Alert Type

SRN - Software Release Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

MX104 ACX1000 ACX2000 ACX4000

Alert Description

Junos Software Service Release version 21.2R3-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Junos Software service Release version 21.2R3-S11 is now available.

Solution

Junos Software service Release version 21.2R3-S11 is now available.

21.2R3-S11 - List of Fixed issues

PR NumberSynopsisCategory: SPC3 HW and SW Issues
1922949
Critical
Executing unsupported pfe cli triggers chassis reset on srx5000 series
Product-Group=junos
Severity=Critical
On Junos SRX5000 series platforms with Services Processing Card 3 (SPC3), executing the unsupported operational command "show pfe statistics dma" causes loss of communication between the Packet Forwarding Engine (PFE) and the Routing Engine (RE), triggering a system-wide Flexible PIC Concentrator reset and resulting in a complete traffic outage.
PR NumberSynopsisCategory: BBE interface related issues
1848887
Major
Routing-services enabled on PPPoE dynamic profile causes subscriber login failure for new subscribers
Product-Group=junos
Severity=Major
On MX platforms, with routing-services enabled on PPPoE (Point-to-Point over Ethernet) Dynamic Profile, subscriber login fails for new subscribers with specific stacking model.
PR NumberSynopsisCategory: Border Gateway Protocol
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
Severity=Critical
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
1915893
Major
The rpd process crash triggered by LLGR stale timer expiry and late reconnection of unconfigured BGP peer on helper node
Product-Group=junos
Severity=Major
On all Junos OS and Junos OS Evolved, when Long-Lived Graceful Restart (LLGR) is configured and a Border Gateway Protocol (BGP) neighbor goes down and reconnects after the LLGR stale timer expires, the Routing Protocol Daemon (rpd) process crashes leading to service disruption.
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1945627
Minor
BGP IPv6 Flow Specification Session Flapping When inet6-flow Is Enabled
Product-Group=junos
Severity=Minor
In certain Junos OS releases, BGP sessions may repeatedly reset when IPv6 Flow Specification (inet6-flow) is enabled. This behavior occurs when the router receives specific IPv6 Flow Specification updates that include a default (wildcard) match. Earlier releases do not exhibit this behavior, leading to a difference in observed stability when upgrading.
PR NumberSynopsisCategory: Device Configuration Daemon
1916208
Major
Traffic drops due to VLAN configuration not updated for Ethernet-Switching Interfaces
Product-Group=junos
Severity=Major
On Junos OS platforms in which VLAN information can be given as a VLAN member name, if both VLAN (Virtual Local Area Network) IDs and VLAN member names are configured together on an interface within a routing instance, the VLAN membership does not update correctly on that interface, resulting in traffic impact associated with that VLAN.
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1847849
Critical
Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop (CVE-2026-21910)
Product-Group=junos
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA106009 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1922670
Critical
KMD process crash during RG0 failover with ADVPN shortcuts in HA cluster
Product-Group=junos
Severity=Critical
On SRX and MX platforms using the IPsec Key Management Daemon (KMD), RG0 failover or failback while Auto Discovery VPN (ADVPN) shortcuts are active may cause the KMD process to crash, temporarily disrupting ADVPN sessions.
PR NumberSynopsisCategory: Firewall Network Address Translation
1933239
Critical
The FPC restarts on SRX series platforms when session-persistence-scan is configured
Product-Group=junos
Severity=Critical
On Junos OS SRX Series platforms with 'session-persistence-scan' and NAT46 or NAT64 configured, modification to source Network Address Translation (NAT) rule will cause Flexible PIC Concentrators (FPCs) to restart when there is live IPv6 traffic. This will cause all traffic to be dropped and cause service disruption.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1838004
Major
VPN Tunnel Instability During Simultaneous Rekey Events on SRX/MX Platforms
Product-Group=junos
Severity=Major
A condition was identified in the IKED daemon where simultaneous IKE rekey operations from both VPN peers can lead to tunnel flapping. Specifically, if each peer sends a create_child request using its own initiated IKE SA (instead of the peer's), both requests are dropped since neither peer is the initiator of the other's IKE SA. This results in both sides failing to complete the rekey and can cause the VPN tunnel to temporarily go down.
PR NumberSynopsisCategory: Key Management Daemon
1909025
Critical
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received, kmd/iked crashes (CVE-2026-33778)
Product-Group=junos
Severity=Critical
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA107868 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to control plane security
1865633
Major
Junos OS: A low-privileged user can escalate their privileges so that they can log in as root (CVE-2026-21916)
Product-Group=junos
Severity=Major
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root, which will lead to a complete compromise of the system. Please refer to https://supportportal.juniper.net/JSA107807 [juniper.net] for more information.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906065
Major
ifStackStatus is not reported correctly for one or more AE bundles
Product-Group=junos
Severity=Major
On all Junos, the ifStackStatus query is executed after the system reboot, the member link status is not reported correctly for one or more AE (Aggregated Ethernet) bundles and thus the relation between AE IFL (Logical Interface) and corresponding member link IFL's cant be fetched from ifStackTable. This is an error message and no traffic impact will be observed.
1906718
Critical
Junos OS and Junos OS Evolved: CVE-2022-24805 resolved in net-SNMP
Product-Group=junos
Severity=Critical
CVE-2022-24805 has been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved. Please refer to https://supportportal.juniper.net/JSA107822 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX branch platforms
1905219
Critical
The traffic on all interfaces of SRX300/SRX320 platforms are dropped while an interface of them is receiving pause frames from connecting device
Product-Group=junos
Severity=Critical
While an interface of SRX300/SRX320 is receiving pause frames from connecting device, all incoming and outgoing traffic on all interfaces of SRX300/SRX320 was dropped unexpectedly. This issue only occurs when the interface with 'auto-negotiation' disabled receives pause frame. This issue occurs because disabling 'auto-negotiation' causes both 'pause frame' and 'Tx/Rx pause frame' to be set to 'yes'. Connecting device is sending pause frames due to hardware failure.
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1846340
Major
FPC0 will not transition to Online and may generate chassis alarm "FPC 0 Hard errors" in SRXTVP devices deployed in chassis cluster
Product-Group=junos
Severity=Major
On SRX TVP platform devices (SRX1500, SRX1600, SRX2300, SRX4100, SRX4120, SRX4200, SRX4300, SRX4600, SRX4700, SRX5k-SPC3) deployed in a chassis cluster, after rebooting the Secondary node, if count of RIB (Routing Information Base) /FIB (Forwarding Information Base) is above 15000, FPC0 will not transition to Online, and a "FPC 0 Hard errors" chassis alarm may be generated.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Critical
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1704886
Critical
Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information (CVE-2026-33776)
Product-Group=junos
Severity=Critical
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information. Please refer to https://supportportal.juniper.net/JSA107866 [juniper.net] for more information.

