Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX4400 QFX5200

Alert Description

Junos Software Service Release version 26.2R1-S1 is now available for EX4400 and QFX5200 series platforms. You can download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we included PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 26.2R1-S1 is now available.

26.2R1-S1 - List of Fixed issues

PR NumberSynopsisCategory: EX interfaces issues
1923212
Major
PFE process crash occurs during EX4k boot-up
Product-Group=junos
Severity=Major
On EX4400/4100 platforms, PFE process (fxpc) crash occurs with a segmentation fault (SIGSEGV) during device boot-up. The crash occurs during the Broadcom PHY firmware broadcast download sequence when initializing the external PHY. No service impact as this crash happens at initial boot cycle.
PR NumberSynopsisCategory: EX5200/7200 SW Platform
1962954
Major
EX5200-48MP supports the "request system power-cycle" CLI command; Not all EX4400 SKU variants support this power-cycle option even though the cli command option is available
Product-Group=junos
Severity=Major
EX5200-48MP supports the "request system power-cycle" Command-Line Interface (CLI). The EX4400-48XP/EX4400-48MXP devices support the "request system power-cycle" command and perform a power cycle as expected. Other EX4400 SKU variants do not support actual power-cycle even though the command is exposed and will undergo a normal reboot when this command is executed.
PR NumberSynopsisCategory: ISSU control procedure
1947573
Minor
ISSU will abort on EX-4400, EX-4100 and EX-4000 if any ISSU incompatible configurations are detected on the device.
Product-Group=junos
Severity=Minor
During ISSU image validation, SW will now check for any ISSU incompatible configurations configured on the device.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1960476
Major
Event script fails during a virtual chassis role change
Product-Group=junos
Severity=Major
Event script failure occurs during a virtual chassis primary role change when the system is unable to load a required component at the time the script is executed.

 


 

26.2R1-S1 - List of Known issues

PR NumberSynopsisCategory: NSD process
1965308
Minor
The nsd process will crash during tunnel inspection operations, resulting in traffic disruption and preventing tunnels from coming up
Product-Group=junos
On SRX platforms running Junos OS versions 23.2 through 25.4, tunnel inspection-related operations involving the security tunnel-inspection feature can cause the nsd process to abort, resulting in traffic disruption and preventing tunnels from coming up. The issue is not triggered solely by the presence of the configuration, but by specific tunnel inspection-related operations such as applying configuration changes, committing updates to security tunnel-inspection, or restarting network-security processes. Recovery is automatic, and the affected FPC should return to an operational state after the crash

Resolved In: junos:25.4R2 junos:26.2R2 junos:26.4R1
1965832
Major
DNS cache failure occurs when the number of routes to the DNS server is a multiple of 256, causing FQDN object resolution to fail on SRX platforms
Product-Group=junos
On Junos SRX platforms of Mid-range (SRX1500, SRX1600, SRX2300) and High-end SRX platforms (SRX4K and SRX5K) platforms, Domain Name System (DNS) cache will not work for Fully Qualified Domain Name (FQDN) referenced objects which are a match criteria in a security policy or NAT rules, when the total number of routes that can reach to the DNS server is a multiple of 256. When this happens the DNS query will not be sent out from the SRX, and the TTL value in the DNS cache table will stay 0 or no IP address will not be populated in the dns-cache table. The related NAT or security-policy lookup may fail, which can lead to traffic drops.

Resolved In: junos:23.2R2-S8 junos:25.4R2 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: NFX Layer 2 Features Software
1913362
Major
NFX150-HA: With manual failover, IPsec tunnel might not form sometimes
Product-Group=junos
NFX150-HA: With manual failover, IPsec tunnel might not form sometimes

Resolved In:
PR NumberSynopsisCategory: MPC10/11/LC9600 Chassis Category
1965224
Major
Incorrect high-temperature readings trigger chassis shutdown
Product-Group=junosvae
An incorrect high-temperature reading from the Intake-B temperature sensor on MX10004 and MX10008 systems running Junos OS with LC9600 line cards triggers an over-temperature condition and causes an automatic chassis shutdown. This results in a complete service outage that requires manual intervention to restore service.

