Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX10003

Alert Description

Junos Software Service Release version 19.3R3-S13 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 19.3R3-S13 is now available.

19.3R3-S13 - List of Fixed issues

PR NumberSynopsisCategory: "agentd" software daemon
1791928
Critical
Junos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribing to sensors chassisd or rpd will crash (CVE-2026-21921)
Product-Group=junos
Severity=Critical
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA106021 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1883803
Major
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash (CVE-2025-59959)
Product-Group=junos
Severity=Major
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA103148 [juniper.net] for more information.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: MX Platform SW - Environment Monitoring
1854693
Major
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash (CVE-2025-60007)
Product-Group=junos
Severity=Major
A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA103173 [juniper.net] for more information.
PR NumberSynopsisCategory: Device Configuration Daemon
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
Severity=Major
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.
PR NumberSynopsisCategory: Firewall Filter
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1718165
Major
ARP learning issues are observed post-execution of the CLI command 'clear bridge mac-table' or 'clear ethernet-switching table' in the EVPN-MPLS over IRB environment
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, L3 (Layer 3) traffic will be impacted when ARP (Address Resolution Protocol) entries get deleted for the MAC (Media Access Control) address having a bad state post execution of the CLI 'clear bridge mac-table' or 'clear ethernet-switching table' command in the EVPN-MPLS (Ethernet VPN - Multiprotocol Label Switching) over IRB (Integrated routing and bridging) environment.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1825998
Major
DHCP ALQ process crashes to recover from memory leak.
Product-Group=junos
Severity=Major
On all Junos platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
1876407
Major
Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP server (CVE-2025-59960)
Product-Group=junos
Severity=Major
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved on ACX Series allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server. Please refer to https://supportportal.juniper.net/JSA103149 [juniper.net] for more information.
1877468
Critical
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable (CVE-2025-59961)
Product-Group=junos
Severity=Critical
An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource. Please refer to https://supportportal.juniper.net/JSA103150 [juniper.net] for more information.
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1876029
Major
Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash (CVE-2026-21905)
Product-Group=junos
Severity=Major
A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA106004 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1783738
Major
The kmd/iked process crashes under rare circumstances
Product-Group=junos
Severity=Major
On Junos SRX/MX platforms, VPNs (Virtual Private Network) that employ the use of KMD (ipsec-key-management) or IKED (ike-key-management) may inadvertently crash while generating the random number used by IPSec services which can cause the device to become very busy.
1922670
Critical
KMD process crash during RG0 failover with ADVPN shortcuts in HA cluster
Product-Group=junos
Severity=Critical
On SRX and MX platforms using the IPsec Key Management Daemon (KMD), RG0 failover or failback while Auto Discovery VPN (ADVPN) shortcuts are active may cause the KMD process to crash, temporarily disrupting ADVPN sessions.
PR NumberSynopsisCategory: Firewall Policy
1847877
Major
The mgd process crash is observed during large amount of configurations
Product-Group=junos
Severity=Major
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.
1882193
Critical
On SRX platform, flowd process is generating crash files
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: lldp sw on MX platform
1890978
Major
Memory corruption in LLDP telemetry API when handling custom TLVs larger than 32 bytes, leads to L2cpd process crash
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, a memory corruption vulnerability exists in the Link Layer Discovery Protocol (LLDP) telemetry API. When a Protocol Data Unit (PDU) contains custom LLDP TLV (TypeLengthValue)values exceeding 32 bytes, it can trigger a crash in the l2cpd process. This crash may lead to service impact, including traffic loss and impaired functionality of protocols such as LLDP, STP (Spanning Tree Protocol), MVRP (Multiple VLAN Registration Protocol) and ERPS (Ethernet Ring Protection Switching).
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1802447
Major
failed to copy file '//var/etc/if_alias_map+' to 're1' error when user authenticated via tacacs comitting netconf configuration change
Product-Group=junos
Severity=Major
Commit error issue via netconf session
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
Severity=Major
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.
PR NumberSynopsisCategory: Issues related to PKI daemon
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
Severity=Major
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1812009
Major
The rpd process crash is observed when there are catastrophic changes under the particular routing instance configuration
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberSynopsisCategory: Scuba fabric software
1807812
Major
MX platforms with some MPCs could run into cm_error during ungraceful SIB or Peer-FPC power off event or due to bad fabric links
Product-Group=junos
Severity=Major
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
Severity=Major
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1897464
Critical
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
Severity=Critical
On all affected platforms, under rare conditions involving heavy control-plane churn and a large number of interfaces within a routing instance, memory allocation failures related to Next-Hop processing will occur. This can lead to traffic drops and, in severe cases, complete service disruption across multiple FPCs.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1795940
Major
The ARP resolution will fail on the interface when the default ARP policer fails to program.
Product-Group=junos
Severity=Major
On AFT(Advanced Forwarding Toolkit) based MX platforms, default ARP(Address Resolution Protocol) policer fails because of which ARP resolution fails on the interface and hence the traffic gets impacted.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Critical
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1882028
Critical
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash (CVE-2026-21914)
Product-Group=junos
Severity=Critical
An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). Please refer to https://supportportal.juniper.net/JSA106015 [juniper.net] for more information.
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
Severity=Major
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

