Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 24.2R2-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 24.2R2-S4 is now available.

24.2R2-S4 - List of Fixed issues

PR NumberSynopsisCategory: NFX Series Platform Software
1903544
Major
QCOW2 images larger than 4GB cause VNF boot failures
Product-Group=junosvae
Severity=Major
On Junos NFX150, NFX250, and NFX350 network services platforms, Virtual Network Functions (VNFs) fail to boot after upgrading to Junos OS 23.4 or later versions as the QEMU Copy-On-Write version 2 (QCOW2) image size exceeds 4GB.
PR NumberSynopsisCategory: "agentd" software daemon
1859761
Minor
Continuous AGENTD_PFE_SENSOR_ INSTALL_FAILED error messages on backup RE
Product-Group=junos
Severity=Minor
On Junos OS platforms with dual Routing Engines, the backup Routing Engine may repeatedly log AGENTD_PFE_SENSOR_INSTALL_FAILED error messages related to telemetry sensor installation. This issue is cosmetic and does not impact traffic forwarding, control-plane operation, or system stability. The issue has been resolved by improving resiliency in telemetry-related components to prevent unnecessary retry attempts on the backup Routing Engine.
1885622
Major
The aaasd process stops responding for RPC calls
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with gRPC configured, the aaasd process rejects incoming RPCs. This issue occurs in some rare cases, and aaasd will stop listening for authentication requests from reverse proxy. This issue does not cause a traffic impact.
PR NumberSynopsisCategory: SRX2000/50000 issue
1904267
Major
In SRX high availability cluster, RG0 failover to secondary node fails as srxpfe daemons failed to reconnect to routing-engine on secondary
Product-Group=junos
Severity=Major
On all Junos OS SRX except branch SRX platforms, in high availability scenario, during redundancy group (RG0) failover, all the FPC PICs need to reconnect to the new primary routing-engine on secondary node within 16 seconds timer. However, this is not happening which is causing a connection reset and impacting traffic.
PR NumberSynopsisCategory: BBE database related issues
1909540
Minor
config commit on Juniper ACX device hangs
Product-Group=junos
Severity=Minor
EVO includes an automatic cleanup mechanism that triggers when the /var/tmp partition usage exceeds 85%. The process deletes temporary files to prevent the partition from filling up completely, which could impact overall system performance or stability. Unfortunately important shared memory log files meant for subscriber management stored under /var/tmp, were deleted. Subsequently when a new configuration is being committed, subscriber management daemon pre-check fails, leading to commit failure.
PR NumberSynopsisCategory: Border Gateway Protocol
1838490
Minor
BGP_PREFIX_ THRESH_EXCEEDED warning message keeps flooding after accepted max prefix limit is reached
Product-Group=junos
Severity=Minor
With this PR fix, BGP_PREFIX_THRESH_EXCEEDED warning message will be stopped after the max prefix limit is reached. The behavior is consitent with prefix-limit feature.
1880630
Major
Scaled BGP sessions remain in the Idle state after interface rollback.
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, after interface configuration rollback, sessions stay in Idle state when multiple BGP(Border Gateway Protocol) sessions exist.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=junos
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.
1915893
Major
PTX10001-36MR - rpd crashed while stale route LLGR timer expired
Product-Group=junos
Severity=Major
PR NumberSynopsisCategory: BBE Remote Access Server
1813456
Minor
Error message is observed after device is restarted
Product-Group=junos
Severity=Minor
On all Junos Evolved platforms, the error message "UI_SCHEMA_SEQUENCE_ERROR" is observed when device is restarted. There is no traffic impact due to this issue.
PR NumberSynopsisCategory: bras licensing prs
1836179
Minor
The smid process restarts as BBE daemons and libraries use incorrect license
Product-Group=junos
Severity=Minor
On Junos MX OS platforms, the use of an incorrect license by BBE (Broadband Edge) daemons and libraries leads to the smid process consuming 100% CPU (Central Processing Unit), which causes the smid (Subscriber Management Infrastructure Daemon) to restart and results in memory corruption.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: MX304 line card platform software
1843577
Minor
Brief transient Temp Sensor Hot alarm observed on MX304 during reboot
Product-Group=junosvae
Severity=Minor
On MX304 platforms, a transient FPC xcvr Temp Sensor Hot alarm may briefly appear and then clear automatically during MIC power cycling or line card reboot operations. This condition occurs when temperature data has not yet been fully updated by the line card management daemon (lcmd). The alarm clears on its own and has no functional impact on the system or the hardware.
PR NumberSynopsisCategory: L2NG Access Security feature
1904091
Critical
During virtual chassis switchover causes default dead route creation
Product-Group=junos
Severity=Critical
On all Junos OS EX and QFX platforms in Virtual Chassis (VC) , during switchover, a race condition between the dcd (Device Control Daemon) and dhcpd (Dynamic Host Configuration Protocol Daemon) causes the dcd to delete Interface Address (IFA) objects that were previously configured by dhcpd. This results in the addition of a default dead route by rpd in the routing table of the new master switch after GRES, leading to services to be impacted.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: Firewall Filter
1859894
Major
MIB2D stucked at 100% on MX10003
Product-Group=junos
Severity=Major
On all MX platforms, during interface flaps with interface-specific / list filters we may see an error "get_counter_list_async: failed in reading counter names (No such file or directory)" due to internal clean-up missing. Please, note that this error is also seen during the churn. This could result in MIB2D hitting at 100% CPU if error remains consistent. The best way to escape this 100% CPU is to restart MIB2d process as soon as the said error is noticed and keep repeating with same counter name.