Resolved In: junos:23.2R2-S3-J24 junos:26.4DCB junos:26.4R1
PR NumberSynopsisCategory: Border Gateway Protocol
1954341
Major
EIBGP ECMP routes are not re-evaluated after modifying the allow-external-internal prefix-policy
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, when BGP Equal-Cost Multi-Path (ECMP) External-Internal BGP (EIBGP) routing is configured using allow-external-internal prefix-policy knob, changes made to the referenced prefix-policy will not be automatically re-evaluated for existing routes after the BGP session is already established. As a result, route selection and EIBGP ECMP behaviour continue to use the previously evaluated policy state until a manual route refresh is performed.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.4R1
1969577
Major
The rpd process crashes when deleting BGP VPN routing instances during an active SNMP walk on the RIB
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, rpd process crash is caused by deleting a routing-instances of type Virtual Routing and Forwarding (VRF) while a Simple Network Management Protocol (SNMP) walk operation is in progress.

Resolved In: evo:23.2R2-S8-EVO evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:23.2R2-S8 junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1976553
Major
,BGP flaps when receives malformed BGP packets on the backup RE
Product-Group=junos
When the BGP session went down, it entered helper mode and retained the received route as a stale route along with its add-path ID. It also clears the add-path capabilities of the session as the session is down now. With GRES/NSR, if the device tries to sync this session to the backup RE when the session is still in helper mode, then the device does not send add-path capabilities for this session but still send the stale route along with the add-path ID. On backup RE, it incorrectly tries to decode the route's path ID as its prefix length resulting in the malformed update errors and flap of the entire replication session. These replication flaps continue in a loop and affect the regular BGP sessions on master RE(due to repeated I/O thread disable and enable affecting the keepalive transmissions).

Resolved In: evo:26.2R2-EVO evo:26.4R1-EVO evo:27.1R1-EVO junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: BBE Remote Access Server
1967413
Major
The authd process crash is seen when IPv6 address is set as the source address under the radius-server
Product-Group=junos
On MX platforms, the authd (authentication daemon) process crashes when an IPv6 address is set as the source address under the radius-server in the access configuration, followed by a device reboot.

Resolved In: junos:23.2R2-S8 junos:26.4R1
PR NumberSynopsisCategory: MX304 fabric issues (ULC side)
1969878
Minor
PFE remains disabled after MIC1 offline/online operation or hot swap
Product-Group=junos
On Junos OS MX304 platform, performing an LMIC (Line Module Interface Card) offline/online operation or LMIC hot swap on MIC1 (Modular Interface Card 1) causes the associated PFE (Packet Forwarding Engine) to remain disabled after recovery. This results in reduced fabric bandwidth and traffic impact due to fewer available PFEs.

Resolved In: junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1964581
Minor
MX2020/MX2010 inserted SFB not correctly shown in "show chassis" commands before online
Product-Group=junos
On the MX2020/MX2010 platforms, when inserting SFB into empty slot and didn't issue "request chassis sfb slot online", some variants of "show chassis" command cannot correctly show the info of target SFB. After issuing "request chassis sfb offline" and re-inserting the SFB, the i2c_data_sent flag is never set because the SFB is not scheduled for power-on in that path. As a result, chassisd never receives the I2C/IDEEPROM data and the SFB does not appear as "Present" in show chassis hardware models / show chassis environment sfb. There is no service impact.

Resolved In:
PR NumberSynopsisCategory: MX Platform SW - UI management
1969032
Minor
ENTITY-MIB returns incorrect hardware containment information for SFP Optics
Product-Group=junos
On Junos OS platforms, devices return incorrect information in response to queries for SFP (Small Form-factor Pluggable) inventory and hierarchy levels when data is retrieved using the standard SNMP MIB (Simple Network Management Protocol Management Information Base). As a result, the ENTITY-MIB object 'entPhysicalContainedIn' can report an incorrect parent hardware component for SFP optics

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:27.1R1-EVO junos:25.4R2 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: Device Configuration Daemon
1970933
Major
Tunnel interface flaps observed on every DNS TTL refresh when FQDN is used as the destination of IP-IP tunnel and the ip-0/0/0 interface is in a routing-instance
Product-Group=junos
On Junos OS SRX platforms, when FQDN (Fully Qualified Domain Name) is used for the destination of IP-IP (Internet Protocol-in-Internet Protocol) tunnel and the ip-0/0/0 interface is in a routing-instance, the ip-0/0/0 interface flaps every time the SRX sends DNS (Domain Name System) query. The issue is caused by a timing condition between rpd (Routing Protocol Daemon) and dcd (Device Control Daemon) during DNS (Domain Name System) re-resolution, resulting in tunnel interface flaps, leading to packet loss.