 


 

Extended Solution

21.2R3-S11 - List of Known issues

PR NumberSynopsisCategory: SRX Fleming Platforms related issues
1927758
Critical
HA failover not triggered after PFE process crash in HA deployments (Chassis Cluster / MNHA) on SRX1600/2300/4300/4700
Product-Group=junosvae
On SRX1600/2300/4300/4700 platforms configured in HA mode (Chassis Cluster or MNHA), when a PFE (Packet Forwarding Engine) process crash occurs on the active node, HA failover is not triggered because the failure condition is not detected by the HA subsystem. This can lead to traffic disruption and service outage.

Resolved In: junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: "agentd" software daemon
1913260
Major
Discrepancy noticed in the interfaces when there is a reset in Linecard or PFE
Product-Group=junos
On all Junos and Junos Evolved platforms, with an established telemetry session with multiple collectors, there will be interface statistics discrepancy when there is a linecard OIR event or PFE offline/online sequence.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.4R2-S8-EVO evo:26.1R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.4R2 junos:26.1R1 junos:26.2R1
1923848
Major
Junos Evolved platfrom, when gNMI collecting data from "optics/lanediags/lane/lane_laser_receiver_power_dbm" and "optics/lanediags/lane/lane_laser_output_power_dbm" are unreadable
Product-Group=junos
The JavaScript Object Notation (JSON) encoding of leafs of type "ieeefloat32"(https://github.com/openconfig/public/blob/master/release/models/types/openconfig-types.yang#L127) is not correct, causing gRPC Network Management Interface (gNMI) data outputs unreadable.

Resolved In: evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: BBE database related issues
1818781
Major
Multiple BBE daemons getting killed automatically on MX platforms
Product-Group=junos
In a scaled subscriber management router, customers observe authd and Jdhcpd daemons being killed automatically due to block tasks.

Resolved In: junos:23.2R2-S2 junos:23.2R2-S3 junos:23.4R2-S7 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: BBE routing
1922536
Major
Forwarding issues for an access DHCPv6-PD or access-internal DHCPv6-IA route or both may be seen on LNS due to an incorrect route programming of such route on PFE
Product-Group=junos
Drop of traffic to subscriber DHCPv6 prefixes may be observed on LNS (L2TP network server) if CPE uses IPv6 address obtained via NDRA process as the source address for DHCPv6 negotiation instead of link-local address.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S2-J13 junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=junos
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S8-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-J1 junos:22.4R3-S10 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:23.4R2-S8 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:24.4R2-S3 junos:24.4R2-S4 junos:24.4R2-S5 junos:25.2R1-S2 junos:25.2R2
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:23.4R2-S8-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:22.3X60 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.2R2 junos:25.3R1
1880630
Major
Some BGP sessions remain in the Idle state after all interfaces are deactivated and rollback is issued
Product-Group=junos
On all Junos and Junos OS Evolved platforms, after all the interfaces are deactivated and the rolled back, some BGP sessions stay in Idle state. This will impact the traffic.

Resolved In: evo:22.3X80-D49-EVO evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:23.2R2-S7 junos:23.4R2-S6-J14 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S2-J8 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.3R3-S5 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.2R2 junos:25.3R1
1898734
Major
The rpd process crashes in an Inter-AS Option-AB L3VPN with BGP multipath list-nexthop enabled
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in an Inter-AS (Autonomous System) Option-AB L3VPN (Layer3 Virtual Private Network) scenario, if 'bgp multipath list-nexthop' is configured and a VRF (Virtual Routing and Forwarding) generates a route with list-nexthop that is advertised to an Option-AB peer, the rpd process crashes and generates a core-dump.

Resolved In: evo:23.2R2-S6-EVO evo:24.4R2-S3-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:19.1R3-S15 junos:22.4R3-S11 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R1-S2-J10 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1914814
Major
BGP task replication will be stuck in 'InProgress' state following an RE switchover when two single hop EBGP sessions are configured on two different interfaces using the IP addresses from the same subnet
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms with NSR (Nonstop Active Routing), when two single hop EBGP (External Border Gateway Protocol) sessions are configured to run on two different interfaces using IP addresses from the same subnet (overlapping subnet), the BGP task replication process does not complete after an RE (Routing Engine) switchover for the EBGP session with a specified local-address. This results in one BGP peer being in the 'Idle' state on the Backup RE while remaining in the 'Established' state on the new Master RE, causing the BGP task replication process to remain stuck in the 'InProgress' state.

