Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification (SRN)

Product Affected

ACX PTX QFX

Alert Description

Junos Software Service Release version 23.4R2-S8-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

For your review

Solution

Junos Software service Release version 23.4R2-S8-EVO is now available.

23.4R2-S8-EVO - List of Fixed issues

PR NumberSynopsisCategory: "agentd" software daemon
1913260
Major
Discrepancy noticed in the interfaces when there is a reset in Linecard or PFE
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, with an established telemetry session with multiple collectors, there will be interface statistics discrepancy when there is a linecard OIR event or PFE offline/online sequence.
1929823
Major
The sysd process crashes with error logs upon exceeding its memory limit
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms with telemetry streaming configured, the sysd (System Daemon) process crashes on the backup RE (Routing Engine), and error logs are observed when sysd memory usage continues to grow over time, and the memory limit is exceeded. This issue is observed when the 64-bit sysd consumes more memory than the configured system limit when the device has been running for a long time (typically more than 100 days) in the dual RE scenario.
PR NumberSynopsisCategory: PTX10001 diagnostics software related issues.
1822938
Major
PTX10001-36MR-K Major Alarm Host 0 Ethernet Interface Link Down
Product-Group=evo
Severity=Major
On the PTX10001-36MR-K routers, sometimes on a reboot the "Link Mon" app starts before the eth1 links come UP. This results in the major alarm "Host 0 Ethernet Interface Link Down" being raised. The alarm does not clear on its own although the Eth1 link does come up and there is no issue with management port connectivity.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1846448
Major
The S-BFD responder session cannot be distributed to PFE and failing S-BFD session to establish
Product-Group=evo
Severity=Major
On al MX and PTX platforms, If S-BFD(Seamless-Bidirectional Forwarding Detection) responder is configured without the "lo0.0" on device and with any other "lo0.x " then this S-BFD responder session cannot be distributed to PFE(Packet Forwarding Engine) and fails to come up in distributed mode. Hence BFD service will be impacted.
PR NumberSynopsisCategory: Border Gateway Protocol
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=evo
Severity=Major
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.
1880630
Major
Some BGP sessions remain in the Idle state after all interfaces are deactivated and rollback is issued
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, after all the interfaces are deactivated and the rolled back, some BGP sessions stay in Idle state. This will impact the traffic.
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.
1907391
Major
Routes are hidden when accept-own feature is enabled with rib-sharding
Product-Group=evo
Severity=Major
On MX480 and MX960 platforms, routes become hidden when the "accept-own" feature is enabled in environments configured with rib-sharding. This issue arises when the "vrf-table-label" is configured within a routing instance and route sharding is enabled, potentially leading to routing failures.
1915893
Major
The rpd process crash triggered by LLGR stale timer expiry and late reconnection of unconfigured BGP peer on helper node
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved, when Long-Lived Graceful Restart (LLGR) is configured and a Border Gateway Protocol (BGP) neighbor goes down and reconnects after the LLGR stale timer expires, the Routing Protocol Daemon (rpd) process crashes leading to service disruption.
1935730
Major
BGP session teardown due to incorrect 'prefix-limit maximum exceeded' error when RIB sharding is enabled
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when prefix-limit or accepted-prefix-limit is configured under family route-target with rib-sharding, prefix-limit will be incorrectly reported as 'prefix-limit maximum is exceeded'. This causes the BGP session to go down immediately. This occurs because the system incorrectly counts each received route multiple times (once for the main thread and once for each shard)
PR NumberSynopsisCategory: Track PRs in BGP Flow Spec area & is part of BGP inside RPD.
1945627
Minor
BGP IPv6 Flow Specification Session Flapping When inet6-flow Is Enabled
Product-Group=evo
Severity=Minor
In certain Junos OS releases, BGP sessions may repeatedly reset when IPv6 Flow Specification (inet6-flow) is enabled. This behavior occurs when the router receives specific IPv6 Flow Specification updates that include a default (wildcard) match. Earlier releases do not exhibit this behavior, leading to a difference in observed stability when upgrading.