 


 

Extended Solution

19.3R3-S13 - List of Known issues

PR NumberSynopsis
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junosvae
PR NumberSynopsis
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junosvae
PR NumberSynopsis
1492449
Major
While verifying the Last-change op-state value through XML, the rpc-reply message is inappropriate.
Product-Group=junos
PR NumberSynopsis
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
PR NumberSynopsis
1776216
Major
IPsec Tunnel behind NAT stops passing traffic when the NAT port Number or IP address changes
Product-Group=junos
PR NumberSynopsis
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
PR NumberSynopsis
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
PR NumberSynopsis
1840825
Major
Junos OS: ACX Series: When 'hot-standby' mode is configured for an L2 circuit, interface flap causes the FEB to crash (CVE-2025-52947)
Product-Group=junos
PR NumberSynopsis
1688613
Major
Telemetry sensor will not stream data if using key value as wildcard '*' character for gNMI in the PFE supported sensor
Product-Group=junos
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/lane_laser_receiver_power_dbm" and "optics/lanediags/lane/lane_laser_output_power_dbm" are unreadable
Product-Group=junos
PR NumberSynopsis
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
PR NumberSynopsis
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
PR NumberSynopsis
1818781
Major
Multiple BBE daemons getting killed automatically on MX platforms
Product-Group=junos
PR NumberSynopsis
1848887
Major
Routing-services enabled on PPPoE dynamic profile causes subscriber login failure for new subscribers
Product-Group=junos
PR NumberSynopsis
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
PR NumberSynopsis
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
PR NumberSynopsis
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
PR NumberSynopsis
1669930
Critical
BGP inactive routes might not be advertised to peers in BGP-LU scenario
Product-Group=junos
1696328
Major
The rpd process will crash on all Junos and Junos OS Evolved platforms when BGP multipath is enabled
Product-Group=junos
1750441
Major
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-30395)
Product-Group=junos
1754935
Major
BGP multipath route is not correctly applied after changing the IGP metric
Product-Group=junos
1756603
Major
RPD process crash is seen on high scale peering scenario where the sessions are un-configured/shutdown abruptly
Product-Group=junos
1766960
Minor
Junos OS and Junos OS Evolved: Junos OS and Junos OS Evolved: Receipt of a specific BGP UPDATE causes an rpd crash on devices with BGP multipath configured (CVE-2025-52964)
Product-Group=junos
1793714
Major
BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=junos
1807533
Critical
Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash (CVE-2024-39525)
Product-Group=junos
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
1851205
Major
Junos OS and Junos OS Evolved: When route validation is enabled, route validation cache connection establishment leads to an rpd crash (CVE-2025-52958)
Product-Group=junos
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
1855477
Critical
Junos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session reset (CVE-2025-52953)
Product-Group=junos
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
1877332
Minor
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
1878812
Critical
Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash (CVE-2025-60003)
Product-Group=junos
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=junos
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
1915893
Major
PTX10001-36MR - rpd crashed while stale route LLGR timer expired
Product-Group=junos
PR NumberSynopsis
1685510
Major
With BMP rib-in, many BGP routes remain in hold down state after route churn
Product-Group=junos
1798164
Critical
BMP reaches a state where no data is sent out to BMP Station
Product-Group=junos
PR NumberSynopsis
1648377
Major
The rpd process crashes when BGP-LU with the prefix-sid attribute is enabled in Segment Routing scenario
Product-Group=junos
PR NumberSynopsis
1822300
Major
Junos OS and Junos OS Evolved: Vulnerability in the RADIUS protocol for Subscriber Management (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
PR NumberSynopsis
1854658
Major
The chassisd process crashes when commit command is issued multiple times
Product-Group=junos
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
PR NumberSynopsis
1921796
Major
VRRP traffic dropped after priority change due to pinned MAC entry on peer device
Product-Group=junos
PR NumberSynopsis
1491492
Major
The match condition of forwarding-class for IPv6 filter might not capture the correct forwarding-class for the host outbound traffic
Product-Group=junos
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
1903874
Major
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
PR NumberSynopsis
1851909
Major
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash (CVE-2026-21920)