Resolved In: junos:25.4R2 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1968928
Minor
False Routing Software Alarms Triggered by Incorrect Bridge Domain Classification as Multicast VXLAN
Product-Group=junos
On Junos OS and Junos OS Evolved, if Virtual Local Area Networks (VLANs) configured in a Media Access Control Virtual Routing and Forwarding (MAC-VRF) instance with Virtual Extensible Local Area Network (VXLAN) are not included in the associated protocols evpn vni-list, the system incorrectly identifies the corresponding Bridge Domains (BDs) as multicast VXLAN bridge domains. This behavior can result in unnecessary Virtualized Multi-Homing Enhanced (VMENH) next-hop creation and trigger a false routing software alarm

Resolved In: evo:26.2R2-EVO evo:26.4R1-EVO junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1963894
Major
Local MAC addresses are not learned on newly added EVPN all-active interfaces
Product-Group=junos
On Junos OS and Junos OS Evolved systems configured with Ethernet VPN (EVPN) Media Access Control Virtual Private Network (MAC-VRF) over Multiprotocol Label Switching (MPLS), when a new all-active interface is added to a service that uses a VLAN-aware instance with interfaces from multiple Ethernet Segments (ESIs) and Egress Link Protection (ELP) enabled, local Media Access Control (MAC) addresses are not learned on the newly added interface. As a result, Layer 2 forwarding for the affected service is impacted and complete loss of Layer 2 forwarding can occur for the affected service. Service can be restored by restarting the affected routing application

Resolved In: evo:24.4R2-S1-J11-EVO evo:24.4R2-S2-J30-EVO evo:24.4R2-S2-J31-EVO evo:24.4R2-S3-J24-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:26.2R2 junos:26.3R1 junos:26.4R1
1964040
Major
Traffic loss for EVPN-MPLS virtual gateway after routing instance changes
Product-Group=junos
On Junos MX, EX 9200 platforms supporting Ethernet virtual private network (EVPN) over Multiprotocol Label Switching (MPLS), adding or deleting an EVPN routing instance configured with vlan-id none, or an Integrated Routing and Bridging (IRB) interface with Virtual Gateway (VGW) going down, withdraws a shared Auto-Discovery/Ethernet Segment (AD/ES) route, resulting in Address Resolution Protocol (ARP) failure and traffic loss.

Resolved In: evo:25.4R2-EVO evo:26.4R1-EVO junos:24.4R2-S4-J16 junos:25.4R2 junos:26.4R1
1966268
Major
In EVPN Node Detection (Backup Liveness Detection), BFD sessions remain down on management interface which is configured in non-default routing instance
Product-Group=junos
On all Junos and Junos Evolved platforms, BFD (Bidirectional Forwarding Detection) liveness sessions may remain Down when the management interface is configured in the mgmt_junos routing instance or any non-default VRF (Virtual Routing and Forwarding) instance under EVPN Node Detection. As a result, EVPN node detection is not triggered upon peer-node failure.

Resolved In: evo:26.4R1-EVO junos:26.4R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1964717
Minor
ND-NS requests for unknown IPv6 targets are not dropped when drop-unknown-mac-ip is used
Product-Group=junos
When drop-unknown-mac-ip is configured, ARP requests (IPv4) and Neighbor Solicitation messages (IPv6) for target IP addresses not present in the MAC-IP table are incorrectly flooded across the EVPN fabric instead of being dropped at the ingress PE. The drop-unknown-mac-ip knob was only being evaluated against the source IP address of incoming ARP/NS packets. When the source was a known static entry but the target IP was unknown, the packet passed the source check and proceeded to be reinjected into L2 forwarding, flooding it to remote PEs and CEs. Added a check so that when drop-unknown-mac-ip is configured and the target IPv4/IPv6 address is not found in the MAC-IP table, the ARP request or Neighbor Solicitation is dropped at the ingress PE rather than being flooded to the EVPN fabric.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: EX4000 PFE issues
1960265
Major
Commit is successful but failed to allocate vrf error
Product-Group=junos
TBD