PR NumberSynopsisCategory: QOS issues in EVO for BCM XGS Platforms
1829998
Major
Intermittent evo-pfemand crash when SNMP query is performed immediately after PFE restart
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, the evo-pfemand crashes intermittently when interface statistics is fetched through SNMP (Simple Network Management Protocol) query immediately after PFE (Packet Forwarding Engine) restart. This issue is seen after multiple PFE restarts and recovers after the evo-pfemand restart.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1890878
Major
On PTX EVO platforms in EVPN-VXLAN scenario traffic will not egress out of the irb next-hop when the bridge-domain doesn't have VXLAN VNI configured
Product-Group=evo
Severity=Major
On all PTX Evolved platforms that support EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN), when the PTX router acts as a MAC-VRF (Media Access Control - Virtual Routing and Forwarding) EVPN gateway, it will fail to forward traffic routed through the 'irb' interface due to packets being discarded at PFE (packet forwarding Engine), causing packet loss.
PR NumberSynopsisCategory: MX304 interface specific
1818120
Critical
100G AOC cable with serial numbers starting with 1A will not get detected on all Junos OS Evolved based FPC
Product-Group=evo
Severity=Critical
On all Junos OS Evolved platforms, MX platforms with MPC10 and above, MX304 and EX9K with EX9200-15C, 100G AOC cable with serial numbers starting with 1A will not get detected. When this issue occurs, interface will go down which causes traffic loss.
PR NumberSynopsisCategory: BX PFE firewall issues
1877486
Minor
Ethernet-switching flood filter stops working when policer action is added
Product-Group=evo
Severity=Minor
On BX-based Junos OS Evolved PTX platforms, when a flood filter with a policer is applied together with VLAN interface configuration in a single commit, the filter may not be properly installed, even though the commit is successful. As a result, the flood filter does not function as intended, leading to degraded traffic handling and performance issues.
PR NumberSynopsisCategory: Express BX PFE L3 Features
1891749
Major
NH Memory Leak and evoaftmand Crash Under High-Scale PNH/MPLS Programming
Product-Group=evo
Severity=Major
On all Junos OS Evolved PTX platforms, Continuous programming of Physical Next-Hop (PNH)/Multiprotocol Label Switching (MPLS) routes with hierarchical Next-Hop Groups (NHGs) can cause a memory leak, leading to NH memory exhaustion. Prolonged updates with a high number of next hops may trigger an evoaftmand core dump. This is a rare issue, typically seen during negative high-scale testing, and does not occur under normal operational loads
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1921796
Minor
Traffic dropped after priority change in VRRP with EVPN-VxLAN scenario
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved platforms, in Virtual Router Redundancy Protocol (VRRP) with Ethernet Virtual Private Network - Virtual Extensible Local Area Network (EVPN-VXLAN) scenario, when VRRP priority is changed, the VRRP virtual Media Access Control (MAC) address can remain pinned as a static entry on the remote device. As a result, MAC movement does not occur correctly, and VRRP packets are dropped on the leaf device. This impacts VRRP operation after priority changes.
PR NumberSynopsisCategory: DNX VPLS
1896785
Major
Stale ARP details after RE switchover leading to traffic loss observed on ACX7K
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX7K Platforms, Layer 3 traffic loss can occur after an RE reboot due to a race condition between ARP and VPLS programming.
PR NumberSynopsisCategory: JUNOS Dynamic Profile Configuration Infrastructure
1930036
Major
High memory usage is showing, when we configure unsupported licensing feature
Product-Group=evo
Severity=Major
On all Junos EX and QFX platforms operating in an EVPN (Ethernet Virtual Private Network) environment, this issue occurs when the CLI command 'licensing hourly update' is executed on a device that does not support the licensing feature.
PR NumberSynopsisCategory: EVO ARP related PRs
1934771
Minor
PyEZ Issue, failing on RPC request "show arp interface <>" to EVO platforms
Product-Group=evo
Severity=Minor
On all Junos Evolved platforms, on invalid interface fetching, display error is seen on "show arp interface <>" command.
PR NumberSynopsisCategory: Firewall related development
1935328
Minor
Prolonged commit time with largescale lo0 filter binds cause configuration load failure
Product-Group=evo
Severity=Minor
On Junos OS Evolved platforms, commit operations with ~38005000 lo0 filter binds take ~4m42s (vs <1m expected). If commit exceeds 5 minutes, mgd times out, which cause configuration load failure and service impact.