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
Severity=Major
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.
PR NumberSynopsisCategory: ACX platform interface issues
1887528
Minor
Optics fail to come up post reboot
Product-Group=junos
Severity=Minor
On all ACX5448 platforms, read errors are observed on 1G copper optics (SFP-T) modules during the device reboot, resulting in the 1G optics ports remaining down and impacting all services.
1896458
Minor
SFP-T port will not come up after system restart
Product-Group=junos
Severity=Minor
On Junos ACX5448 platforms, when the port with SFP-T copper optics is disabled or chassisd is restarted, Tx is disabled before the media is identified. This is a timing issue. The port will not come up even if disable is removed from the configuration. Reinserting the transceiver will resolve the issue.
1912165
Minor
[ACX5448] QSFP May Stop Functioning After Reboot-Related Operations Due to I2C Read Errors
Product-Group=junos
Severity=Minor
After performing operations that involve a reboot - such as system reboot, Junos upgrade/downgrade, or restart chassis-control - the QSFP module may detect I2C read errors and stop functioning. When this issue occurs, the following messages can be observed in the system log: Jan 11 11:11:11.111 20XX acx5448 fpc0 qsfp[RIO-MIC(0/1)(2)] I2C READ access reached max try qsfp_tk_i2c_rd_wr_access Jan 11 11:11:11.111 20XX acx5448 fpc0 RIO-MIC(0/1)(2): Reading the power-mode failed.
PR NumberSynopsisCategory: Dynamic rendering infrastructure
1915225
Major
cli-pfe does not terminate immediately when user issues Ctrl-C
Product-Group=junos
Severity=Major
A cli-pfe show command may continue to gather data in the background after the user issues a Ctrl-C. Eventually the background command will complete. However, the CPU usage for the cli-pfe process will continue to be high while it is still running.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1908719
Major
On all mx platforms chassid gets stuck and becomes unresponsive it resumes only after restarting both control units
Product-Group=junos
Severity=Major
On MX devices, the sub-linecard feature with MPC11 cards. When this feature is used, the main system process can sometimes freeze, which may lead to system crashes and error logs.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1889335
Minor
Traffic drop is observed in an EVPN multihoming as the MAC route points to the ESI interface when the CE (ESI) IFD flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, in an Ethernet Virtual Private Network (EVPN) MultiHoming setup with Ethernet Segment Identifier (ESI) configured under logical Interface (IFL) (CE-facing), when the corresponding IFD (Physical Interface) flaps, the MAC route will point to the ESI interface, while it should point to the Multihoming CE (Customer Edge) interface. This results in traffic loss.
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1884781
Major
Slow configuration commit observed on devices with a single Routing Engine (RE)
Product-Group=junos
Severity=Major
On all Junos OS Evolved platforms with single RE and the system type is cluster, a commit delay is observed when operating with a single RE. This occurs because the system attempts to synchronize with the second RE by default, but since it's not present, the process waits and causes the delay in commit.
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
1916656
Major
Incorrect CCC state displayed when IFL or interface status is absent
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved platforms, When the logical interface (IFL) is not present, the system incorrectly reports the Circuit Cross-Connect (CCC) state as CCC Up. Similarly, when the interface status itself is not available, the pseudowire state is shown as CCC_Up or CCC_Down. The pseudowire state should instead be reported as Not Applicable, since the underlying interface or IFL required to determine a valid CCC state does not exist. Displaying CCC Up/Down incorrectly in the absence of interface.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=junos
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.
PR NumberSynopsisCategory: EX interfaces issues
1909608
Minor
Auto-negotiation is not displayed in 'show interfaces' command output
Product-Group=junos
Severity=Minor
On EX3400 and EX4400-48F, when using 1G optics, the auto-negotiation information does not appear in the output of the "show interfaces" command.
1915222
Minor
Interfaces down after Virtual Chassis reboot
Product-Group=junos
Severity=Minor
On all Junos EX Series platforms, following a Virtual Chassis (VC) reboot, random interface links GE(Gigabit) and XE(10 Gigabit) intermittently appear in a down state at the Interface Descriptor (IFD) level, even though the physical link remains operational.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1926732
Major
DHCP clients fail to obtain an IP address when a VXLAN GBP profile is configured
Product-Group=junos
Severity=Major
On EX4100/EX4400/EX4650/QFX5120 platforms, when any VXLAN (Virtual Extensible LAN) Group-Based Policy (GBP) profile is configured, DHCP clients will fail to obtain an IP address. As a result, affected clients will lose network connectivity.
PR NumberSynopsisCategory: SRX1500 platform software
1910445
Major
Link status of disabled SFP-T port becomes up after rebooting on SRX1500
Product-Group=junos
Severity=Major
When an SFP-T port is disabled, it shows admin down but can be in a physical up state after a reboot.
PR NumberSynopsisCategory: MX MIC-3D-10GE-SFP-X driver
1906675
Major
Link failure due to auto-negotiation state getting stuck on MX platforms having Junos OS
Product-Group=junos
Severity=Major
On all Junos OS MX platforms that support MPC2E-NG, MPC2E-3D-NG-Q, MPC3E-NG and MPC3E-3D-NG-Q, the Auto-Negotiation (AN) process on certain PHY interfaces of the MIC (MIC-3D-10GE-SFP-E) may intermittently get stuck, preventing link establishment and causing traffic loss. This issue can be triggered by reinserting an SFP-T module, multiple times restarting the mic or by interface driver resets, which lead to inconsistent enable/disable sequences during Auto-Negotiation.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
Severity=Major