Resolved In:
PR NumberSynopsisCategory: EX4100 RE, Platform Infra, Drivers
1942521
Major
request system firmware upgrade jfirmware allfw only upgrading only one of the components when multiple components are available for upgrade
Product-Group=junos
request system firmware upgrade jfirmware allfw only upgrading only one of the components even when multiple components are available for upgrade

Resolved In: junos:25.4R2
PR NumberSynopsisCategory: EX interfaces issues
1955093
Major
EX4400-24P: Output packet rate exceeds expected value when flow control is enabled
Product-Group=junos
EX4400-24P: Interface traffic statistics may report incorrect output packet rate

Resolved In:
1962091
Major
EX5200 with 8x25G ULM: Ge interfaces on the ULM were down after multiple iterations of device reboot or removal/insertion of the ULM in the PIC2 slot
Product-Group=junos
On an EX5200 device with 8x25G uplink module(ULM) inserted in PIC2, in some instance during repeated reboot operations or removal/insertion of the ULM in the PIC2 slot, the 1G link will remain in down state

Resolved In:
PR NumberSynopsisCategory: EX5200/7200 PFE
1949715
Major
IFL stats show inflated values when Port-mirror or Analyzer in configured.
Product-Group=junos
When port mirroring or analyzer is enabled, the output packet and byte counters for logical interfaces (IFL) of input interface show inflated counts (includes the count of mirrored pkt count). This behavior is by design in hardware.

Resolved In:
PR NumberSynopsisCategory: EX optics issues
1887303
Minor
[EX4400-48F] One of the 10gBase-T transceiver is not detected - showing as "Partial" Unknown in PFE
Product-Group=junos
In the EX4400-48F systems, a 10G-BaseT transceiver that was earlier up may not come up post a reboot/image upgrade event; The transceiver may go undetected causing the interface to not be created in the system.

Resolved In:
PR NumberSynopsisCategory: EX POE
1913669
Major
EX: On OIR of 2nd PSU feeder, APs which go down due to insufficient power take time ~ 47 seconds to come up
Product-Group=junos
When a Power Supply Unit (PSU) is removed and reinserted in an EX5200 48/24MP-member Virtual Chassis (VC) setup, PDs that were down due to a lack of power may take between 14 to 47 seconds to repower. This behaviour is due to the system's automatic update of power bank programming and subsequent power budget calculation, which occurs when a PSU is replaced or its power cable is reconnected. There is no functional impact due to this behaviour, and the only effect is on the uptime of Power Devices (PDs), which may experience a slightly longer downtime before powering back on.

Resolved In:
1939315
Major
EX: OIR of PSU within short intervals can affect APs not to come up in N+1 PSU redundancy mode.
Product-Group=junos
EX: OIR of PSU within short intervals can affect APs not to come up in N+1 PSU redundancy mode. Work-Around: restart chassisd daemon helps to recover from the issue. Recommendation: Please wait enough (~30s) between OIRs of PSUs

Resolved In:
1969511
Major
False alarms related to PoE Device Manager failures were observed on EX4100
Product-Group=junos
On EX4100-F-24P and EX4100-24P platforms, while running 26.2R1 Junos release, PoE (Power over Ethernet) device manager failed alarms observed for PoE manager 3 to 11 without any triggers. These PoE device managers does not exist physically in these platforms. The actual PoE device managers are 0, 1 and 2. The alarms are cosmetic and there is no operational impact. These alarms can be ignored.

Resolved In: junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1916949
Major
Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood (CVE-2026-57020)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA110080 [juniper.net] for more information.

Resolved In: junos:22.2R3-S8 junos:22.3R3-S5 junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S4
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1960371
Major
RG1 failover is not automatically triggered after fan failures on SRX4100/SRX4200 chassis clusters, resulting in traffic degradation
Product-Group=junosvae
On SRX4100 and SRX4200 chassis clusters, when all chassis fans fail or are removed, the affected node continues forwarding traffic in a degraded thermal state instead of automatically triggering a Redundancy Group 1 (RG1) failover. This result in the traffic loss on the affected node.