Product-Group=junos
PR NumberSynopsis
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
PR NumberSynopsis
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
PR NumberSynopsis
1853294
Major
Packet loss observed across multiple traffic items using SR profiles within the L3VPN
Product-Group=junos
PR NumberSynopsis
1764083
Major
Interface flaps leading to PFE crash due to FPC heap corruption
Product-Group=junos
PR NumberSynopsis
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
PR NumberSynopsis
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
PR NumberSynopsis
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
PR NumberSynopsis
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
PR NumberSynopsis
1802464
Major
VXLAN/EVPN ip-address for mac-address in forwarding table in hold state
Product-Group=junos
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=junos
PR NumberSynopsis
1825281
Major
Random ports of EX4400 will not be created on upgrade or reboot
Product-Group=junos
PR NumberSynopsis
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
PR NumberSynopsis
1823764
Major
, In virtual-chassis after routing-engine switchover traffic of type 5 routes of EVPN-VXLAN are not getting forwarded
Product-Group=junos
1847849
Critical
Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop (CVE-2026-21910)
Product-Group=junos
PR NumberSynopsis
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
PR NumberSynopsis
1865354
Major
Traffic to anycast IPv6 destination addresses dropped when using ECMP routes
Product-Group=junos
PR NumberSynopsis
1905490
Major
On MX10003 with FIPS enabled, KATs failure in SMIC_QSFP28_MACSEC_TIC causes system halt
Product-Group=junos
PR NumberSynopsis
1793344
Major
The 10g channelized Interface doesn't come up after router reboot on the PTX5000 platform
Product-Group=junos
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
PR NumberSynopsis
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
PR NumberSynopsis
1906675
Major
Link failure due to auto-negotiation state getting stuck on MX platforms having Junos OS
Product-Group=junos
PR NumberSynopsis
1696598
Major
Wrong SRTE Secondary path weight makes the secondary path active in forwarding table
Product-Group=junos
1778841
Major
With protocol ISIS configured, any new LSP generation triggers SPF
Product-Group=junos
PR NumberSynopsis
1885178
Major
Memory leak and DHCP process crash occur on all platforms using DHCP short-cycle protection with the client-discover-match feature
Product-Group=junos
PR NumberSynopsis
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
PR NumberSynopsis
1788400
Major
SNMP walk timeout
Product-Group=junos
PR NumberSynopsis
1834338
Major
GRE traffic is getting blocked due to a software programming issue and MTU going below minimum value
Product-Group=junos
1868005
Major
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash (CVE-2026-21906)
Product-Group=junos
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
1892015
Major
Junos MX/SRX flowd Crash After Tunnel Removal Leaves Stale Flows, Causing FPC Reboot
Product-Group=junos
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
PR NumberSynopsis
1839910
Major
Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash (CVE-2025-52981)
Product-Group=junos
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
PR NumberSynopsis
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
PR NumberSynopsis
1895790
Major
Backup node stuck in cold sync failure after FPC (Flexible PIC Concentrators) reset due to PFE crash in SRX chassis cluster
Product-Group=junos
PR NumberSynopsis
1841364
Major
The kmd process crash is seen on random number generation by the third-party library API
Product-Group=junos
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
PR NumberSynopsis
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
PR NumberSynopsis
1899131
Major
Multicast packets are getting dropped when multicast is configured in strict-ordering mode
Product-Group=junos
PR NumberSynopsis
1933239
Major
The FPC restarts on SRX series platforms when session-persistence-scan is configured
Product-Group=junos
PR NumberSynopsis
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
PR NumberSynopsis
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
1901732
Major
VPN traffic stops flowing intermittently on the st0 interface on SRX platforms
Product-Group=junos
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
PR NumberSynopsis
1689702
Major
mcontrol misses keepalives from backup RE, mcontrol_ore_alive_set: other RE is not alive
Product-Group=junos
PR NumberSynopsis
1863228
Major
IFL configured on the LAG interface goes down when the VLAN operation is changed
Product-Group=junos
PR NumberSynopsis
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=junos
PR NumberSynopsis
1607372
Critical
The fxpc process might crash and generate a core file
Product-Group=junos
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=junos
PR NumberSynopsis