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.
PR NumberSynopsisCategory: ISIS routing protocol
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.
1925611
Minor
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface
Product-Group=junos
Severity=Minor
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
Severity=Major
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.
PR NumberSynopsisCategory: Flow Module
1873580
Major
The TCP session is not closing properly on the SRX4600 and SRX5K platforms after receiving the FIN-ACK message causing packets to drop for new session if reusing same source port
Product-Group=junos
Severity=Major
On SRX4600 and SRX5K platforms, when IDP (Intrusion Detection and Prevention) is configured in global policy, TCP (Transmission Control Protocol) sessions are not closing immediately after receiving the final FIN-ACK (finish-acknowledgement) message. If one end has initiated TCP session close by sending FIN packet and other end has sent an acknowledgement of FIN, IDP ignores the TCP session during processing of ACK packet as policy which accepts TCP packet is not configured with IDP application service. If other end device is reusing the same source port to initiate new connections, device drops because the existing session is still active.
1892015
Major
Junos MX/SRX flowd Crash After Tunnel Removal Leaves Stale Flows, Causing FPC Reboot
Product-Group=junos
Severity=Major
On Junos OS SRX and MX with SPC3 platforms, any tunnels such as GRE, IPIP, DS-Lite, or IPSEC tunnel has its configuration removed, the IKE SAs can go down causing invalid entires. These can later cause the flowd process to crash
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
Severity=Major
All Junos SRX platforms that support PMI (Power Mode IPsec) fat tunnel configuration may experience, FPC reboot in some occasional scenarios, when traffic hits FAT tunnel. The reboot is occasional in some timing scenarios and that timing is when system gets wrong data to process the traffic. Not all customer experience this, and so far a customer reported, the issue is seen every 2 weeks or more.
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.
1922670
Critical
KMD process crash during RG0 failover with ADVPN shortcuts in HA cluster
Product-Group=junos
Severity=Critical
On SRX and MX platforms using the IPsec Key Management Daemon (KMD), RG0 failover or failback while Auto Discovery VPN (ADVPN) shortcuts are active may cause the KMD process to crash, temporarily disrupting ADVPN sessions.
PR NumberSynopsisCategory: Firewall Policy
1882193
Critical
On SRX platform, flowd process is generating crash files
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.
1901732
Major
VPN traffic stops flowing intermittently on the st0 interface on SRX platforms
Product-Group=junos
Severity=Major
On Junos SRX platforms, Virtual Private Network (VPN) traffic stops even though the IPsec tunnel remains UP. This issue occurs when Class of Service (CoS) is configured on the secure tunnel (st0) interface. IPsec packet processing fails, and memory buffer (mbuff) resources are not freed, leading to resource exhaustion. As a result, encrypted traffic cannot be transmitted through the tunnel. The problem does not impact tunnel status or Internet Key Exchange (IKE) negotiation, but impacts the interface traffic.
PR NumberSynopsisCategory: Security platform jweb support
1725808
Critical
Junos OS: J-Web: Multiple vulnerabilities resolved in PHP software (CVE-2023-0567, CVE-2023-0662, CVE-2023-3823, CVE-2023-3824, CVE-2023-0568)
Product-Group=junos
Severity=Critical
PHP software included with Juniper Networks Junos OS J-Web has been updated to resolve multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88120 [juniper.net] for more information.
1916722
Minor
Software upgrade via J-Web does not work on specific SRX platforms while using Upload Package option
Product-Group=junos
Severity=Minor
The Upload Package option does not work on all non-vmhost SRX platforms ( all SRX platforms except SRX5K with SRX5K-RE3, SRX1600, SRX2300, SRX4120, SRX4300) or vSRX when J-Web is used to upgrade the software release.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1909786
Critical
EVPN traffic blackholing occurs when re-ARP uses VGA IP with IRB MAC in dual-homed LAG setups
Product-Group=junos
Severity=Critical
On all Junos OS platforms, when Ethernet VPN (EVPN) VXLAN is deployed with Integrated Routing and Bridging (IRB) interfaces configured with a Virtual Gateway Address (VGA) IP and MAC, the device generates re-ARP packets using the VGA IP as the source IP while using the IRB MAC as the source MAC. In all-active dual-homed Link Aggregation Group (LAG) environments, this behavior causes connected hosts to overwrite their ARP entries and bind the VGA IP to the IRB MAC instead of the virtual gateway MAC. As a result, traffic destined to the virtual gateway is forwarded to the wrong leaf switch, causing deterministic traffic blackholing for dual-homed hosts.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1911538
Major
Show command execution failure for show system macsec license on MX platforms
Product-Group=junos
Severity=Major
On all Junos MX10004, MX10008, MX304, MX301 platforms on executing the command "show system maces license" fails and doesn't fetch any information however it doesn't cause any service disruption. This is a Day-1 issue.
PR NumberSynopsisCategory: JNP10K-RE3 CB Centralized MX timing
1849943
Minor
"show snmp mib get <>" output is not proper for certain mibs
Product-Group=junos
Severity=Minor
On MX10008 platforms, "show snmp mib get <>" output is not proper for certain mibs.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=junos
Severity=Major
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.
1923867
Minor
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
Severity=Minor
On Junos OS and Junos OS Evolved platforms with Graceful Restart and RSVP-TE (Resource Reservation Protocol - Traffic Engineering) configured, an rpd crash is observed, leading to traffic impact after a Graceful Restart if a PVC (Permanent Virtual Circuit) fails to allocate correctly during this recovery process, leaving it in an incomplete or unallocated state, and the system attempts to clean up or remove this unallocated PVC.