Resolved In: junos:25.2R2-S2 junos:25.2R2-S3 junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: IDP attack detection in the subscriber qmodules
1853515
Major
Accuracy Failures Observed in ARM-based cSRX platform
Product-Group=junos
For cSRX/ARM platform, the below three attacks need to be configured outside the attack groups for proper detection. SHELLCODE:X86:AVD-UTF8TLWR-STC SHELLCODE:PHP:BASE64-STC HTTP:NNMRPTCONFIG-EXE-RCE

Resolved In:
PR NumberSynopsisCategory: IDP policy
1921354
Major
IDP: On-box packet capture fails when packet-log host or port is not reachable with SSL Initiation Profile
Product-Group=junos
IDP: On-box packet capture fails when packet-log host or port is not reachable with SSL Initiation Profile For On-box packet capture, ssl initiation profile configuration is NOT required. This issue will not be seen if we do not configure ssl initiation profile.

Resolved In:
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1943169
Major
ipv6 router advertisement not processed on vme/me interface
Product-Group=junos
On EX5200 and EX4400 family switches, IPV6 Router Advertisement packets are getting dropped by i210 NIC controller as its MTA table is not program with the hash of multicast MAC address: 33:33:00:00:00:01(IPv6 RA packet multicast group mac address)

Resolved In:
PR NumberSynopsisCategory: ISIS routing protocol
1955832
Minor
Inconsistent ISIS IPV6 topology information seen in "show isis adjacency detail" command
Product-Group=junos
On all Junos and Junos OS Evolved platforms with IS-IS and IPv6 enabled, after interface flap, command "show isis adjacency detail" shows additional IPv6 topologies along with Unicast topology in the output. This is a display issue and non service impacting.

Resolved In: evo:26.3R1-EVO
PR NumberSynopsisCategory: jdhcpd daemon
1947179
Major
The dhcpd crash triggered by DHCPv6 ALQ peer state inconsistency
Product-Group=junos
On MX104, MX204, MX240, MX301, MX304, MX480, MX960, MX2008, MX2010, MX2020, MX10003, MX10004, MX10008 and MX10016 platforms DHCPv6 (Dynamic Host Configuration Protocol version 6) ALQ (Active Lease Query) peer state inconsistency creates an invalid subscriber entry for a bound IPv6 address, resulting in a jdhcpd (Junos DHCP daemon) crash with recurring core dumps and subscriber traffic impact.

Resolved In: evo:24.2R2-S6-EVO evo:25.2R2-S2-EVO evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO junos:23.4R2-S8-J11 junos:23.4R2-S8-J5 junos:24.2R2-S3-J14 junos:24.2R2-S6 junos:24.4R2-S4-J5 junos:25.2R2-S2 junos:25.4R2 junos:25.4R2-S1 junos:26.2R2 junos:26.3R1 junos:26.4R1
1967994
Major
Subscribers cannot obtain IP addresses nor renew DHCP leases when configuring persistent-storage for DHCP
Product-Group=junos
On Junos OS platforms, with Dynamic Host Configuration Protocol (DHCP) configured and including persistent storage, option-82, interface id and remote id enabled, there is a buffer overwrite triggered by a large size on session attributes when they are written in the persistent file which can cause multiple jdhcpd core dumps and jdhcp process crashes resulting in existing and new subscribers unable to obtain IP addresses . When the issue is observed it can lead to service disruption.

Resolved In: junos:23.2R2-S8 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1955888
Major
IPsec packet loss during IPsec phase 2 rekey on SRX rekey responder under heavy load
Product-Group=junos
On SRX Series platforms running with iked (Internet Key Exchange Daemon), SRX device acting as the IKEv2(Internet Key Exchange version 2) phase2 IPsec (Internet Protocol Security) rekey responder temporarily drop inbound IPsec packets when the system is under heavy load. Traffic resumes automatically after the newly negotiated Security Association (SA) is installed in the Packet Forwarding Engine (PFE).

Resolved In: junos:24.4R2-S2-J1 junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1964908
Major
IPsec tunnel goes down/up on a non-Juniper peer device every time at phase1 rekey
Product-Group=junos
On SRX1500, SRX1600, SRX2300, SRX4100, SRX4200, SRX4300, SRX4600,SRX4700, SRX5400, SRX5800, vSRX and MX platforms running iked/ikemd for IKEv1 IPsec gateway negotiations, IPsec traffic can be interrupted for approximately 6 seconds during Phase 1 rekey when interoperating with certain non-Juniper peers. The peer can interpret the deletion of the old Phase 1 security association as a request to remove the associated Phase 2 security associations, causing temporary traffic loss until the Phase 2 associations are re-established.