PR NumberSynopsisCategory: software upgrade infra issues
1867902
Major
Software upgrade aborts or FPC does not come online on specific Junos Evolved PTX platforms while upgrading with an option validate-restart or add restart
Product-Group=evo
Severity=Major
1. Software upgrade failure is observed on specific to Junos OS Evolved PTX platforms (PTX10004/PTX10008/PTX10016/PTX12K) when 'request system software validate-restart' or 'request system software add restart' is used to perform software upgrade and the base and target image have different IMA (Integrity Measurement Architecture) keys or successful 'request system software add restart', followed by a second 'request system software add restart' will fail and there is a low disk space issues on FPC. 2. FPC is not coming online on specific to Junos OS Evolved PTX platforms (PTX10004/PTX10008/PTX10016/PTX12K) when reboot is performed post installing an image with 'request system software add restart' and the base and target image have different IMA keys.
PR NumberSynopsisCategory: Issues related to debug utilties - objmon, objshell/Dashboard
1899438
Critical
Routing instance mgmt_junos is not being recognized as a valid VRF by the VRF infrastructure, which is causing the outbound SSH application to fail in connecting to the hostname
Product-Group=evo
Severity=Critical
Routing instance mgmt_junos is not being recognized as a valid VRF by the VRF infrastructure, which is causing the outbound SSH application to fail in connecting to the hostname
1932148
Minor
[EVO] snmp get-next on hrStorage mib fails every 10 seconds
Product-Group=evo
Severity=Minor
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1919313
Major
The LDP session does not come up when an IPsec SA is configured under OSPFv3
Product-Group=evo
Severity=Major
On Junos Evolved platforms, when Open Shortest Path First version 3 (OSPFv3) Internet Protocol Security (IPsec) SA is applied at the interface (IFD/IFL) level, Label Distribution Protocol (LDP) is able to discover the neighbor via User Datagram Protocol (UDP) Hellos, but fails to bring up the Transmission Control Protocol (TCP) session, preventing the LDP session from becoming operational. Disabling the OSPFv3 IPsec SA immediately restores normal LDP operation. During the service impact, the session will be down and traffic will not be send. Once the LDP session comes up, traffic can be routed through it.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1926159
Major
Dropping packets on PTX PE from any ingress PE device adds padding to IPv6 packets going over MPLS L3VPN
Product-Group=evo
Severity=Major
On all Junos Evolved PTX series platforms, when acting as egress PE router, it drops padded packets from any ingress PE device. When this occurs, the packets that are discarded are padding to small IPv6 packets going over MPLS L3VPN. If the padding is removed, they are forwarded as expected.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1865935
Minor
Configuration archival via SCP fails with IPv4 and IPv6 archivesites in Junos OS EVO 23.4 or lower
Product-Group=evo
Severity=Minor
In Junos OS EVO 23.4 releases published after March 2025, configuration archival using SCP fails when archive-sites are configured with IPv4 or IPv6 addresses. This behavior is caused by a software defect, where the archival transfer mechanism does not correctly fall back to the legacy SCP implementation required for OpenSSH 7.5 compatibility. This issue does not impact Junos OS EVO 24.4 or later releases.
PR NumberSynopsisCategory: EVPN control plane issues
1894803
Major
Inconsistency is observed between the ARP table learned on PE devices in EVPN-MPLS or EVPN-VXLAN Multihoming scenario
Product-Group=evo
Severity=Major
On all Junos OS and Junos OS Evolved platforms, during EVPN-MPLS (Ethernet VPN over MPLS) or EVPN-VXLAN (Ethernet VPN over VXLAN) multi-homing scenarios (active-active or active-standby) the ARP (Address Resolution Protocol) tables from Customer Edge (CE's) device may not update simultaneously on Provider Edge (PE) devices when an IP address moves between two different Ethernet Segments (ESIs) during a switchover, leading to temporary traffic disruption until the tables are refreshed.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1916646
Major
IRB interface state is observed incorrect on IFD events tracked by a Network Isolation group
Product-Group=evo
Severity=Major
On MX, EX9200, QFX, PTX platforms, Traffic forwarded over the IRB (Integrated Routing and Bridging) is impacted when isolation decisions rely on the state of a tracked interface, because the Network Isolation Group tracks the interface but processes only IFL (Interface Logical) events and does not process IFD (Interface Device) events.
1926818