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
Severity=Major
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.
1910534
Major
SPC3 crashes when three-color policer is attached to firewall filter
Product-Group=junos
Severity=Major
On MX platforms with SPC3, when three-color policer is configured and attached to firewall filter SPC3 crashes and flowd crash files are seen. This will cause service impact since SPC3 keeps crashing and may not come up if the configuration leading to crash is not deleted.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1879079
Major
SRX5600 and SRX5800 SPC3 are going offline after software upgrade
Product-Group=junos
Severity=Major
On SRX5600 and SRX5800 platforms configured in active/passive cluster, upgrading to Junos OS versions 24.4R2.1 or 25.X results in the Services Processing Card 3 (SPC3) on the primary node transitioning to an 'offline' state.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
PR NumberSynopsisCategory: QFX5K hostpath
1921455
Major
The dcpfe process crashes when adding or removing classifier configuration on QFX5210
Product-Group=junos
Severity=Major
On QFX5210 platform with Class of Service (CoS), the dcpfe process crashes when classifier is configured or removed on interface with active traffic. This can affect traffic forwarding till dcpfe process restarts post crash.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1897459
Minor
qfx5120 Flooding back GARP BUM traffic towards source.
Product-Group=junos
Severity=Minor
When EVPN is configured on Broadcom-based platforms, GARP reply packets are flooded and may be sent back toward the source device. With this fix, GARP reply packets will be terminated rather than flooded.
PR NumberSynopsisCategory: RPD Interfaces related issues
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
Severity=Major
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1853521
Major
BGP keeps trying to retrieve VPLS table info from the kernel even after the Layer2 instance is deactivated
Product-Group=junos
Severity=Major
On Junos OS Evolved platforms, when a Layer2 instance configuration is deactivated, the Kernel Routing Table (krt) continues attempting to retrieve VPLS table information from the kernel, even though the table has already been deleted. This results in repeated retries by krt.
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
Severity=Major
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
Severity=Major
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
PR NumberSynopsisCategory: Segment routing traffic Engineering
1911821
Minor
(SPRING-TE Entropy-label is not supported for segment-list with single label for tunnel) is reported in messages logs even if the entropy label feature is not configured
Product-Group=junos
Severity=Minor
On Junos and Junos Evolved where Segment Routing Traffic Engineering (SRTE) Tunnel is supported, the log message (RPD_SPRING_TE_ENTROPY_UNSUPPORTED_FOR_ONE_LBL: SPRING-TE Entropy-label is not supported for segment-list with single label for tunnel) is observed even when entropy label feature is not configured.
PR NumberSynopsisCategory: SRX branch platforms
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
Severity=Major
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.
1913911
Major
ARP reply packets may be sent out from the STP blocked port
Product-Group=junos
Severity=Major
On SRX300-series devices, when ethernet-switching is used with spanning-tree protocol enabled, in some cases ARP reply packets may be sent out from a spanning-tree blocked port.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1904696
Major
FPC flaps and the Ukern process will crash on certain SRX platforms when the policer action is changed from 'discard' to 'loss-priority'
Product-Group=junos
Severity=Major
On SRX4600, SRX4700, and SRX5K platforms, the Flexible PIC Concentrator (FPC) flaps and Ukern process will crash when the policer action is changed from 'discard' to 'loss-priority'. Traffic will be impacted when the FPC flaps.
1911845
Critical
SRX PFE crash is observed if nexthop limit is reached
Product-Group=junos
Severity=Critical
On all SRX platforms, SRX PFE ( Packet Forwarding Engine ) crash is observed if next-hops in the PFE next-hop table exceeds the limit 64k.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1927107
Major
FPC might crash with high scale of BBE subscriber
Product-Group=junos
Severity=Major
On MX304 and MX platforms with MPC10, MPC11, or LC9600, the Flexible PIC Concentrator (FPC) might crash when operating with a high scale of Broadband Edge (BBE) subscriber.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
Severity=Major
On all Junos platforms, FPC (Flexible PIC Concentrator) crashes due to panic caused by incorrect handling of an application. This causes service impact since the card restarts after crash.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1905768
Major
FPC crash triggered when a line card reboots with a large number of static subscribers
Product-Group=junos
Severity=Major
On all MX platforms with the MPCs/Line cards except MPC10E, MPC11E, LC9600 and MX304. When a line card hosting an AE ( Aggregate Ethernet ) interface with a large number of static subscribers (around 4000) reboots, excessive processing load across multiple subscriber interfaces will cause delays that trigger the watchdog timer and result in an FPC ( Flexible PIC Concentrator ) crash.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1890097
Major
Memory leak in FPC during login/logout
Product-Group=junos
Severity=Major
On all Junos platforms, when policer is attached to interface-specific filter, while mangling the policer name one residual string is not cleared, which is causing the memory leak.
1903047
Minor
Intermittent traffic loss after pfe reset due to FLT filters
Product-Group=junos
Severity=Minor
On all Junos MX platforms with line cards MPC7/8/9 (EA Asic) , if any PFE restarts as part of any encountered CM Error defects, then fast-lookup-table filters will not work properly and traffic black holing will be seen.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1913870
Major