Resolved In: evo:22.4R3-S9-EVO evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: BGP BMP Software
1785723
Major
When BGP rib-sharding is enabled, show bgp bmp output hangs
Product-Group=junos
On all Junos and Junos evolved platforms, the output of command show bgp bmp hangs when rib-sharding is enabled and rpd restarts

Resolved In: evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R3-S5-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R1
PR NumberSynopsisCategory: MX Platform SW - UI management
1898722
Major
The craft-control process is unable to start on MX10004/MX10008 platforms
Product-Group=junos
On all Junos MX10004 and MX10008 platforms with FPM/craft interface, the craftd (craft control daemon) is unable to run, it causes the craft-control process does not start properly, leading the jnxAlarmRelayMode unable to retrieve data when an alarm condition is triggered. The issue does not cause traffic impact and only may affects monitoring traffic.

Resolved In: junos:24.4R2-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: L2NG Access Security feature
1911142
Major
Client IP assignment failure observed on EX4300 due to DHCPv6 snooping validation issue
Product-Group=junos
On EX4300, DHCPv6 ( Dynamic Host Configuration Protocol for IPv6 ) clients will fail to receive IP addresses due to improper client entry handling when DHCPv6 snooping is enabled.

Resolved In: junos:21.4R3-S12
PR NumberSynopsisCategory: QFX Access Control related
1801760
Major
The dot1xd process crashes during large-scale 802.1x authentication scenarios due to a defect in dynamic VLAN handling in multiple supplicant mode
Product-Group=junos
On Junos and Junos OS Evolved platforms, the dot1x daemon (dot1xd) crashes and generates a process crash dump during large-scale 802.1x authentication scenarios (approximately 1000 clients). This issue happens in dot1x multiple supplicant mode. The crash was triggered when the dot1x daemon processed a MAC (Media Access Control) learning request following an IFBD (Interface Forwarding Bridge Domain) deletion, resulting in an assertion failure caused by an invalid bridge-domain lookup.

Resolved In: evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1921796
Minor
Traffic dropped after priority change in VRRP with EVPN-VxLAN scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, in Virtual Router Redundancy Protocol (VRRP) with Ethernet Virtual Private Network - Virtual Extensible Local Area Network (EVPN-VXLAN) scenario, when VRRP priority is changed, the VRRP virtual Media Access Control (MAC) address can remain pinned as a static entry on the remote device. As a result, MAC movement does not occur correctly, and VRRP packets are dropped on the leaf device. This impacts VRRP operation after priority changes.

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R1-S2-EVO evo:25.4R2-EVO junos:23.2R2-S7 junos:23.4R2-S7-J4 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: OpenSSH and related subsystems
1922002
Major
Major alarms showing SPMB1 not online on MX2008 will be seen on 24.2R1 and later releases
Product-Group=junos
On the Junos MX2008 VMhost platform with dual Routing Engines (REs), the backup SPMB {Switch Processor Mezzanine Board} (spmb1) fails to come online following a graceful switchover on releases starting when upgrading to releases starting from Junos 24.1. As a result, if the backup SPMB cannot boot, the traffic will be impacted during switchovers.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Firewall Filter
1903874
Major
[MX10008] cmd='ls -i /var/etc/filters/filter-define.conf' is logged every 1 second instead of every 30 seconds
Product-Group=junos
An issue where client sessions were not cleared on a router/switch, leaving stale session data that triggered immediate timeout handling instead of the expected 30?second delay. This caused once?per?second master?data lookups and repeated log entries such as "ls -i /var/etc/filters/filter-define.conf", but had no functional impact.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:22.4R3-S10 junos:23.2R2-S7 junos:23.4R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: ACX BFD specific issues
1899540
Major
DNX error logs consuming syslog in ACX platforms post upgrade causing display issue
Product-Group=junos
On Junos ACX710 and ACX5448 platforms, post upgrade the error logs "DNX PKT: (is microbfd pkt) payload length(1) is lesser to have a udp header" are reported in the devices causing display issue.

Resolved In: junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1930036
Major
High memory usage is showing, when we configure unsupported licensing feature
Product-Group=junos
On all Junos EX and QFX platforms operating in an EVPN (Ethernet Virtual Private Network) environment, this issue occurs when the CLI command 'licensing hourly update' is executed on a device that does not support the licensing feature.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R1-S2-J4 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1919313
Major
The LDP session does not come up when an IPsec SA is configured under OSPFv3
Product-Group=junos
On Junos Evolved platforms, when Open Shortest Path First version 3 (OSPFv3) Internet Protocol Security (IPsec) SA is applied at the interface (IFD/IFL) level, Label Distribution Protocol (LDP) is able to discover the neighbor via User Datagram Protocol (UDP) Hellos, but fails to bring up the Transmission Control Protocol (TCP) session, preventing the LDP session from becoming operational. Disabling the OSPFv3 IPsec SA immediately restores normal LDP operation. During the service impact, the session will be down and traffic will not be send. Once the LDP session comes up, traffic can be routed through it.

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1899530
Major
MAC learning failure when moving the AE interface from one VLAN to another VLAN in a single commit
Product-Group=junos
On Junos OS Evolved platforms, when an Aggregated Ethernet (AE) logical interface (IFL) is moved from one Virtual LAN (VLAN) to another VLAN in a single commit, Layer 2 forwarding tables fail to update correctly. This causes Media Access Control (MAC) learning failure and traffic disruption.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.2X2-EVO evo:24.4R2-S2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=junos
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R1-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: EX interfaces issues
1814093
Major
Multi-rate Gigabit Ethernet port on the EX4100 and EX4400 platforms does not receive or forward traffic
Product-Group=junos
On all EX4100 and EX4400 platforms with mge ports, the mge (multi rate gigabit ethernet) port shows up but does not allow traffic to pass through after port initialization or port flap.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2-S4 junos:25.1R1
1904884
Critical
VCP link flap due to SYSPLD read failures
Product-Group=junos
On EX4100 platform VCP link flap due to SYSPLD read failures and mark SFP as unplugged

Resolved In: junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: EX4400 PFE software
1900891
Critical
Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physical interface one of those is not applied (CVE-2026-33773)
Product-Group=junos
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks.. Please refer to https://supportportal.juniper.net/JSA107815 [juniper.net] for more details.

Resolved In: junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S2 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
1908971
Major
DHCP Snooping drops due to misrouted server packets causing intermittent issues.
Product-Group=junos
Intermittent performance issues observed across sites due to anomalous DHCP behavior, where DHCP server packets are incorrectly received on downstream switch interfaces, triggering snooping drops.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1823764
Major
, In virtual-chassis after routing-engine switchover traffic of type 5 routes of EVPN-VXLAN are not getting forwarded
Product-Group=junos
On Junos virtual-chassis specifically on EX4400, EX4100, EX4650, QFX5120, and QFX5110 platforms, EVPN VxLAN type 5 routes will not pass traffic after a routing-engine switchover.

Resolved In: junos:22.2R3-S5 junos:22.4R3-S7 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: EX POE
1930080
Major
PoE outage observed on EX4400 in a rare scenario
Product-Group=junos
On EX4400 platforms, loss of PoE (Power over Ethernet) power is seen on ports after port bounce or even during normal operation without specific external trigger . This causes outage on all PoE ports and devices connected to PoE port will not receive power causing service impact.

Resolved In: evo:26.2R1-EVO evo:26.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1721890
Major
The dcpfe process crash while trying to free some handle memory which was not even allocated
Product-Group=junos
On Junos QFX10k platforms, while attempting to free some memory that was not allocated results in Packet Forwarding Engine (PFE) core and if the dcpfe process crashes, Flexible PIC Concentrators(FPC) will restart every time.

Resolved In: junos:21.4R3-S4 junos:22.1R3-J2 junos:22.1R3-J3 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.3R3-S1 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1 junos:23.4R2-S11
PR NumberSynopsisCategory: FIPS related issues
1905490
Major
On MX10003 with FIPS enabled, KATs failure in SMIC_QSFP28_MACSEC_TIC causes system halt
Product-Group=junos
In Junos, MX10003 platforms with Federal Information Processing Standards (FIPS) enabled experience repeated halts due to Known Answer Test (KATs) failures in the SMIC_QSFP28_MACSEC_TIC crypto path.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1928462
Major
FPC crash occurs after configuration changes are made to a service-filter on specific MX platforms
Product-Group=junos
FPC crash and aftd-trio core-dump will be observed on MX platforms supporting MPC10E, MPC11E, LC9600 line cards, and MX304 after configuration changes were made to a service-filter which was in use by BBE subscribers.

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R1-S2-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S2-J15 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1933452
Major
ICMP ping with higher MTU size fails in VPLS when IRB MTU exceeds MPLS core MTU
Product-Group=junos
On all Junos OS platforms, configured with VPLS (Virtual Private LAN Service) and IRB (Integrated Routing and Bridging ) interfaces, when the MTU (Maximum Transmission Unit) configured on the IRB or CE interface is larger than the MPLS ( Multiprotocol Label Switching ) core interface MTU (including MPLS label overhead), ICMP Echo Request (ping) packets with higher packet sizes fail.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: jdhcpd daemon
1911001
Major
On Junos devices supporting subscriber services acting as DHCPv6 relay randomly deletes IA_NA or IA_PD binding/route
Product-Group=junos
On all Junos devices supporting subscriber services, in case of dual stack DHCP (Dynamic Host Configuration Protocol) subscribers with IA_NA (Identity Association for Non-temporary Address) and IA_PD (Identity Association for Prefix Delegation) bindings with lease times (For the assignment of IPv6 address to a client device), when a client initiates separate renew exchanges for the IA_NA and IA_PD, and once client and DHCP server are in sync with these timers, there can be a race condition at Junos device which is DHCPv6 relay, has not refreshed lease timer and can go out of sync. This can result in deleting IA_NA/IA_PD binding and route to get deleted for that subscriber only. This causes one of the leg for IA_PD or IA_NA to go down for that subscriber, which can result in traffic impact for that leg.

Resolved In: evo:24.4R2-S4-EVO evo:25.4R1-S1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:22.4R3-S9 junos:23.2R2-S5-J2 junos:23.2R2-S6 junos:23.2R2-S7 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1-S1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Flow Module
1834338
Major
GRE traffic is getting blocked due to a software programming issue and MTU going below minimum value
Product-Group=junos
On Junos OS SRX platforms with GRE (Generic Routing Encapsulation) configured, due to a software programming issue, some threads have incomplete information while processing the data and even if "no-path-mtu-discovery" or "no-gre-path-mtu-discovery" is configured, the MTU going below minimum value (IPv4- 578, IPv6 1280) resulting in the GRE traffic being blocked i.e. complete traffic impact.

Resolved In: junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1868005
Major
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash (CVE-2026-21906)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart. Please refer to https://supportportal.juniper.net/JSA106005 [juniper.net] for more information.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
1892015
Major
Junos MX/SRX flowd Crash After Tunnel Removal Leaves Stale Flows, Causing FPC Reboot
Product-Group=junos
On Junos OS SRX and MX with SPC3 platforms, any tunnels such as GRE, IPIP, DS-Lite, or IPSEC tunnel has its configuration removed, the IKE SAs can go down causing invalid entires. These can later cause the flowd process to crash.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S4 junos:24.4R1-S2-J9 junos:24.4R2-S1-J5 junos:24.4R2-S2 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1903515
Major
On the SRX platform the FPC reboots when traffic reaches the FAT IPSec tunnel
Product-Group=junos
All Junos SRX platforms that support PMI (Power Mode IPsec) fat tunnel configuration may experience, FPC reboot in some occasional scenarios, when traffic hits FAT tunnel. The reboot is occasional in some timing scenarios and that timing is when system gets wrong data to process the traffic. Not all customer experience this, and so far a customer reported, the issue is seen every 2 weeks or more.

Resolved In: junos:23.2R2-S6 junos:23.4R2-S5-J38 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: SRX power-mode (PMI/PME)
1858490
Major
flowd crashes due to a timing issue during IPsec SA re-keying on certain SRX platforms
Product-Group=junos
On certain SRX platforms, the flowd process crash is observed during Internet Protocol Security (IPsec) Security Association (SA) re-keying. This occurs due to an internal timing issue, leading to IPsec tunnel establishment failure, traffic loss during re-key events, and traffic switchover.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1841364
Major
The kmd process crash is seen on random number generation by the third-party library API
Product-Group=junos
On Junos and Junos evolved platforms on rare circumstances when device is busy kmd process crash is seen on random number generation used for VPN negotiation by the third-party library API.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S5 junos:24.4R1 junos:25.1R1
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.

Resolved In: evo:24.2R2-S4-EVO junos:21.4R3-S12 junos:22.2R3-S7 junos:23.2R2-S6 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SRX Datapath Multicast Solution
1899131
Major
Multicast packets are getting dropped when multicast is configured in strict-ordering mode
Product-Group=junos
On Junos OS SRX1600 platforms, when multicast is configured in strict-ordering mode, and certain threads are dedicated to processing multicast traffic, some multicast packets get dropped. This occurs due to the way the system handles message processing in this configuration, which can impact multicast traffic forwarding.

Resolved In: junos:24.4R2-S3 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.

Resolved In: junos:21.4R3-S12 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2-S4 junos:24.4R1 junos:25.1R1
1912271
Major
State synchronization failure between SRX cluster nodes
Product-Group=junos
On all SRX series platform in cluster with IKED package enabled, when the backup node becomes active, some tunnel configuration were missing. This occurs because, during cold synchronization, the IPC communication between IKED and SPU can have a chance to fail due to a kernl error which ultimately led to traffic disruption.

Resolved In: junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S2-J1 junos:24.4R2-S3 junos:24.4R2-S4 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=junos
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile have same profile index allocated then the storm control profile configuration and system state will not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.

Resolved In: evo:23.4R2-S8-EVO evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=junos
ARP resolution failure when there is quick flap of core facing interface on scaled setup

Resolved In: evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:23.4X100-D43-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Label Distribution Protocol
1852934
Major
The rpd process crash is seen during RE switchover
Product-Group=junos
On Junos and Junos OS Evolved dual RE (Routing-Engine) platforms with LDP (Label Distribution Protocol) configuration, an rpd process crash in the new master RE is observed during a RE switchover.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1872082
Critical
Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root (CVE-2026-33791)
Product-Group=junos
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Please refer to https://supportportal.juniper.net/JSA107875 [juniper.net] for more information.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S4-J2-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S10-J4 junos:21.4R3-S10-J6 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50 junos:23.2R2-S3-J20 junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.2X1 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1793982
Major
Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash (CVE-2026-21909)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA106008 [juniper.net] for more information.

Resolved In: evo:23.2R2-EVO evo:23.4R1-S1-J5-EVO evo:23.4R1-S1-J7-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.2R2 junos:23.2R2-J14 junos:23.4R1-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.2R2-S5-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.2R2-S5 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1923867
Minor
The rpd process crash is observed after a graceful restart in the RSVP-TE scenario
Product-Group=junos
On Junos OS and Junos OS Evolved platforms with Graceful Restart and RSVP-TE (Resource Reservation Protocol - Traffic Engineering) configured, an rpd crash is observed, leading to traffic impact after a Graceful Restart if a PVC (Permanent Virtual Circuit) fails to allocate correctly during this recovery process, leaving it in an incomplete or unallocated state, and the system attempts to clean up or remove this unallocated PVC.

Resolved In: evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S1-C1 junos:24.4R2-S1-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: MQTT protocol, Mosquitto Broker and Client API
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:22.4X8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.2X1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ACX Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Express Chip L3 software
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
PR NumberSynopsisCategory: Phone-Home-Client Infrastructure
1811521
Major
PHC gets initiated and sends DNS request to Juniper server "redirect.juniper.net" even when device is supposed to get provisioned using ZTP with vendor specific option 43
Product-Group=junos
Rarely, on all Junos platforms, PHC (Phone Home Client) is signaled to attempt bootstrapping by AIU (Auto Image Upgrade) when legacy ZTP (Zero Touch Provisioning) fails if vendor specific options (option 43 is sent by DHCP server) are not valid. This is followed by PHC sending DNS request to resolve "redirect.juniper.net" which is the redirect Juniper Server even if DHCP is released by ZTP and no IP is expected to be present.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S5-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2-S4 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).

Resolved In: evo:24.4R2-S4-EVO junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X9 junos:24.2R2-S3 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1919729
Major
SRX4300 and SRX1600 Enter System Halt or Amnesiac State After Reboot When TPM/MEK is Enabled
Product-Group=junos
On SRX4300 and SRX 1600 platforms When Master password and Master Encryption Key is set on the device and rebooted , the system was getting into amnesiac state.

Resolved In: junos:24.2R2-S5 junos:24.4R2-S4 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1931633
Major
PFE crash due to memory corruption when STP is enabled
Product-Group=junos
On all Junos Platforms, a rare memory corruption condition may occur in the Packet Forwarding Engine (PFE) when Spanning Tree Protocol (STP) is enabled and operating in default (distributed) mode. When the issue is triggered, the PFE crashes and a dc-pfe core file is generated. The exact trigger for the memory corruption is currently unknown.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:19.2R3-S12 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: QFX5K hostpath
1804090
Major
High storage utilization in /var/log due to uncompressed UKERN_GBL.log file
Product-Group=junos
On Junos QFX5100 and EX4600 Platforms, high storage Utilization is observed in /var/log due to uncompressed UKERN_GBL.log file. This can lead to low storage warnings and potential write errors for other system logs during that period.

Resolved In: junos:21.4R3-S9 junos:22.4R3-S9 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2
1921455
Major
The dcpfe process crashes when adding or removing classifier configuration on QFX5210
Product-Group=junos
On QFX5210 platform with Class of Service (CoS), the dcpfe process crashes when classifier is configured or removed on interface with active traffic. This can affect traffic forwarding till dcpfe process restarts post crash.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX L2 PFE
1938291
Major
Deactivating sub-interfaces on flexible ethernet ports leads to VLAN traffic loss
Product-Group=junos
On Junos platforms having QFX and EX, VLAN(Virtual Local Area Network) traffic loss occur on interfaces configured with flexible-vlan-tagging when an L3 (SP style) sub-interface is deactivated on a port that also carries L2 (enterprise style) VLAN units.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1823601
Major
Protocol traffic drops were seen in the network for any configuration change in the protocol
Product-Group=junos
On all Junos QFX5K platforms, with ECMP (Equal Cost Multi Path) configured, when there is any routing protocol change (like ISIS cost metric change), the protocol traffic on the network is dropped.

Resolved In: junos:21.4R3-S10 junos:21.4X30 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.4R3-S7 junos:23.4R2-S4 junos:23.4R2-S7 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1
1855990
Major
Traffic drop observed due to ECMP next-hop programming issue
Product-Group=junos
On QFX5k, EX4k, EX2300 and EX3400 platforms, ECMP next-hop programming issue causes some prefixes to drop traffic. The issue is observed when the software-configured ECMP size (maximum-ecmp) exceeds the limit of 64 during a network churn event in the network. This triggers ECMP to skip updates, leading to stale forwarding paths and a temporary traffic freeze.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S7 junos:23.4R2-S4 junos:23.4R2-S7 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
On Junos OS QFX5k and EX4k platforms, when static ECMP (Equal-Cost Multi-Path) is configured, traffic loss will be observed due to a next-hop programming issue. The device fails to install the next-hop entries in hardware for static ECMP routes, resulting in traffic not being forwarded as expected after a device upgrade.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X4 junos:24.4R2 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
1905607
Major
Hardware MTU stuck at default value, causing packet drops on VXLAN Interfaces
Product-Group=junos
On QFX5K and EX4K platforms which are running Junos release, when new VxLAN (Virtual Extensible LAN) vlans with IRBs (Integrated Routing & Bridging) are added, the L3 (Layer 3) interface values overwrite the MTU (Maximum Transmission Unit) entries previously programmed for non-VxLAN vlans that use the same hardware token internally. The VxLAN L3 interface is created with default MTU (1514) because L3 interface MTU value is still 1514 as it is not update by RE (Routing Engine).

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1877194
Major
Traffic drop is seen in a scaled scenario on certain EX platforms
Product-Group=junos
On Junos EX4400, EX4400-24T, EX4400-24X, EX4400-48T, EX4400-48F, EX4400-24MP, EX4400-48MP, EX4300-MP platforms, it is observed that in a scaled scenario with more than three thousand next hops configured, further next hop installation fails which in turn causes routes to fail leading to traffic drop.

Resolved In: junos:23.2R2-S7 junos:23.2R2-S8 junos:23.2R2-S9 junos:23.4R2-S10 junos:23.4R2-S11 junos:23.4R2-S8 junos:23.4R2-S9 junos:24.2R2-S4 junos:24.2R2-S5 junos:24.2R2-S7 junos:24.2R2-S8 junos:24.4R2-S4 junos:24.4R2-S5 junos:24.4R2-S6 junos:24.4R2-S7 junos:25.2R1 junos:25.3R1
1933698
Major
PFE crash due to memory corruption in EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale
Product-Group=junosvae
On Junos QFX5110, QFX5120, EX4650, EX4400, EX4100, and EX5200 platforms, when operating with EVPN-VxLAN type5 overlay ECMP at high tunnel next hop scale, the Packet Forwarding Engine (PFE) crash when a memory corruption issue is observed due to a buffer overflow that leads to corruption of heap management structures. This corrupted metadata is detected by the memory manager when later heap allocation or free operations are invoked, resulting in a reported heap corruption condition.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1B1 junos:26.1R1 junos:26.2R1
1939298
Major
Traffic drop is seen due to tagged IRB L3 interface with native-vlan and vlan members
Product-Group=junos
On all Junos OS QFX5K and EX4k platforms, configuring a native VLAN along with VLAN members on an underlay Integrated Routing and Bridging (IRB) Network-to-Network Interface (NNI) that carries VxLAN (Virtual Extensible LAN) traffic results in the VLAN tag not being stripped as expected. Instead of treating the native VLAN traffic as untagged, the interface adds the VLAN tag, leading to packet drops at the remote end.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1773567
Major
100G optics settings to CAUI4 on Junos QFX5120-48T platforms
Product-Group=junos
The port interface on the 100G optics of the QFX5120-48T platform is incorrectly configured

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1 junos:25.2R1
1938876
Major
Incorrect interface mode leading to 100G Link Flaps on QFX5210-64C
Product-Group=junos
On Junos OS QFX5210-64C platform, 100G optics inherently operate in CAUI-4 (Chip-to-Module 100 Gb/s Four-Lane Attachment Unit Interface) mode, which is automatically selected by the system and not user-configurable; mismatches due to software versions leading to link instability or flapping.

Resolved In: junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.2R1
PR NumberSynopsisCategory: RPD Interfaces related issues
1831337
Major
When configuring router-advertisement on PS interfaces, the system sends router advertisement with invalid source link-address option
Product-Group=junos
On Junos OS and Junos OS Evolved platform, when router-advertisement is enabled on Pseudowire Subscriber(PS) interface configurations where Virtual Local Area Network (VLAN) tags are used, the system may incorrectly assign MAC (Media Access Control) addresses, causing routing and forwarding failures.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S9 junos:23.4R2-S7 junos:24.2R2 junos:24.4R1 junos:25.1R1
1913519
Major
EVPN routes are stuck in the KRT queue
Product-Group=junos
When EVPN (Ethernet Virtual Private Network) routes attempt to transition between private (eg, management em1 - with IGP enabled) and public interfaces, it causes an error in next-hop resolution in the kernel, because the system deletes the old indirect next-hop and creates a new one. This happens as the kernel does not support changing an indirect next-hop between private and public interfaces directly.

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1908681
Major
RIB and the FIB inconsistency results in traffic loss in IPsec scenario with st0 interface configured
Product-Group=junos
On Junos OS SRX platforms having IPsec (Internet Protocol Security) with st0 (Secure Tunnel Interface) interface configured, traffic loss will be observed if the "next-hop-tunnel" configuration is removed and added within a few seconds. This happens due to a inconsistency between the RIB (Routing Information Base) and the FIB (Forwarding Information Base).

Resolved In: evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1858032
Major
The rpd process crashes when generate routes are configured in a rib-sharding scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd process crash is seen when Border Gateway Protocol (BGP) rib-sharding is enabled and generate routes are configured. This occurs due to issue in route resolution, the rpd crash impacts routing and rpd will restart when this issue occurs.

Resolved In: junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S2-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1849202
Major
BGP route still seen in routing table when route not available
Product-Group=junos
On all Junos and Junos Evolved platforms , the router learns routes through the BGP (Border Gateway Protocol) and has the feature: "BGP RIB Sharding" enabled for IPv4. These routes are stored in the Inet.0 routing table. Later, if the neighbor that announced this route or the protocols associated with the routing table of the used VRF (Virtual Routing and Forwarding) are removed, the route remains in the routing table, and hence traffic is forwarded to the stale routes.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.

Resolved In: evo:22.3X80-D49-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S5-EVO evo:23.4X100-D40-EVO evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:21.4R3-S10-J4 junos:21.4R3-S12 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:22.4X50 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1907558
Major
The rpd process crashes in a vrf having EVPN-VXLAN routes with specific configuration.
Product-Group=junos
In all Junos and Junos OS Evolved platforms, when EVPN-VXLAN (Ethernet Virtual Private Network-Virtual Extensible LAN) routes are present in a VRF (Virtual Routing and Forwarding), configuring a generate route in same vrf can cause rpd (Routing Protocol Daemon) to crash and restart. Generate route configuration has to be removed to recover from this behaviour.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S6-EVO evo:24.2R2-S4-EVO evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1767102
Major
Regular expression (*) does not work when used with 'match-prefix'
Product-Group=junos
On all Junos and Junos OS Evolved platforms, regular expression (*) does not work when used with 'match-prefix'.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:22.4R3-S6 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1792192
Major
Missing HELLO object in RSVP Hello messages after RE failovers in the NSR mode
Product-Group=junos
In rare unknown condition after RE switchover, rsvp hello can have local instance to be zero due to wrong information synced from master RE by mirroring process. When rsvp neighbor is created and never received hello exchange with neighbor, the replication entry which is synced to standby RE will have most of the information as zero, including the local instance, which is used to generate hello object. After RE switchover, rsvp hello will have local instance to be zero due to the wrong information synced from master RE by mirroring process. This is addressed by update the replication entry once all the parameters of the rsvp neighbor is filled, so standby RE will receive the right info, also for future protection, backup RE will avoid creating neighbor until after switchover and setting a new local instance if it is zero.

Resolved In: evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S5-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.2R2-S5 junos:25.2R1 junos:25.3R1
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:20.3X75-D441 junos:20.3X75-D442 junos:20.3X75-D52 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1854093
Major
SNMP INFORM handling issue due to routing-instance-based trap source socket
Product-Group=junos
On Junos platform, Improved SNMPv3 INFORM handling to ensure messages are evenly distributed across all configured trap targets.

Resolved In: junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Segment routing traffic Engineering
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S8-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1913911
Major
ARP reply packets may be sent out from the STP blocked port
Product-Group=junos
On SRX300-series devices, when ethernet-switching is used with spanning-tree protocol enabled, in some cases ARP reply packets may be sent out from a spanning-tree blocked port.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S7 junos:23.4X11 junos:24.2R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: MPC7E, MPC8E and MPC9E timing and synchronization
1803105
Major
PTP attribute changes on upstream device causes best clock master slot switchover
Product-Group=junos
On all MX platforms(except MX80) with multi line card chassis, when PTP slave or stateful streams are configured across multiple linecards with clock from same PTP time provider and the announce msg parameters changes from the upstream device, the best master clock (BMC) slot switchover is observed and is restored back within few seconds. Although the slot time interval is very less, it can still lead to major impact as the active PTP slot and clock path is switched over and results in re-routing of the clocks.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:23.4R2-S6 junos:24.2R2-S5 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1886395
Major
FPC crash is seen on Junos platforms in a rare scenario
Product-Group=junos
On all Junos platforms, FPC (Flexible PIC Concentrator) crashes due to panic caused by incorrect handling of an application. This causes service impact since the card restarts after crash.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:23.4R2-S4-J23 junos:23.4R2-S4-J30 junos:23.4R2-S6 junos:24.2R2-S2-J16 junos:24.2R2-S4 junos:25.2R2 junos:25.4R2
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1890097
Major
Memory leak in FPC during login/logout
Product-Group=junos
On all Junos platforms, when policer is attached to interface-specific filter, while mangling the policer name one residual string is not cleared, which is causing the memory leak.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:23.4R2-S8 junos:24.2R2-S2-J8 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1913870
Major
Traffic is not passing through GRE-over-GRE tunnel due to keepalive packets are dropped in the outer tunnel
Product-Group=junos
On Junos MX platforms with MPC ( 1 to 9 ) or LC2103 linecards and platforms ( MX5- MX80 ) / MX104 / MX150 / MX204; when Generic Routing Encapsulation (GRE)-over-GRE is configured, end-to-end keepalive packets in the outer tunnel are dropped, and tunnel interface cannot pass traffic.

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1 junos:26.1R1
1927194
Major
When a resolution for an IPv4/IPv6 address fails, NH IFL is throttled causing service impact
Product-Group=junos
In MX uKern and AFT based cards, NH IFL throttling will be seen when resolution for an destination IPv4/IPv6 address fails.

Resolved In: evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO junos:23.2R2-S7 junos:23.4R2-S7-J16 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: DDos Support on MX
1801213
Major
DDOS protection Max arrival rate shows incorrect values
Product-Group=junos
On MX platforms with MPC10/MPC11/LC9600 and MX304 platforms, DDOS max-arrival rate value is incorrect in "show ddos-protection protocols" command.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:23.2R2-S7 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.

Resolved In: evo:23.2R2-S7-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.2R2-S7 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1736976
Major
qfx goes into amnesiac after a power outage and commit errors for scripts prevent recovery
Product-Group=junos
On all Junos platforms, the group file /etc/backup/group and the directory /var/etc/ are becoming corrupt, causing the mgd initialization to fail during system boot. This rare issue occur due to an abrupt power outage occurring while the files were being written.

Resolved In: junos:21.4R3-S7 junos:22.2R3-S4 junos:22.4R3-S6 junos:23.2R2 junos:23.4R2 junos:23.4R2-S8 junos:24.1R1
1821845
Major
The system scripts refresh will fail when using load CLI option
Product-Group=junos
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:23.4R2-S2-EVO evo:23.4X31-EVO evo:24.2R1-S1-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D46 junos:20.3X75-D52 junos:22.4R3-S4 junos:22.4X4 junos:22.4X50 junos:23.2R2-S2 junos:23.4R2-S1 junos:23.4X30-D30 junos:24.2R1-S1 junos:24.2R2 junos:24.2X1 junos:24.3B1 junos:24.3R1 junos:24.4R1 junos:25.2R2-S1
PR NumberSynopsisCategory: Issues related to NETCONF
1585855
Critical
< ok/> response is getting generated along with < rpc-error>
Product-Group=junos
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.

Resolved In: evo:22.1R3-S6-EVO evo:22.2R3-S1-EVO evo:22.3R2-S2-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R0-J0-EVO evo:22.4R1-S2-J5-EVO evo:22.4R2-S1-J5-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.3X75-D36 junos:22.1R3-S6 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.3X60 junos:22.4R2-S2 junos:22.4R3 junos:23.1R1 junos:23.2R1 junos:23.4R2
PR NumberSynopsisCategory: Issues related to YANG Data Models
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=junos
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X1 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R1-S2 junos:24.2R2 junos:24.2X1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: content filtering bugs
1927484
Critical
Traffic loss occurs due to high memory utilisation in UTM pools
Product-Group=junos
On Junos OS SRX platforms, configuring cache preload in web filtering causes high memory utilization in the UTM (Unified Threat Management) pool, which results in traffic loss.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: web filterig issues
1876037
Critical
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash (CVE-2026-21917)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA105996 [juniper.net] for more information.

Resolved In: junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S2 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
1887814
Minor
SNMP polling leaks memory in the UTM daemon ultimately leading to a crash
Product-Group=junos
On all SRX platforms, the memory leak is observed in the Unified Threat Management Daemon (utmd) due to continuous Simple Network Management Protocol (SNMP) polling which ultimately leads to utmd process crash.

Resolved In: junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:19.4R3-S16 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MX10K linecard
1898825
Major
Unexpected line card restart due to timing condition
Product-Group=junos
On Junos platforms using line cards LC480 and LC2101, a timing defect in the embedded microkernel thread handling logic causes a panic when a thread attempts to yield execution while interrupt processing is still active. This panic results in a line card reboot.

Resolved In: evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S8 junos:24.2R2-S2-J9 junos:24.2R2-S3-J7 junos:24.2R2-S4 junos:24.4R2-S3 junos:24.4R2-S4 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf ams related issues
1913560
Major
Routing Engine restart on MX platforms with SPC3 line card could cause loss of traffic processing
Product-Group=junos
On Junos MX960, MX240, and MX480 platforms using SPC3 service line cards, restarting the Routing Engine may result in the network security daemon (nsd) not starting or failing to program internal subsystems like service sets . When this occurs, the control plane becomes unavailable and traffic stops forwarding permanently. This is a timing related behavior observed during the boot sequence and does not appear on every restart.

Resolved In: evo:26.1R1-EVO evo:26.3R1-EVO junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-J10 junos:24.4R2-S4 junos:25.2R2-S1 junos:26.1R1
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1925039
Major
Memory leak in ipv4-to-ipv6 session reuse trigger flowd crash
Product-Group=junos
On Junos OS MX240/MX480/MX960 platforms with MX-SPC3 cards, the flowd process crash and reboots the service PIC when a stale IPv4 session is mistakenly reused for IPv6 due to a memory issue. During process restart the services remain down, session information is briefly lost and active traffic will drop, however the system recovers automatically.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R2-S1 junos:25.4R2 junos:26.1R1 junos:26.2R1

 


 

Modification History

First publication 2026-05-07