Major
ARP resolution failure for /32 static host routes via IRB in EVPN virtual-switch routing instances
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms that support EVPN (Ethernet VPN) virtual-switch routing instances, ARP (Address Resolution Protocol) resolution fails for static host routes configured with a /32 mask when the next-hop interface is an IRB (Integrated Routing and Bridging) interface and the destination host resides in a different subnet. As a result, ARP entries are not installed, MAC (Media Access Control) addresses of destination hosts are not learned, and traffic destined to those hosts becomes unreachable, causing service impact.
1943641
Major
ARP and MAC/IP table for virtual IP mac is not installed in bridge domain which is part if EVPN instance
Product-Group=evo
Severity=Major
In any EVPN setups of MX , EX, QFX using Aggregated Ethernet across multiple FPCs, the VRRP virtual IP may fail to install ARP and destination route entries when the VRRP virtual MAC is learned on one FPC while the ARP response is received on another with a source MAC and SHA mismatch.
PR NumberSynopsisCategory: Express AFT Common FW issues
1934506
Major
The FPC crashes when VLANs on an AE interface are updated or deleted
Product-Group=evo
Severity=Major
On all Junos OS Evolved PTX Series platforms with multiple VLANs on an Aggregate Ethernet (AE) interface and an Firewall filter with family ethernet switching and bandwidth policer attached to both the AE interface and its associated VLAN interfaces, a modification or deletion of the VLANs will lead to a FPC crash. All the traffic over the affected FPC will be dropped.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1928462
Major
FPC crash occurs after configuration changes are made to a service-filter on specific MX platforms
Product-Group=evo
Severity=Major
FPC crash and aftd-trio core-dump will be observed on MX platforms supporting MPC10E, MPC11E, LC9600 line cards, and MX304 after configuration changes were made to a service-filter which was in use by BBE subscribers.
PR NumberSynopsisCategory: ACX7332 & ACX7348 Platform Software
1914062
Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
Product-Group=evo
Severity=Major
[ACX] HWD_ALARM_CLEAR_NOTICE: ClearFault: Fault(Location: /Chassis[0]/Psm[0] Device: psm0 Error: psm_cml_pec_fault) cleared
PR NumberSynopsisCategory: ACX7509 Linecard (FPC) related issues
1894512
Minor
Interfaces Fail to Come Up After Repeated Activation and Deactivation of Ports with 1G SFP-T Optics on Junos OS Evolved Platforms
Product-Group=evo
Severity=Minor
On all Junos OS Evolved platforms supporting 1G SFP-T optics , repeated deactivation and reactivation (~12+ cycles) of such interfaces can cause the interface to go down permanently. All the services and traffic running on that interface will be affected.
1931077
Major
CRC errors and packet loss are being observed at the peer device when using 1G fibre optic connections
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7509, ACX7348, ACX7332, and ACX7100-32C platforms with 1G fibre Optics, when the Inter-Packet Gap (IPG) setting intermittently falls below the IEEE minimum requirement of 8 bytes, and traffic passes through the PHY, certain receiving devices are sensitive to this reduced IPG, which leads to CRC (Cyclic Redundancy Check) errors and packet loss on the peer device connected to 1G fibre optics connection.
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.
PR NumberSynopsisCategory: jdhcpd daemon
1825998
Major
DHCP ALQ process crashes to recover from memory leak.
Product-Group=evo
Severity=Major
On all Junos platforms , In a rare scenario when memory leak happens the Dynamic Host Configuration Protocol (DHCP) active-leasequery (ALQ) process crashes automatically.
1927449
Major
Jdhcpd cores generated after upgrade
Product-Group=evo
Severity=Major
jdhcpd cores seen after upgrade with dhcpv6 for IANA/PD
1939685
Minor
Insert command not working for "dhcp-local-server group" hierarchy
Product-Group=evo
Severity=Minor
Insert command not working for "dhcp-local-server group" hierarchy, below error is seen: user@host# insert system services dhcp-local-server group servers-1 after syntax error, expecting `after' or `before'. user@host# insert system services dhcp-local-server group servers-1 bef syntax error, expecting `after' or `before'.
PR NumberSynopsisCategory: Layer 2 Control Module
1930380
Major
The hash collision for storm control profile indices will result in an l2ald process crash
Product-Group=evo
Severity=Major
On all Junos OS platforms and Junos OS Evolved platforms which supports storm control, when a different storm-control profile is applied for interface where these profile have same profile index allocated then the storm control profile configuration and system state will not be in sync and a different profile will be applied for interface binding due to profile index collision which results into l2ald process crash.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1816344