Traffic is not passing through GRE-over-GRE tunnel due to keepalive packets are dropped in the outer tunnel
Product-Group=junos
Severity=Major
On Junos MX platforms with MPC ( 1 to 9 ) or LC2103 linecards and platforms ( MX5- MX80 ) / MX104 / MX150 / MX204; when Generic Routing Encapsulation (GRE)-over-GRE is configured, end-to-end keepalive packets in the outer tunnel are dropped, and tunnel interface cannot pass traffic.
1921361
Major
Slow memory leak triggered by subscribing to the pipeline sensor for a long duration
Product-Group=junos
Severity=Major
On Junos platforms with MPC 1-9, LC2101, LC480, LC2103 line-cards and MX204, a slow memory is observed when subscribing to the pipeline sensor ( path is /components/component/integrated-circuit/pipeline-counters/). Over time, this causes a gradual increase in heap memory usage. Increase in heap memory usage beyond a certain threshold will lead to FPC crash resulting in loss of services and traffic over that FPC.
1922741
Minor
FPC heap memory will be leaked when CCNHs are recreated due to VPLS PNH are getting deleted and re-added
Product-Group=junos
Severity=Minor
On Junos MX platforms with MPC1-9/LC480/LC2101, when "set protocols l2circuit resolution preserve-nexthop-hierarchy" is enabled, FPC heap memory will leak when CCNHs (Chained Composite Next Hops) are recreated because of the VPLS (Virtual Private LAN Service) PNH (Preserve Nexthop Hierarchy) are getting deleted and re-added.
PR NumberSynopsisCategory: DDos Support on MX
1860439
Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces
Product-Group=junos
Severity=Minor
DDOS/SCFD culprit-flows display wrong PPS on the detected subscriber demux0 interfaces.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1562848
Major
The mustd process may crash on all platforms
Product-Group=junos
Severity=Major
With a large-scale configuration, in rare cases, the mustd process might crash. The mustd process, which is responsible for configuration constraint checks, might crash on commit, leading to commit failure.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1761939
Major
CLI users cannot access configuration mode on Junos and Junos OS Evolved platforms
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms due to the mgd(Management Daemon) process not releasing commit lock, CLI users cannot change the configuration. CLI users cannot access configuration mode when maximum edit sessions limit is reached in this state. There is no service impact due to this issue.
1829614
Major
config rollback fails with commit error: Invalid XML from dfwd
Product-Group=junos
Severity=Major
after switchover in MX2010 platform , test config is removed with load update and then rollbacked. during rollback commit , config commit failed with below error: error: commit-check-daemon : Invalid XML from dfwd error: configuration check-out failed
1902713
Minor
The mgd process crash observed on running commit check after replace operation of groups name for apply-groups-except
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, when replace operation was done on apply-groups-except object it was not clearing the entry of that object from apply-groups-info-tree, as a result 'mgd' process crash observed on commit check. There is no service impact due to this issue.
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
Severity=Minor
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.
PR NumberSynopsisCategory: Issues related to NETCONF
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=junos
Severity=Critical
On ACX7024, ACX710032C, and ACX7348 platforms running Junos OS Evolved, enabling netconf notifications with the command "set system services netconf notification" may cause a memory leak. This results in a control plane crash (vmcore). Forwarding plane remains unaffected.
1879816
Major
GNMI get native configuration garbage reply when there is no configuration related to openconfig
Product-Group=junos
Severity=Major
The native configuration is observed when there is no configuration related to openconfig but if there are configuration related to openconfig, the native config is not seen. This is just a corner case and no service impact is observed.
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1843789
Critical
Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI
Product-Group=junos
Severity=Critical
A core-dump issue has been identified in the Management Daemon (MGD) when executing certain configuration display commands with the display json option in the CLI. This may lead to an abrupt session termination and CLI disruption.
PR NumberSynopsisCategory: content filtering bugs
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
Severity=Critical
On Junos OS SRX platforms, configuring cache preload in web filtering causes high memory utilization in the UTM (Unified Threat Management) pool, which results in traffic loss.
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Timing defect in ukern thread handling causing LC reboot
Product-Group=junos
Severity=Major
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.
PR NumberSynopsisCategory: Virtual Private LAN Services
1882938
Major
In VPLS scenario due to ungraceful switchover rpd process crash is observed
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms with VPLS (Virtual Private LAN Service) configured, during an ungraceful GRES (Graceful Switchover) switchover with NSR enabled, an issue with VPLS label replication will cause a mismatch, resulting in an rpd (Routing Protocol Process) crash.
PR NumberSynopsisCategory: usf ipsec related issues
1888205
Major
Change in the behaviour of configured lifesize kilobytes of ipsec proposal.
Product-Group=junos
Severity=Major
The lifesize parameter (in kilobytes) within the IPsec proposal is negotiated only when it is explicitly defined in the local device configuration.
PR NumberSynopsisCategory: Unified Services Framework
1912459
Critical
The nsd process crash will be seen on MX platforms when configuration change is commited using ephemeral database
Product-Group=junos
Severity=Critical
On MX platforms with SPC3 line cards, when the ephemeral configuration-database is configured, parsing of the respective hierarchies by nsd (Network Security Domain) was faulty and leads to the daemon crash.