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
PR NumberSynopsis
1789663
Major
Unexpected rpd crash when huge amount of telemetry data is being streamed
Product-Group=junos
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
PR NumberSynopsis
1719682
Major
LACP interface will be down after aggressive link flaps with 100ms interval
Product-Group=junos
1727066
Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
Product-Group=junos
PR NumberSynopsis
1798780
Major
The system goes into a bad state when an SFB ungraceful offline happens due to a fatal Interrupt
Product-Group=junos
PR NumberSynopsis
1793982
Minor
Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash (CVE-2026-21909)
Product-Group=junos
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
1923867
Major
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
PR NumberSynopsis
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
PR NumberSynopsis
1846557
Critical
When "set chassis redundancy failover on-re-to-fpc-stale" is configured unexpected master RE switchover will be seen if backup RE reboots resulting in traffic disruption
Product-Group=junos
PR NumberSynopsis
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
PR NumberSynopsis
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
1910534
Major
SPC3 crashes when three-color policer is attached to firewall filter
Product-Group=junos
PR NumberSynopsis
1819102
Critical
Junos OS: Specific unknown traffic pattern causes FPC and system to crash when packet capturing is enabled (CVE-2025-52948)
Product-Group=junos
PR NumberSynopsis
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
PR NumberSynopsis
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
PR NumberSynopsis
1645221
Major
Junos OS and Junos OS Evolved: RPD crash upon receipt of specific OSPFv3 LSAs (CVE-2022-22230)
Product-Group=junos
PR NumberSynopsis
1583480
Major
The egress traffic might be dropped after flapping the inet6 family from the AEx bundle
Product-Group=junos
1713279
Major
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
PR NumberSynopsis
1811521
Major
PHC gets initiated and sends DNS request to Juniper server "redirect.juniper.net" even when device is supposed to get provisioned using ZTP with vendor specific option 43
Product-Group=junos
PR NumberSynopsis
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
PR NumberSynopsis
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
PR NumberSynopsis
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
PR NumberSynopsis
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
PR NumberSynopsis
1698894
Major
The communication between primary and backup Routing Engines breaks in the event of scale network churn
Product-Group=junos
PR NumberSynopsis
1804090
Major
High storage utilization in /var/log due to uncompressed UKERN_GBL.log file
Product-Group=junos
1921455
Major
The dcpfe process crashes when adding or removing classifier configuration on QFX5210
Product-Group=junos
PR NumberSynopsis
1866016
Minor
Model: qfx5120-32c | Junos: 22.2R3-S4.10 | Management lost | JSD Coredumps observed
Product-Group=junos
PR NumberSynopsis
1823601
Major
Protocol traffic drops were seen in the network for any configuration change in the protocol
Product-Group=junos
1855990
Major
Traffic drop observed due to ECMP next-hop programming issue
Product-Group=junos
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
PR NumberSynopsis
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
PR NumberSynopsis
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
PR NumberSynopsis
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
PR NumberSynopsis
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
PR NumberSynopsis
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
PR NumberSynopsis
1756068
Major
Junos OS and Junos OS Evolved: With BGP sharding enabled, change in indirect next-hop can cause RPD crash (CVE-2025-59962)
Product-Group=junos
1858032
Major
The rpd process crashes when generate routes are configured in a rib-sharding scenario
Product-Group=junos
PR NumberSynopsis
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
PR NumberSynopsis
1807037
Major
BGP backup routes are installed as primary routes after enabling 'protect core' feature
Product-Group=junos
1834075
Major
Junos OS and Junos OS Evolved: When jflow/sflow is configured continuous logical interface flaps causes rpd crash and restart (CVE-2025-52955)
Product-Group=junos
1842654
Major
RPD process crash observed with dynamic tunnel configuration with overlap in destination networks under APP based and NHB mode and rollback
Product-Group=junos
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
PR NumberSynopsis
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
PR NumberSynopsis
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
PR NumberSynopsis
1811474
Major
In Junos MX platforms specifically MX2010 and MX2020 with SFB2 Fabric installed replacing MPC9E linecards with MPC6E linecards results in all SFB2 fabric get into check state and FPCs becomes destination error and offline