Major
EVPN : Traffic failure after multiple link flaps of core facing interfaces on scaled setup
Product-Group=evo
Severity=Major
ARP resolution failure when there is quick flap of core facing interface on scaled setup
1928530
Critical
A buffer overflow during IPv6 NDP operations in an EVPN environment caused segmentation faults leading to FPC crash files and repeated reboots
Product-Group=evo
Severity=Critical
On JunOS MX240/MX480/MX960/MX2008/MX2010/MX2020 platforms with MPC10E/MPC11E line cards as well as the MX304 platform, an issue in IPv6 EVPN (Ethernet Virtual Private Network) during NDP (Neighbor Discovery Protocol) resolicitation of a link local target address causes the system to use the IRB link local address in outgoing packets. Stack corruption happens when handling the IRB link local address and resulting in continuous FPC (Flexible PIC Concentrator) reboots (around 3 or 4 times) and crash files generation.
1936648
Major
EVPN-VXLAN remote MAC IP programming is removed after a MAC move, resulting in missing ARP on a remote VTEP
Product-Group=evo
Severity=Major
In an Ethernet VPN (EVPN) Virtual Extensible LAN (VXLAN) deployment, a remote MAC move event can cause the remote MAC IP entry to be removed after it is initially installed, resulting in missing Address Resolution Protocol (ARP) state and incomplete hardware programming on the remote Virtual Tunnel Endpoint (VTEP), which can lead to traffic loss for the affected endpoint.
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1881572
Minor
Logs are seen when unsupported feature license key is added
Product-Group=evo
Severity=Minor
Logs are seen when unsupported feature license key is added using "request system license add " command. It is a display issue.
1897682
Major
Incorrect port bandwidth license usage is shown when VLAN tagging is enabled on ae interfaces.
Product-Group=evo
Severity=Major
On PTX platforms running Junos EVO, ae interfaces are excluded from bandwidth calculation when VLAN tagging is configured.
1933553
Minor
License check process crashes due to mutex synchronization issue
Product-Group=evo
Severity=Minor
A software issue was identified in the license check process that could cause the process to crash due to a synchronization condition between internal threads. This behavior may occur when multiple threads access the LicenseMonitorEventNotify() function simultaneously, potentially leading to a mutex deadlock and generating a core dump. This issue has no impact on traffic forwarding or network services.
PR NumberSynopsisCategory: MPC11 ULC platform software related issues.
1881499
Minor
On MPC11E linecards, Periodic error messages are logged as "Temp sensor DDR4 A failed"
Product-Group=evo
Severity=Minor
DDR temp sensor is designed to be used periodically to get temps to send to chassisd. The temp sensors reside may have an intermittent contention that can cause these read failures resulting in DDR4 Temp Sensor Fail" logs on MPC11E linecards.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1908506
Major
Frequent link-protection flaps are observed for container LSP's with no change in member LSP
Product-Group=evo
Severity=Major
This is a timing issue seen on all Junos and Junos OS Evolved platforms when the optimisation timer expires for a member LSP (Label-Switched Path) when normalisation is in progress for a container LSP, this generates an unrequired route update leading to the link protection route of the LSPs to flap. LSP flap will result in impact on the traffic.
PR NumberSynopsisCategory: Multicast for L3VPNs
1918004
Minor
Multicast traffic disruption in multi-homed networks
Product-Group=evo
Severity=Minor
On Junos and Junos OS Evolved platforms, blackholed traffic disruption can occur in multi-homed NGEN MVPN (Next Generation Multicast Virtual Private Network) setups when a PE(Provider Edge) acting as both multicast source and DR/RP (Designated Router/Rendezvous Point) experiences path changes or flaps, provided the source is local and multi-homed across two PEs.
PR NumberSynopsisCategory: Path computation client daemon
1929225
Critical
The pccd process crashes when muliple LSP updates are received from PCE
Product-Group=evo
Severity=Critical
On all Junos and Junos Evolved platforms with PCEP (Path Computation Element Protocol) configured, the pccd process crash is seen when multiple LSP (Label Switched Path) updates are received in a single PCE (Path Computation Element) message. The LSP update sent by the PCE will not get programmed into the forwarding plane and LSP states will not be updated till the pccd process restarts.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1931633