 

Extended Solution

24.2R2-S4 - List of Known issues

PR NumberSynopsisCategory: EX4000 HW issues
1902609
Minor
Intermittent kernel panic results in device reboot or fxpc crash
Product-Group=junosvae
On all EX4000-48MP/EX4000-48P/EX4000-48T platforms, false ECC (Error-Correcting Code) alarms are observed due to the usage of un-initialised memory on the chip and intermittent kernel panic might result in vm core dump causing device reboot or fxpc crash. This results in impact on the traffic.

Resolved In: junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4B1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: ISSU
1900759
Major
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"
Product-Group=junos
EX4650/QFX5120-48Y: ISSU fails with reason "error Host OS is not compatible; in-service-upgrade cannot continue"

Resolved In: junos:23.4R2-S6 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: NFX Series Platform Software
PR NumberSynopsisCategory: MX YT-ZF Linecards Fabric Software Category
1891047
Minor
SFB is stuck in CMTY_SFB_STATE_OFFLINE_ACK_WAIT state and does not come offline or online
Product-Group=junos
SFB ( Switch Fabric Board ) is stuck in transitioning to offline, when SFB offline (sfb slot X offline) is attempted after disabling fabric planes (fabric plane X offline).

Resolved In: junos:24.2R2-S2-J14 junos:24.2R2-S2-J5 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:22.3X60 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.4R2-S4 junos:25.2R1
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:26.2R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1921796
Major
VRRP traffic dropped after priority change due to pinned MAC entry on peer device
Product-Group=junos
On all Junos and Junos Evolved platforms, when Virtual Router Redundancy Protocol (VRRP) priority is changed, the VRRP virtual Media Access Control (MAC) address can remain pinned as a static entry on the remote device. As a result, MAC movement does not occur correctly, and VRRP packets are dropped on the leaf device. This impacts VRRP operation after priority changes.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:25.4R2-EVO junos:23.2R2-S7 junos:23.4R2-S7-J4 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.4R2
PR NumberSynopsisCategory: Firewall Filter
1903874
Major
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVPN control plane issues
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EX4100 PFE
1925850
Minor
High CPU utilization and dfwd crash when modifying firewall filter terms applied on lo0 interface of Junos-based EX and QFX platforms
Product-Group=junos
On Junos-based EX and QFX platforms, modifying any term of a firewall filter applied on the lo0 interface triggers repeated Dynamic Firewall Daemon (dfwd) restarts and causes the Routing Engine (RE) CPU to reach 100 percent. The condition persists until the filter is removed or the previous configuration is restored.

Resolved In: junos:23.4R2-S8 junos:25.2R2 junos:25.4R2
PR NumberSynopsisCategory: EX optics issues
1864715
Major
EX4100: 10g-BASE-T didn't come up after dc-pfe restart
Product-Group=junos
After multiple iterations of dc-pfe process restart, we may see interface with 10g-base-t transceiver (part# 740-123734) will not come up.