Resolved In: junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: Platform infra to support jvision
1940874
Minor
The /interfaces/interface/state/enabled/ does not export all interfaces under a single wrap
Product-Group=junos
On MX platforms with MPC1-11, LC2301/LC9600, LC4800 and MX304, when subscribed to the OpenConfig gNMI sensor /interfaces/interface/state/enabled/ with a 60-second sample interval, an incomplete data delivery at collector is observed when the device is deployed with 2 or more line cards.

Resolved In: evo:25.4R2-EVO evo:26.3R1-EVO junos:23.2R2-S8 junos:23.4R2-S3-J32 junos:24.2R2-S6 junos:24.4R2-S2-J17 junos:25.4R2 junos:25.4R2-S1 junos:25.4R2-S2 junos:26.3R1
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1958503
Minor
Traffic flooding and traffic drops with egress link protection enabled in EVPN-MPLS deployments
Product-Group=junos
On MX-series with MPC10 and MPC11 cards, MX304, PTX10008, PTX10016, PTX10004, PTX10003-160C, PTX10003-80C, and PTX10001-36MR platforms running Junos or Junos Evolved, Ethernet Virtual Private Network (EVPN) over Multi-protocol Label Switching (MPLS) deployments with Egress Link Protection (ELP) enabled experience traffic flooding because affected Media Access Control (MAC) addresses are not programmed into the Packet Forwarding Engine (PFE) after an ELP update.As a result, traffic destined for the affected MAC addresses is flooded instead of being forwarded to the correct destination which result in unnecessary network traffic and degraded forwarding behavior.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1964600
Minor
Configuring interface-mac-ip-limit under a routing instance VLAN causes commit validation to fail unless an explicit instance-level mac-ip-table-size is configured
Product-Group=junos
On all Junos Evolved platforms, configuration using interface-mac-ip-limit under EVPN (Ethernet Virtual Private Network) MAC (Media Access Control) VRF (Virtual Routing and Forwarding) VLANs (Virtual LAN) or switch-options without an explicit mac-ip-table-size are facing commit failures. However, there is no service impact due to this issue.

Resolved In: evo:25.2R2-S2-EVO evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1968275
Minor
[mx10008] ND probes for static MAC-IP EVPN entries are sourced from wrongly built EUI-64 link-local addresses
Product-Group=junos
The EUI-64 link-local address construction in l2alm_irb_local_addr() was missing the mandatory 0xFF, 0xFE byte insertion at positions 3-4 of the interface identifier. After bzero, bytes 3-4 remained 0x00, 0x00, causing NS probes for static MAC-IP entries to use a malformed source address. For example, in problem state, IPv6 link-local address is fe80::2293:3900:eb:f44a, derived as follows: IRB MAC: 20:93:39:eb:f4:4a Buggy - before fix - bytes 3-4 left as 00:00 after bzero: [20 | 0x02] 93 39 : 00 00 : eb f4 4a [00 00 is inserted between 2 halves of MAC address] -> fe80::2293:3900:eb:f44a [above result is prefixed with fe80::] After fix: [20 | 0x02] 93 39 : ff fe : eb f4 4a [FF FE is inserted between 2 halves of MAC address] -> fe80::2293:39ff:feeb:f44a [above result is prefixed with fe80::]

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.4R1-EVO evo:27.1R1-EVO junos:25.4R2 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1881511
Minor
MX platforms with MPC10 and PPPoE subscribers can experience egress traffic black holing after WAN link flap events
Product-Group=junos
On MX Series routers equipped with MPC10 cards and high scale PPPoE (Point to Point Protocol over Ethernet) subscriber deployments, a WAN (Wide Area Networks) interface link flap under active traffic conditions can cause corruption of internal scheduler credits. When this occurs, Packet Forwarding Engine queue flush operations can fail and subscriber egress traffic can become permanently black holed. Symptoms include "cannot Free L1/L2/L3/L4 node" messages, and queue flush failures. The issue is more likely to occur on interfaces carrying significant subscriber traffic and repeated link flap events.