Major
PFE crash due to memory corruption when STP is enabled
Product-Group=evo
Severity=Major
On all Junos Platforms, a rare memory corruption condition may occur in the Packet Forwarding Engine (PFE) when Spanning Tree Protocol (STP) is enabled and operating in default (distributed) mode. When the issue is triggered, the PFE crashes and a dc-pfe core file is generated. The exact trigger for the memory corruption is currently unknown.
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=evo
Severity=Major
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1937870
Minor
Incorrect module temperature readings trigger unintended optics shutdown
Product-Group=evo
Severity=Minor
On MX platforms with MPC11, LC9600, LC4800 Linecards, MX304 and all Junos OS Evolved platforms, optics modules intermittently reports extremely high false temperature values in "show interfaces diagnostics optics" command. This can trigger false high-temperature alarms, leading to unnecessary optics shutdown.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1906718
Critical
Junos OS and Junos OS Evolved: CVE-2022-24805 resolved in net-SNMP
Product-Group=evo
Severity=Critical
CVE-2022-24805 has been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved. Please refer to https://supportportal.juniper.net/JSA107822 [juniper.net] for more information.
PR NumberSynopsisCategory: Segment routing traffic Engineering
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=evo
Severity=Major
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1927107
Major
FPC might crash with high scale of BBE subscriber
Product-Group=evo
Severity=Major
On MX304 and MX platforms with MPC10, MPC11, or LC9600, the Flexible PIC Concentrator (FPC) might crash when operating with a high scale of Broadband Edge (BBE) subscriber.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1926050
Major
The auditd process crashes when the Radius server is configured but unreachable
Product-Group=evo
Severity=Major
On Junos OS and Junos OS Evolved having the Radius (Remote Authentication Dial-In User Service) server with accounting configured, the auditd crash is observed if the Radius server is unreachable for a long time and a large number of accounting records accumulate, which leads to memory exhaustion during accounting processing and results in a process crash.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1872703
Major
Junos OS: Privileged local user can gain access to a Linux-based FPC as root (CVE-2025-30650)
Product-Group=evo
Severity=Major
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. Please refer to https://supportportal.juniper.net/JSA107863 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to NETCONF
1858635
Critical
ACX Series vmcore crash when netconf notifications are enabled
Product-Group=evo
Severity=Critical
On ACX7024, ACX710032C, and ACX7348 platforms running Junos OS Evolved, enabling netconf notifications with the command "set system services netconf notification" may cause a memory leak. This results in a control plane crash (vmcore). Forwarding plane remains unaffected.
PR NumberSynopsisCategory: ACX724 platform issues
1895749
Critical
BIOS version 22.01 - for ACX7024 - System crashes due to a CPU glitch
Product-Group=evo
Severity=Critical
On Junos Evolved ACX7024 and ACX7024X platforms, the system crashes, and a kernel crash is generated due to a random CPU error.
PR NumberSynopsisCategory: Virtual Private LAN Services
1806424
Major
The snmp mib walk on jnxVplsPwBindTable fails with vpls routing-instances having multiple mesh-groups
Product-Group=evo
Severity=Major
If VPLS mesh-groups are configured with different neighbours having different vpls-id the SNMP mib walk over jnxVplsPwBindTable might fail with the error Request failed: OID not increasing. No functional impact is seen due to this issue.
PR NumberSynopsisCategory: ACX7000 platform software related issues.
1799095
Minor
sysObjectID.0 does not display product name on ACX7024X
Product-Group=evo
Severity=Minor
On Junos OS Evolved ACX7024 the sysObjectID.0 is blank when the CLI (Command Line Interface) command 'show snmp mib' walk sysObjectID ' is executed. The expected output should be the product name instead of blank output, there is no impact of data traffic because of this.
1935793
Major
I2C alarm and traffic drop is seen with a type of QSFP on certain ACX platforms
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX7100-32C, ACX7100-48L, ACX7100-32C-K and ACX7100-48L-K platforms when QSFP-100G-FR optics which has serial number starting with 2J4 is plugged in, it is observed that the port goes down with I2C(Inter-Integrated Circuit) access failure alarm and traffic is dropped.