Product-Group=junos
PR NumberSynopsis
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
PR NumberSynopsis
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
PR NumberSynopsis
1807541
Major
SRX4600 with SOF is observed to continue sending ipv6 traffic out a downed member link.
Product-Group=junos
PR NumberSynopsis
1607810
Major
SecIntel Intelligence process crashes when the traffic source IP or destination IP hits Blacklist IP
Product-Group=junos
PR NumberSynopsis
1913911
Major
ARP reply packets may be sent out from the STP blocked port
Product-Group=junos
PR NumberSynopsis
1869285
Major
Speed conversion from 10G to 1G on MX routers with MPC7E-10G does not synchronise across PFE and Kernel when adding the interface to Aggregate Ethernet (AE)
Product-Group=junos
PR NumberSynopsis
1812276
Major
Persistent link error in one fabric plane towards some PFE could causes traffic blackholing from non-native LC PFE towards that remote PFE over all fabric planes
Product-Group=junos
PR NumberSynopsis
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
PR NumberSynopsis
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
PR NumberSynopsis
1712727
Major
Continuous vmcores observed on the secondary node when committing set system management-instance command
Product-Group=junos
1846340
Major
FPC0 will not transition to Online and may generate chassis alarm "FPC 0 Hard errors" in SRXTVP devices deployed in chassis cluster
Product-Group=junos
1904696
Major
FPC flaps and the Ukern process will crash on certain SRX platforms when the policer action is changed from 'discard' to 'loss-priority'
Product-Group=junos
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
PR NumberSynopsis
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
PR NumberSynopsis
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
PR NumberSynopsis
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
PR NumberSynopsis
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
PR NumberSynopsis
1890097
Major
Memory leak in FPC during login/logout
Product-Group=junos
PR NumberSynopsis
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
1933552
Critical
The traffic get looped when enhanced-convergence is enabled on MC-AE link and IRB interfaces when the CE device reboots
Product-Group=junos
PR NumberSynopsis
1913870
Major
Traffic is not passing through GRE-over-GRE tunnel due to keepalive packets are dropped in the outer tunnel
Product-Group=junos
PR NumberSynopsis
1686068
Major
Disabling PFE triggers the memory leak which may cause FPC to crash
Product-Group=junos
PR NumberSynopsis
1801213
Major
ISIS DDOS protection Max arrival rate shows incorrect values
Product-Group=junos
PR NumberSynopsis
1671112
Major
Test Configuration will fail even though the configuration file is having valid configurations
Product-Group=junos
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
PR NumberSynopsis
1562848
Major
The mustd process may crash on all platforms
Product-Group=junos
PR NumberSynopsis
1717477
Major
The system processes accessing the ephemeral database can crash
Product-Group=junos
PR NumberSynopsis
1514927
Critical
Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor (CVE-2025-59957)
Product-Group=junos
1736976
Major
qfx goes into amnesiac after a power outage and commit errors for scripts prevent recovery
Product-Group=junos
1761939
Major
CLI users cannot access configuration mode on Junos and Junos OS Evolved platforms
Product-Group=junos
1784818
Major
The non-root user will not be able to copy files
Product-Group=junos
1821845
Major
The system scripts refresh will fail when using load CLI option
Product-Group=junos
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
PR NumberSynopsis
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
PR NumberSynopsis
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=junos
PR NumberSynopsis
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=junos
PR NumberSynopsis
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
PR NumberSynopsis
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
PR NumberSynopsis
1898825
Major
Timing defect in ukern thread handling causing LC reboot
Product-Group=junos
PR NumberSynopsis
1819412
Major
Junos OS: After removing SSH public key authentication root can still log in (CVE-2025-52983)
Product-Group=junos
PR NumberSynopsis
1835860
Major
Fabric plane goes into check state and alarm is consistently seen along with traffic drop when ADC based line cards are restarted on certain MX platforms
Product-Group=junos
PR NumberSynopsis
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
PR NumberSynopsis
1814701
Major
, URL filtering sessions are bypassed on MX platform with SPC3
Product-Group=junos
PR NumberSynopsis
1844731
Critical
High heap memory caused MX-SPC3 PIC to go offline
Product-Group=junos
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
PR NumberSynopsis
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos

 

Modification History

First publication 2026-02-18