Resolved In:
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1762490
Minor
JDI-RCT-MPC10E: Ksyncd crash on backup RE after fpc reboot
Product-Group=junos
On MX series, when PS over RLT is configured where all member LTs are hosted on the same FPC and user restarts this FPC then on rare occasion, ksyncd crash can occur on backup RE. However, there is no impact on the master and only backup RE is affected. This issue is not consistent and seen only once out of ~10 or 15 fpc restart operations.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: ISIS routing protocol
1859099
Minor
Memory leak is observed for certain topologies when TI-LFA is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms , where IS-IS/OSPF is enabled and TI-LFA (post-convergence-lfa) is configured in a SR (Segment Routing) environment. In a scenario where the computed backup paths to reach a destination is fetched from the more than one originator, duplicate paths gets computed for certain topology combinations and the clean-up of infosid list doesn't happen this leads to memory leak that might eventually lead to high memory usage and result in rpd crash and thus impacting traffic.

Resolved In: evo:22.4R3-S8-EVO evo:23.4R2-S6-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1 junos:25.3R1
1925611
Minor
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface
Product-Group=junos
Telemetry sensors on ACX EVO to pull /network-instances/network-instance/protocols/protocol/isis/interfaces only report the first ISIS interface

Resolved In: evo:24.2R2-S4-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: Flow Module
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1841364
Major
The kmd process crash is seen on random number generation by the third-party library API
Product-Group=junos
On Junos and Junos evolved platforms on rare circumstances when device is busy kmd process crash is seen on random number generation used for VPN negotiation by the third-party library API.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: SRX Datapath Multicast Solution Specific to Motorola
1899131
Major
Multicast packets are getting dropped when multicast is configured in strict-ordering mode
Product-Group=junos
On Junos OS SRX1600 platforms, when multicast is configured in strict-ordering mode, and certain threads are dedicated to processing multicast traffic, some multicast packets get dropped. This occurs due to the way the system handles message processing in this configuration, which can impact multicast traffic forwarding.

Resolved In: junos:24.4R2-S3 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.

Resolved In: junos:24.4R2-S2-J1 junos:24.4R2-S3 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Label Distribution Protocol
1906611
Major
Crash in the rpd process after LDP P2MP LSP Identifier reaches its maximum value and rolls over, due to duplicate identifier allocation
Product-Group=junos
On all Junos OS and Junos OS Evolved versions that support Label Distribution Protocol Point-to-Multipoint Label Switched Paths (LDP P2MP LSPs), the rpd process (routing protocol daemon) crashes when an LSP Identifier reaches its 24-bit maximum value (224 1 = 16, 777, 215) and rolls over to the starting value because a duplicate identifier is incorrectly allocated. This condition occurs only after prolonged tunnel flapping (typically more than 16 million flaps). When the rpd process crashes, routing convergence is briefly disrupted, and services relying on label-switched traffic are impacted until the process automatically restarts.

Resolved In: evo:26.1R1-EVO junos:26.1R1
PR NumberSynopsisCategory: PTX1000 platform
1770739
Critical
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message
Product-Group=junosvae
Reboot on PTX1k with image 22.3x60 causes fpc to reboot with "Fatal ASIC initialization error, Offlining FPC" Error message times

Resolved In: junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3-S2 junos:22.4R3-S8 junos:22.4X3 junos:22.4X4
PR NumberSynopsisCategory: SW PRs for MPC10E PlatformD
1909455
Major
RADIUS interim accounting will not work for subscribers after GRES on MX platforms with MPC10 line card
Product-Group=junos
On MX platforms with MPC10, RADIUS (Remote Authentication Dial-In User Service) interim accounting will not be working for subscribers after GRES (Graceful Routing Engine Switchover).

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: TCP/UDP transport layer
1893210
Minor
Master RE crashed and triggered unexpected switchover due to memory corruption
Product-Group=junos
On all Junos OS platforms, In Nonstop active routing (NSR) enabled system Routing Engine (RE) crash can occur due to a double free of a memory buffer (mbuf) was not handled properly leading to memory corruption causing synchronization issue and triggers unexpected switchover.

Resolved In: junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: PTX10K Routing Engine
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1936048
Minor
QFX5K RE is consuming EAPOL packets on interfaces even though layer2-control l2pt is configured
Product-Group=junos
QFX5K RE is consuming EAPOL packets on VXLAN enabled interfaces even though layer2-control l2pt is configured.

Resolved In:
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1888543
Minor
SNMP trap on Junos QFX5100 and EX4600 platforms report incorrect jnxOperatingState after PEM reinsertion on master switch
Product-Group=junos
On Junos QFX5100 and EX4600 platforms with releases 21.4R3-S3, 21.4R3-S10, and 21.4R3-S11, the SNMP trap generated after reinserting a PEM on the master switch incorrectly reports the jnxOperatingState as 6 (down) instead of the expected value 2 (running). This behaviour is consistently reproducible across multiple versions and persists even after performing a mastership switchover.

Resolved In: junos:21.4R3-S12 junos:26.1R1
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1858032
Major
The rpd process crashes when generate routes are configured in a rib-sharding scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crash is seen when Border Gateway Protocol (BGP) rib-sharding is enabled and generate routes are configured. This occurs due to issue in route resolution, the rpd crash impacts routing and rpd will restart when this issue occurs.