 


 

23.4R2-S8-EVO - List of Known issues

PR NumberSynopsisCategory: Software build tools (packaging, makefiles, et. al.)
1663426
Major
NETCONF: RPC get & get-configuration display invalid json format response for an OpenConfig when adds a routing-options configuration
Product-Group=evo
After adding a "routing-options" configuration via OpenConfig operation, subsequent "get" and "get-configuration" may display an invalid JSON format.

Resolved In: evo:24.2R2-S5-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: "agentd" software daemon
1886043
Major
Few telemetry paths are not exported after router reboot
Product-Group=evo
Following a router reboot, the router management socket, telemetry infrastructure, and RE daemons (such as mib2d and rpd) become operational before telemetry producers. Consequently, the external telemetry collector can establish a connection (e.g. sensor: "/interfaces" ; sample-mode) with the device as soon as the telemetry infrastructure and management interface are up and running. Since producers require several minutes to come up. Therefore, na-grpcd sends a consolidated initial sync completion message to the external collector based on the local init-sync responses from the telemetry producers present at telemetry subscription time (mostly RE based producers). When an application (evo-aftman-bt) becomes operational, a sensor is installed within it (if applicable).However, it is possible that the application has not consumed, thus not exported the interfaces data at the initial sync time (local to the application). As zero-suppression is activated after initial sync, a few statistics with a zero value will not be exported by the device.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:24.4X200-D30-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1947511
Major
OSPF adjacency will fail when OSPF is configured IRB VLAN interface which is enabled with IGMP-snooping
Product-Group=evo
In Junos Evolved QFX5220, QFX5230 and QFX5240 platforms, when IGMP-snooping is enabled on IRB VLAN interface and OSPF is configured on same IRB VLAN interface, OSPF adjacency fails with peer neighbour.

Resolved In: evo:25.2X100-EVO evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1928605
Minor
IRB routed traffic is dropped when both hosts are learned on the same SP-style Layer 2 interface on EVO-PTX platforms
Product-Group=evo
On all Junos OS Evolved PTX platforms, IRB (Integrated Routing and Bridging) routed traffic is dropped when both source and destination hosts are reachable through the same Service Provider (SP)-style Layer 2 IFL (Logical Interface) and associated IRB interface.

Resolved In: evo:23.2R2-S8-EVO evo:24.2R2-S5-EVO evo:25.4R1-S3-EVO evo:25.4R2-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1893165
Major
Micro BFD packets egress through incorrect queue on PTX platforms
Product-Group=evo
On PTX platforms that support inline micro BFD ( Bidirectional Forwarding Detection), the BFD packets are sent through Q3 ( network-control queue) instead of Q5 (protocol queue). This can cause packet drops due to wrong queue selection.

Resolved In: evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.4R1 junos:26.1R1
1947926
Major
The forwarding traffic drops on Next-hop corruption when ARP/NDP fails to re-learn
Product-Group=evo
On Junos Evolved PTX platforms, when Class-of-Service (CoS) forwarding-class is enabled, there's a mis-handle during route install. Due to ARP/NDP (Address Resolution Protocol (IPv4) / Neighbor Discovery Protocol (IPv6)) timeout, the internal Next-hop changes are not updated properly, causing the route to point to invalid memory. It will affect the forwarding traffic to a destination that is tied to a Class-of-Service forwarding-class, with the classification-override feature enabled. As a result the route points to invalid Next-hop memory in hardware and traffic drops.

Resolved In: evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO
PR NumberSynopsisCategory: CoS support on DNX
1776127
Major
Multihop BFD packets always uses the network-control egress queue
Product-Group=evo
Multihop BFD packets by default uses the network-control queue in EVO ACX. This setting will remain same despite configuring the host-outbound-traffic to a different forwarding-class.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: Firewall support for DNX
1836457
Major
Traffic is dropped without entering the SRv6 dynamic tunnel
Product-Group=evo
On all ACX platforms all the traffic directed towards a SRv6 (Segment Routing IPv6) dynamic tunnel it's not getting forwarded inside the tunnel and gets dropped.

Resolved In: evo:24.2R2-S4-EVO evo:24.2X2-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: Host path software for ACX platform
1930141
Major
The ACX-Series platforms stop sending and receiving control plane traffic.
Product-Group=evo
On all ACX-Series platforms running Junos Evolved Operation System (OS), the device stops sending and receiving control plane traffic and a packetio core-dump is generated while handling incorrect packets length received from ASIC.

