Junos Software service Release version 17.1R2-S10 is now available.
The MRU of aggregated Ethernet interface might reset to default value.
When configuring an aggregated Ethernet interface and after commit, some harmless log messages might appear. But with a certain configuration such as VRRP, the child links of the aggregated Ethernet interface get reset to the default MRU and cause traffic loss.
Some error messages might be seen when flapping physical interface on MPC 7/8/9E cards.
Continuous error messages may be seen when physical interface quickly flaps on MPC7/8/9E cards. This might cause egress stream flush failure.
The MAC_STUCK might be seen on MS-MPC or MS-MIC
On MS-MPC/MS-MIC in ALG scenario, MAC_STUCK might be seen and traffic may be lost.
JSA10905 [juniper.net] 2019-01 Security Bulletin: Junos OS: EX and QFX series: Stateless firewall filter ignores IPv6 extension headers (CVE-2019-0005). See https://kb.juniper.net/JSA10905 [juniper.net] for details.
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet filtering is unaffected by this vulnerability. See https://kb.juniper.net/JSA10905 [juniper.net] for details.
JSA10900 [juniper.net] 2019-01 Security Bulletin: Junos OS: MX Series: uncontrolled recursion and crash in Broadband Edge subscriber management daemon (bbe-smgd) (CVE-2019-0001)
JSA10900 [juniper.net] 2019-01 Security Bulletin: Junos OS: MX Series: uncontrolled recursion and crash in Broadband Edge subscriber management daemon (bbe-smgd) (CVE-2019-0001). See https://kb.juniper.net/JSA10900 [juniper.net] for details.
Traffic might be dropped on third-generation FPCs on PTX.
On PTX with third-generation FPCs, if optics not certified by Juniper Networks (NON-JNPR) is used and there is a specific traffic pattern with congestion, traffic might be dropped.
OpenSSL Security Advisories [16 Apr 2018] and [12 June 2018]
The ?OpenSSL project has published security advisories for vulnerabilities resolved in the OpenSSL library on April 16, 2018, and June 12, 2018. See https://kb.juniper.net/JSA10919 [juniper.net] for details.
First publication 2019-01-11