Resolved In: junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S2-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
1854481
Minor
The rpd gets struck with 100% CPU usage after enabling BGP RIB-Sharding
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms , enabling the BGP RIB-Sharding causes the routing protocol daemon (rpd) leading to spike and remain at 100% CPU usage due to a background task ( such as the Route Target/User Interface (RT/UI) delete job ) entering into the continuous processing cycle and looping behaviour.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S4-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.2R2-S4 junos:23.4R2-S4 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1860792
Minor
When rib-sharding or update-threading are enabled, generated bgp traceoptions files become accessible only to root users
Product-Group=junos
On all Junos and Junos Evolved platforms, when rib-sharding or update-threading are enabled, generated bgp traceoptions files become accessible only to root users. As the file generated will shows only the root privilege. Any normal privilege user will not be able to access the file generated.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1881609
Minor
RSVP hello messages uses secondary address when primary/preferred address are present for same interface
Product-Group=junos
On all Junos and Junos OS Evolved platforms where RSVP (Resource Reservation Protocol) configuration is present and a RSVP enabled interface has 2 IP address of which one is configured as primary/preferred in that case the RSVP Hello message uses the secondary IP address to form neighborship.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Sangria Platform including chassisd, RE, CB, power managemen
1913580
Major
Chassisd crash will happen when shutting down the FPC of PTX5000 and PTX3000 using online/offline button
Product-Group=junos
When the FPC(Flexible PIC Concentrator)online/offline button is pressed on PTX5000 and PTX3000 twice in a short period, chassisd crash will happen. it is causing all FPCs to lose connectivity with the Routing Engine while remaining in an online state. As a result, service impact happened till all FPCs become online.

Resolved In: junos:22.3X60 junos:22.4R3-S9
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.

Resolved In: junos:21.2R3-S10 junos:21.2R3-S6-J16 junos:22.4R3-S7-J5 junos:22.4R3-S9
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1872799
Major
Auto-negotiation status is not shown in "show interface" command and snmp get/getnext/walk
Product-Group=junos
On MX platforms, if auto-negotiation is configured on the interface, the status of auto-negotiation is not shown in "show interface media/extensive" command and snmp get/getnext/walk.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S6 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1901312
Major
Firewall filter not processing traffic with flex offset configuration is enabled
Product-Group=junos
On all Junos and Junos Evolved platform in applicable MX series and EX92xx, when firewall filter with flex-offset is configured and if there is term to match less than 4 bytes offset towards end of the packet, then filter drops the packet and user can see traffic drop for that particular firewall term.

Resolved In: evo:25.2R2-EVO junos:23.2R2-S6 junos:23.4R2-S5-J31 junos:23.4R2-S7 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: DDos Support on MX
1897237
Major
Traffic flow display not accurate when SCFD is enabled
Product-Group=junos
On MX platforms with MPC10/MPC11/LC9600/LC4800 linecards and MX304/MX301 platforms, if SCFD (Suspicious Control Flow Detection) is enabled and lot of flow are tracked on the device, error logs may be reported when the table overflows. This is purely a display issue.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J36 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:19.2R3-S12 junos:19.2R3-S13 junos:19.3R3-S13 junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:24.2R2-S5 junos:24.4R2-S4
PR NumberSynopsisCategory: Ephemeral Database
1717477
Major
The system processes accessing the ephemeral database can crash
Product-Group=junos
On all Junos and Junos OS Evolved supporting ephemeral databases, due to a race condition, when a system process reads configuration from ephemeral database and in parallel, there is a commit in the static database, the system process crashes.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R0-J0-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.2X33 junos:21.2X9 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.3X60 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=junos
Few yang package are occuring multiple place On Box

Resolved In:
PR NumberSynopsisCategory: Junos Fusion Aggregation Device Infra
1913169
Major
The smdp process crash is observed on MX Aggregation Device during Junos upgrade in a Junos Fusion Deployment
Product-Group=junos
In all Junos MX platforms acting as the AD (Aggregation Device) in a Junos Fusion deployment, a Junos software upgrade causes the smdp (Satellite Platform and Management Daemon) process to crash impacting forwarding plane services. This issue is observed when AD nodes are moved to a higher Junos version while the SD (Satellite nodes) are still running a lower version.

Resolved In: junos:22.4R3-S7-J7 junos:22.4R3-S9 junos:23.2R2-S6
PR NumberSynopsisCategory: Virtual Private LAN Services
1806424
Major
The snmp mib walk on jnxVplsPwBindTable fails with vpls routing-instances having multiple mesh-groups
Product-Group=junos
If VPLS mesh-groups are configured with different neighbours having different vpls-id the SNMP mib walk over jnxVplsPwBindTable might fail with the error Request failed: OID not increasing. No functional impact is seen due to this issue.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S8 junos:24.4R2 junos:25.1R1 junos:25.2R1

 

Modification History

First publication 2026-02-23