular firewall term.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
Severity=Major
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.
1921361
Major
Slow memory leak triggered by subscribing to the pipeline sensor for a long duration
Product-Group=junos
Severity=Major
On Junos platforms with MPC 1-9, LC2101, LC480, LC2103 line-cards and MX204, a slow memory is observed when subscribing to the pipeline sensor ( path is /components/component/integrated-circuit/pipeline-counters/). Over time, this causes a gradual increase in heap memory usage. Increase in heap memory usage beyond a certain threshold will lead to FPC crash resulting in loss of services and traffic over that FPC.
1922741
Minor
FPC heap memory will be leaked when CCNHs are recreated due to VPLS PNH are getting deleted and re-added or next-hop is changed on BGP-LU LSP
Product-Group=junos
Severity=Minor
On Junos MX platforms with MPC1-9, when "set protocols l2circuit resolution preserve-nexthop-hierarchy" is enabled, FPC heap memory could get leaked when CCNHs (Chained Composite Next Hops) are recreated because of the VPLS (Virtual Private LAN Service) PNH (Preserve Nexthop Hierarchy) are getting deleted and re-added or next-hop is changed on BGP (Border Gateway Protocol)-LU (Labeled Unicast) LSP (Label Switched Path).
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1562848
Major
The mustd process may crash on all platforms
Product-Group=junos
Severity=Major
With a large-scale configuration, in rare cases, the mustd process might crash. The mustd process, which is responsible for configuration constraint checks, might crash on commit, leading to commit failure.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1761939
Major
CLI users cannot access configuration mode on Junos and Junos OS Evolved platforms
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms due to the mgd(Management Daemon) process not releasing commit lock, CLI users cannot change the configuration. CLI users cannot access configuration mode when maximum edit sessions limit is reached in this state. There is no service impact due to this issue.
1863354
Minor
Command line freezes when Ctrl+Z is used
Product-Group=junos
Severity=Minor
In Junos OS Releases 24.2 and later(BSD 15), pressing Ctrl+Z in the Command Line Interface CLI suspends the process and causes it to become unresponsive. This behaviour is observed on systems using the and Berkeley Software Distribution BSD15 platform.
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
Severity=Minor
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1853209
Major
Syslog forwarding intermittently stops post DUT reboot on virtual devices.
Product-Group=junos
Severity=Major
On virtual devices, on reboot, vpn may take time to come up. Meanwhile since mgmt_junos is first in the routing table, syslog gets bound to mgmt_junos and hence forwarding stops.
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1843789
Critical
Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI
Product-Group=junos
Severity=Critical
A core-dump issue has been identified in the Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI. This may lead to an abrupt session termination and CLI disruption.
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Timing defect in ukern thread handling causing LC reboot
Product-Group=junos
Severity=Major
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
Severity=Critical
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

 


 

24.4R2-S3 - List of Known issues

PR NumberSynopsisCategory: Software documentation- ex-series
1905956
Major
[EX4400-48F]: With 1g SFP-T, when DUT:Speed=100m and Peer:Speed=10m, link fails to come up.
Product-Group=junos
With SFP-T optics and DUT configured speed=100M with Auto-Neg enabled and peer configured speed=10M with Auto-Neg enabled. Link will not come up

Resolved In:
PR NumberSynopsisCategory: access node control protocol daemon
1877794
Major
The L2BSA subscriber fails to logout when "auto-configure-trigger" knob is edited on ANCP neighbour of MX platforms
Product-Group=junos
On all MX platforms with Access Node Control Protocol(ANCP) configured, the knob auto-configure-trigger on ANCP neighbor if edited (deactivate and activate) between system boot-ups, is not getting applied to the ANCP neighbour correctly. As a result, if an ANCP session goes down and the adjacency-loss-hold-time expires, the Layer 2 Bit Stream Access(L2BSA) interface still remains up indefinitely and the subscribers will fail to logout. Chassis needs to be rebooted after editing the configuration.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S2-J13 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: BBE UP Session Manager related issues
1890895
Major
BNG Controller: Issue with changing the IP address of an active BNG user-plane
Product-Group=junos
BNG Controller: Issue with changing the IP address of an active BNG user-plane

Resolved In:
PR NumberSynopsisCategory: Border Gateway Protocol
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:22.3X60 junos:23.2R2-S5 junos:25.2R1
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=junos
On all Junos and Junos OS Evolved platforms, after interface configuration rollback, sessions stay in Idle state when multiple BGP(Border Gateway Protocol) sessions exist.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S6-J14 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.

Resolved In: evo:22.4R3-S9-EVO evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1886633
Major
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.
Product-Group=junos
Logs from internal ethernet links monitoring script keep repetitively logged to /var/log/messages file if "set system syslog file messages user any" config is used.

Resolved In:
PR NumberSynopsisCategory: MX Platform SW - Environment Monitoring
PR NumberSynopsisCategory: MX Platform SW - UI management
1906927
Minor
SNMP OID jnxDomCurrentLaneWarnings values are using lane 0 value causing other lanes value incorrect
Product-Group=junos
When a interface supports multiple lanes, the SNMP OID jnxDomCurrentLaneWarnings is incorrectly handled as a single lane, resulting in the value from lane 0 being replicated across all other lanes.

Resolved In:
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVPN control plane issues
1916656
Major
Incorrect CCC state displayed when IFL or interface status is absent
Product-Group=junos


Resolved In: evo:24.2R2-S4-EVO evo:24.2X2-EVO evo:25.2R2-EVO evo:25.4R1-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:24.2R2-S4 junos:25.2R2 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: EX interfaces issues
1870962
Major
In EX4400 devices with 4x25G or 1x100g ULM, when we perform PIC online, CPU hog by CMQFX thread may be seen
Product-Group=junos
In EX4400 devices with 4x25G or 1x100g ULM, when we perform PIC online, CPU hog by CMQFX thread may be seen for as much as 3.5seconds

Resolved In:
PR NumberSynopsisCategory: EX optics issues
1864715
Major
EX4100: 10g-BASE-T didn't come up after dc-pfe restart
Product-Group=junos
After multiple iterations of dc-pfe process restart, we may see interface with 10g-base-t transceiver (part# 740-123734) will not come up.

Resolved In:
1887303
Minor
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1916949
Major
IPv6 Multicast traffic on non-IRB interfaces causes traffic loops and MAC move on QFX10K
Product-Group=junos
The IPv6 multicast packet gets flooded by the DF Spine to NDF and ESI leafs, loops back to the Spine, and causes the switch to see the same MAC on different ports, resulting in a traffic loop and MAC flapping.

Resolved In: junos:24.2R2-S4
PR NumberSynopsisCategory: SRX1500 platform software
1905001
Minor
FPC stuck in network loop scenario
Product-Group=junos
On SRX1500 in network loop scenarios, FPC gets stuck and traffic drop happens. System can be recovered by rebooting the device.

Resolved In: junos:25.2R2 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Express ASIC interface
1793344
Major
The 10g channelized Interface doesn't come up after router reboot on the PTX5000 platform
Product-Group=junos
On Junos PTX5K platforms running 22.3X60 configured with FPC3-PTX-U2 and FPC3-PTX-U3, the 10g channelized Interface port doesn't come up after router reboot. In rare conditions, the interface might remain down when firmware attempts to configure the line-side lane configuration during the firmware mode set process.

Resolved In: junos:22.3X60 junos:22.4R3-S5
PR NumberSynopsisCategory: Signature Database
1919218
Minor
Adding new CLI option to jist conversion command.
Product-Group=junos
Adding new CLI option to jist conversion command. > request security idp jist-conversion ? Possible completions: input-file Snort rules file output-file Redirect converted attacks-set commands to this file best-effort-conversion Best effort conversion, skip unsupported Snort modifiers

Resolved In: evo:26.2R1-EVO
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1889298
Major
On SRX devices running Multi-Node High Availability (MNHA), the iked process crashed due to repeated negotiation failures, which led to a VPN outage.
Product-Group=junos
On SRX devices running Multi-Node High Availability (MNHA) and IPSec, the IKED process may crash due to a high number of unsuccessful VPN negotiations. To restore the VPN environment, the active node must be rebooted.

Resolved In: junos:22.4R3-S5-J6 junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result into l2ald process crash
Product-Group=junos
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile has same profile index allocated then the storm control profile configuration and system state may not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.

Resolved In: evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:25.2R2 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface em0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: TCP/UDP transport layer
1893210
Minor
Master RE crashed and triggered unexpected switchover due to memory corruption
Product-Group=junos
On all Junos OS platforms, In Nonstop active routing (NSR) enabled system Routing Engine (RE) crash can occur due to a double free of a memory buffer (mbuf) was not handled properly leading to memory corruption causing synchronization issue and triggers unexpected switchover.

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).

Resolved In: junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X9 junos:24.2R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: PTX10K Routing Engine
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:24.2R2-S4 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5 junos:22.4R3-S9
PR NumberSynopsisCategory: SRX branch platforms
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
On all Junos platforms, FPC (Flexible PIC Concentrator) crashes due to panic caused by incorrect handling of an application. This causes service impact since the card restarts after crash.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J23 junos:23.4R2-S4-J30 junos:23.4R2-S6 junos:24.2R2-S4 junos:25.2R2
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1903047
Minor
Intermittent traffic loss after pfe reset due to FLT filters
Product-Group=junos
On all Junos MX platforms with line cards MPC7/8/9 (EA Asic) , if any PFE restarts as part of any encountered CM Error defects, then fast-lookup-table filters will not work properly and traffic black holing will be seen.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:23.2R2-J22 junos:24.2R2-J11 junos:24.2R2-S2-J12 junos:24.2R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:19.2R3-S12 junos:19.3R3-S13 junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: Ephemeral Database
1717477
Major
The system processes accessing the ephemeral database can crash
Product-Group=junos
On all Junos and Junos OS Evolved supporting ephemeral databases, due to a race condition, when a system process reads configuration from ephemeral database and in parallel, there is a commit in the static database, the system process crashes.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R0-J0-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.2X33 junos:21.2X9 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1882584
Minor
SERDES link errors observed on SIB8 modules due to power rail instability
Product-Group=junos
On Junos platforms utilizing the JNP10008-SF (aka SIB8), systems experience CRC errors on fabric links between the SIB and the FPC (Flexible PIC Concentrator). These errors are attributed to electrical noise on an internal power rail within the SIB. This condition will lead to multiple FPC-to-SIB link failures, potentially affecting traffic forwarding and overall fabric stability.

Resolved In: junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50

 


 

Modification History

First publication 2026-02-11