Resolved In: evo:26.4R1-EVO junos:23.4R2-S1-J12 junos:23.4R2-S3-J35 junos:23.4R2-S7-J27 junos:26.4R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1944799
Major
ARP is not resolved on directly connected interface of Junos QFX5K platform enabled with Spanning Tree protocol
Product-Group=junos
On the Junos QFX5K platform, when any Spanning Tree Protocol (STP) variant, such as STP, RSTP, MSTP, or VSTP, is enabled, ARP is not resolved on QFX5K interfaces if the interface is configured with flexible VLAN tagging and Enterprise (EP) or Service Provider (SP) style configuration. As a result, IP traffic is lost over the affected interfaces.

Resolved In: junos:23.2R2-S8 junos:24.2R2-S6 junos:25.4R2 junos:26.3R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1962277
Major
AE interface remains down after enabling 'lag-heap-optimization' with LACP and 'native-vlan-id' configured
Product-Group=junos
On Junos QFX5K and EX Series platforms, an Aggregated Ethernet (AE) interface configured with Link Aggregation Control Protocol (LACP) and a 'native-vlan-id' remains operationally down after enabling 'lag-heap-optimization'. As a result, LACP does not establish and traffic forwarding over the aggregate link is impacted.

Resolved In: junos:25.4R2 junos:25.4R2-S1 junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1934076
Minor
The dcpfe process crash observed during a system reboot or PFE restart when software-based linkscan is configured
Product-Group=junos
On QFX5120-48Y, QFX5120-48T, QFX5120-32C and EX4650 platforms, a system reboot or PFE restart after configuring software-based linkscan causes the dcpfe process to crash. As a result, traffic forwarding on interfaces associated with the affected FPC will be temporarily impacted during the recovery period.

Resolved In: junos:25.2R2-S2 junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1966878
Major
The rpd process might restart during normal routing events due to a rare timing condition
Product-Group=junos
During normal routing events, the rpd process might restart due to a rare timing condition, temporarily impacting new route learning and route changes while transit traffic using already programmed routes may continue forwarding.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1967283
Minor
The rpd process consumes high CPU when an aggregate route temporarily loses all active contributors with OC-TLV support enabled
Product-Group=junos
On Junos OS and Junos OS Evolved platforms supporting OC-TLV, the rpd process may experience sustained high CPU utilization when OC-TLV support is enabled, and an aggregate route temporarily loses all active contributing routes. A minor CPU hog alarm for the rpd process will be reported. This high CPU utilization subsequently compromises other system processes and protocols, leading to an impact on the traffic.

Resolved In: evo:26.2R2-EVO evo:26.4R1-EVO junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1922237
Major
In Class-Based Forwarding with ECMP scenario traffic gets dropped due to incorrect next-hop handling process in PFE programming
Product-Group=junos
On all Junos and Junos Evolved platforms where CBF (Class-Based Forwarding) and ECMP (Equal-Cost Multi Path) is configured and in non - MPLS (Multi-Protocol Label Switching) based IP traffic forwarding scenario, packet loss can be observed due to next-hop process handling in PFE (Packet Forwarding Engine) programming for indexed next-hop installation by CBF.

Resolved In: evo:26.2R1-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1853895
Major
Service route is hidden over BGP LU multipath upon neighbor route withdrawn
Product-Group=junos
On all Junos and Junos Evolved platforms, the following condition is a prerequisite - Service route resolving over BGP LU (Border Gateway Protocol Labeled Unicast) multipath route with multipath resolve policy enabled. The issue occurs when one BGP LU neighbour withdraws its route. This withdrawal causes the top-level service route to temporarily become hidden, and then it reappears after re-resolving over the remaining BGP LU multipath routes. However, after this recovery, the BGP LU resolution changes from multipath to single path.This behavior results in a brief traffic loss during the interval when the service route is hidden and then restored.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.2R3-S6-J3 junos:22.4X4 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1967461
Major
RSVP detour LSP does not follow configured FRR admin-group exclusion constraints
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching), RSVP (Resource Reservation Protocol), dynamic tunnels, and an LSP (Label-Switched Path) template with FRR (Fast Reroute) admin-group exclusion constraints are configured, the detour LSP does not follow the configured exclusions after the primary LSP becomes unavailable. The detour LSP uses an unintended path, while traffic and services remain unaffected.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.3R1-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.3R1 junos:26.4R1
1969952
Major
RSVP LSP traffic loss during primary path recovery with setup-protection
Product-Group=junos
On Junos and Junos OS Evolved platforms, Resource Reservation Protocol (RSVP) Label-Switched Paths (LSPs) using facility backup(setup-protection) experience a temporary traffic disruption when the primary path recovers and local reversion is enabled. The issue occurs when the LSP is signaled through a non-Junos ingress router and the administrative group constraints of the bypass LSP change. The affected LSP is resignaled during primary path recovery and traffic is disrupted for a few seconds before the LSP recovers automatically.

Resolved In: evo:25.4R2-EVO evo:26.2R2-EVO evo:26.4R1-EVO junos:25.4R2 junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
PR NumberSynopsisCategory: Issues related to control plane security
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1957635
Major
SNMP trap is sent with incorrect source IP address
Product-Group=junos
SNMP traps are sent with fxp0 or uplink port IP even though trap source is configured with lo0.0 IP. The issue occurs after deactivate+activate of the trap-source/trap-target addresses.

Resolved In: evo:27.1R1-EVO
PR NumberSynopsisCategory: Segment routing traffic Engineering
1970382
Major
rpd crash during SR-TE path computation with SID-stack compression on Junos OS and Junos OS Evolved platforms
Product-Group=junos
On Junos OS and Junos OS Evolved platforms that support Segment Routing Traffic Engineering (SR-TE), the routing protocol process (rpd) can crash when an SR-TE label-switched path (LSP) uses Segment Identifier (SID)-stack compression with on-box path computation after a previous unsuccessful path-computation or resolution attempt. The issue applies to both statically configured and dynamically created SR-TE LSPs. After rpd restarts, the SR-TE and path-computation states are rebuilt automatically. Transient traffic loss can occur during forwarding next-hop restoration, depending on network scale and the number of Packet Forwarding Engines (PFEs) requiring updates

Resolved In: evo:26.2R2-EVO evo:26.4R1-EVO evo:27.1R1-EVO junos:26.2R2 junos:26.4R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. Please refer to https://supportportal.juniper.net/JSA100096 [juniper.net] for more information.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S5-EVO evo:23.4X100-D31-EVO evo:24.2R2-S1-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S12 junos:20.2X42 junos:20.3X75-D36 junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:21.2R3-S10 junos:21.2X32-D30 junos:21.2X33 junos:21.4R3-S11 junos:21.4R3-S11-X1 junos:21.4X12 junos:21.4X12-X1 junos:22.2R3-S7 junos:22.3R3-S5 junos:22.3X60 junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:22.4X50 junos:23.2R2-S3-C21 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4X15 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R2-S1 junos:24.2X1 junos:24.4R1-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1 junos:25.4R1-S2 junos:26.4DCB
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1861779
Major
Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash (CVE-2026-57025)
Product-Group=junos
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA110085 [juniper.net] for more information.

Resolved In: evo:22.4R3-S9-EVO evo:23.2R2-S7-EVO evo:23.4R2-S8-EVO evo:24.2R2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:24.4R2-S3-J1-EVO evo:25.2R1-EVO evo:25.4R2-EVO junos:20.2X42 junos:20.3X75-D443 junos:21.2R3-S11 junos:22.2R3-S8 junos:22.4R3-S10 junos:22.4R3-S7-J1 junos:22.4R3-S9 junos:23.2R2-S7 junos:23.4R2-S7 junos:23.4R2-S8 junos:23.4X12 junos:23.4X13 junos:23.4X14 junos:23.4X15 junos:23.4X30 junos:24.2R2 junos:24.2X1 junos:24.4R1-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:26.3R1 junos:26.4DCB
PR NumberSynopsisCategory: Issues related to YANG Data Models
1826630
Major
Annotations are improperly structured in NETCONF after enabling YANG compliance
Product-Group=junos
When the YANG(Yet Another Next Generation)-compliant knob is configured, annotations containing non-alphanumeric characters are written as-is, instead of being escaped into their corresponding formats.

Resolved In: evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-C1-EVO evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S4 junos:23.4X1 junos:23.4X15 junos:23.4X30-D20 junos:23.4X30-D30 junos:24.2R1-S2 junos:24.2R2 junos:24.2X1 junos:24.4R1 junos:25.1R1

 


 

Modification History

First publication 2026-09-09