Resolved In: evo:24.4R2-S3-J10-EVO evo:25.4R1-S3-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO evo:26.3R1-EVO
PR NumberSynopsisCategory: DNX L2 related features
1841573
Minor
High CPU utilization observed on all Junos Evolved ACK7k platforms
Product-Group=evo
On all Junos Evolved ACX7k platforms, high CPU utilization is observed when multiple IFLs (logical interface) are configured over the same IFD (physical interface device). The Broadcom (Brcm) MACs become out of sync with Routing Engine (RE) MACs, performance is affected, and then there is potential traffic disruption.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO
PR NumberSynopsisCategory: Index management related issues; idmd* daemons
1879392
Major
The rpdagent crashes due to the forward slash character being used in routing-instance name
Product-Group=evo
On all Junos Evolved platforms, configuring a routing-instance name with special characters such as forward slash can trigger a 'rpdagent' crash causing traffic disruption.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S4-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.2R1-EVO evo:26.3R1-EVO junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: System Management daemon and related issues
1852221
Minor
The l2cpd-agent crashes due to its state cleaned up during shutdown
Product-Group=evo
On all Junos Evolved platforms, due to a timing issue, it is observed that the l2cpd agent crashes when the app's state is being cleaned by external garbage collection as app is about to shutdown. But there is no traffic impact due to this issue.

Resolved In: evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.2R1-EVO evo:26.3R1-EVO
PR NumberSynopsisCategory: EVO TCP AO module
1924030
Major
BGP/LDP sessions flap due to TCP sequence number wraparound when TCP-AO is enabled
Product-Group=evo
On all Junos OS Evolved platforms, Border Gateway Protocol (BGP) or Label Distribution Protocol (LDP) sessions will intermittently flap when Transmission Control Protocol-Authentication Option (TCP-AO) is enabled under high traffic or long-lived connections due to TCP sequence number rollover, leading to TCP authentication failures. The issue is primarily observed in interoperability scenarios and does not cause system crashes.

Resolved In: evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.2X100-EVO evo:25.4R2-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: Configd, ffp issues
1907238
Minor
Rescue Configuration Check Fails
Product-Group=evo
On all Junos OS Evolved ACX Series platforms, which do not verify the syntax and integrity of the saved rescue configuration file when performing a configuration check, rescue configuration check fails.

Resolved In: evo:25.2R2-S1-EVO evo:25.4R2-EVO evo:25.4X300-EVO evo:26.1R1-EVO evo:26.2R1-EVO
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1813021
Major
JDI-REG : VIRTUAL : JUNOS : Observing jsd.core with backtrace @exec_ctx_run, @pollset_work, @grpc_pollset_work
Product-Group=evo


Resolved In:
PR NumberSynopsisCategory: Category for QFX5K EVO Platform Software PRs related to Inte
1747315
Minor
On QFX5230-64CD 400G DAC cable of 2.5m and 4X100G DAC Break out may not link up with some peer devices
Product-Group=evo
On QFX5230-64CD platform, 400G DAC cable of 2.5m length and 4X100G DAC BO may not link up with some peer devices. This issue is not seen with all peer devices. If this happens, please replace the 2.5m cable with a 1m DAC cable or use supported 400G Optics instead.

Resolved In:
PR NumberSynopsisCategory: PTX10K specific platform PRs
1621525
Major
Junos OS Evolved: Local, authenticated attackers can gain access to FPCs (CVE-2026-33788)
Product-Group=evo
A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. Please refer to https://supportportal.juniper.net/JSA107806 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S7-EVO evo:22.1R3-S6-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D47-EVO evo:22.4R3-S2-EVO evo:23.2R2-EVO evo:23.2R2-S1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:23.4R1-S2-EVO evo:24.1R1-EVO junos:24.1R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1800466
Major
Hamilton :: LC4800 :: Initial Sync values not streaming
Product-Group=evo
Hamilton :: LC4800 :: Initial Sync values not streaming

Resolved In:
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=evo
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: Issues related to YANG Data Models
1781023
Minor
Few yang package are occuring multiple place On Box
Product-Group=evo
Few yang package are occuring multiple place On Box

Resolved In: