Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX
Alert Description
Junos Software Service Release version 18.4R2-S10 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 18.4R2-S10 is now available.
18.4R2-S10 - List of Fixed issues
PR Number
Synopsis
Category: EX2300/3400 PFE
1619970
Junos OS: EX2300 Series, EX2300-MP Series, EX3400 Series: A slow memory leak due to processing of specific IPv6 packets (CVE-2022-22180)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/
JSA11286
[juniper.net]
for more information.
PR Number
Synopsis
Category: QFX PFE CoS
1575049
Not able to configure policer with bandwidth-limit greater than 50g
Product-Group=junosvae
On AS7816/QFX5110/5120/5200/5210 platforms, it could not configure a policer with a "bandwidth-limit" greater than 50g for 100g port, even though it is supported in hardware. The traffic exceeding 50g cannot be policed on a 100g port.
1579178
The dcpfe process might crash while loading any scale configuration
Product-Group=junos
On QFX-series switch, while loading any scale configuration if the CPU utilization is increased close to 100%, in a rare instance dcpfe process might crash and lead to traffic impact.
PR Number
Synopsis
Category: "agentd" software daemon
1600412
The gNMI Telemetry might stop working after RE switchover
Product-Group=junos
In a dual RE (Routing Engine) system with GRES (Graceful Routing Engine Switchover) NSR (Nonstop Active Routing) enabled telemetry might stop working after RE switchover.
PR Number
Synopsis
Category: BBE state synchronization issues
1580528
Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message (CVE-2022-22160)
Product-Group=junos
An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11268
[juniper.net]
for more information.
PR Number
Synopsis
Category: BBE Remote Access Server
1625858
Radius CoA (Change of Authorization) NAK may not be sent with the configured Source Address in a virtual-router environment
Product-Group=junos
On all Junos, when running a radius server in multiple routing instances, the CoA NAK messages uses the interface address instead of the configured source address for non-existent sessions. This issue happens when the Radius server is configured in different virtual routers with different settings.
PR Number
Synopsis
Category: Device Configuration Daemon
1569399
,Traffic might be interrupted while adding xe-/ge- interfaces as member of aggregated Ethernet interface bundle
Product-Group=junos
On all Junos platforms, if a xe- or ge- interface has the "set interfaces disable" configuration, the interface is added as a member of an aggregated Ethernet interface bundle, and "delete interfaces disable" command is committed, then in some rare scenario it might result in vmcore and cause the system to reboot. This leads to traffic impact. After vmcore, system boots up and comes to normal state.
PR Number
Synopsis
Category: Covers Application classification workflows apart from custo
1599053
Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy (CVE-2022-22167)
Product-Group=junos
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on the device. While JDPI correctly classifies out-of-state asymmetric TCP flows as the dynamic-application UNKNOWN, this classification is not provided to the policy module properly and hence traffic continues to use the pre-id-default-policy, which is more permissive, causing the firewall to allow traffic to be forwarded that should have been denied. Refer to https://kb.juniper.net/
JSA11265
[juniper.net]
for more information.
PR Number
Synopsis
Category: EX driver issues
1600291
The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR Number
Synopsis
Category: Kernel software for AE/AS/Container
1610540
QFX5200 mib OID ifOutDiscards misbehaving and returning value 0 which is not expected
Product-Group=junos
ifOutDiscards(Output Error Drops) returning value 0 for AE interface intermittently. Issue is observed when we receive both SYNC and ASYNC request at the same time for AE member link interface. SYNC request from mib2d(since ASYNC is not supported by QFX for AE) and ASYNC request is from sflowd. Before post-processing completes for the pending SYNC request if ASYNC request is created, ASYNC q_counters is taken for stats calculation and it results in 0.
PR Number
Synopsis
Category: ISIS routing protocol
1482983
The output of the show isis interface detail command might be incorrect if wide-metrics-only is enabled for IS-IS and the ASCII representation of the metric in decimal is more than 6 characters long.
Product-Group=junos
If 'wide-metrics-only' is enabled for any IS-IS level and a metric configured on the IS-IS enabled interface for that level has ASCII representation in decimal more than 6 characters long, this interface's metric for that level will be merged with 'priority' field value in the output of 'show isis interface detail'.
PR Number
Synopsis
Category: jdhcpd daemon
1488771
Layer 2 Ethernet Services For MX204 platform, the Vendor-ID is set as MX10001 in factory-default configuration and DHCP client. messages
Product-Group=junos
MX204 platform presents itself as MX10001 in Factory default config and DHCP client messages.
1594371
Junos OS: jdhcpd crashes upon receipt of a specific DHCPv6 packet (CVE-2022-22163)
Product-Group=junos
An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11271
[juniper.net]
for more information.
1618977
Junos OS: The jdhcpd crashes upon receiving a specific DHCP packet (CVE-2022-22179)
Product-Group=junos
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of the jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11285
[juniper.net]
for more information.
PR Number
Synopsis
Category: Security platform jweb support
1594516
Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root. (CVE-2021-31372)
Product-Group=junos
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. Refer to https://kb.juniper.net/
JSA11237
[juniper.net]
for more information.
PR Number
Synopsis
Category: Layer 2 Control Module
1602588
Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS (CVE-2022-22172)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11278
[juniper.net]
for more information.
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1570148
A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
PR Number
Synopsis
Category: TCP/UDP transport layer
1472367
Junos OS: FreeBSD-EN-18:11.listen: TCP during bind, listen or connect and UDP during bind may experience Denial of Service for IPv6 based sockets. (CVE-2018-6925)
Product-Group=junos
In Juniper Networks Junos OS there are various cases in the IPv6 socket code where the protocol control block's state flags are modified during a syscall, but are not restored if the operation fails. Please refer to https://kb.juniper.net/
JSA11178
[juniper.net]
for more information.
PR Number
Synopsis
Category: Kernel Tunnel Interface Infrastructure
1609630
BFD over GRE tunnel interface stuck in "init" state with GRES enabled
Product-Group=junos
On all JUNOS platforms, when disabling the physical interface where GRE tunnels is established and performing a GRES (Graceful Routing Engine Switchover). After GRES, enabling the physical interface will cause BFD to become stuck in init state.
PR Number
Synopsis
Category: Periodic Packet Management Daemon
1599751
rpd core might be observed due to memory corruption
Product-Group=junos
On all Junos and Evo devices, when connection between Internal Junos Modules (Routing Module & Periodic Packet Manager Module) resets, data structure representing that connection is not completely reset/freed. Due to this next time, when the connection is re-established, there is a possibility of re-using the old/stale data structure and this could lead to memory corruption and thereby rpd core.
PR Number
Synopsis
Category: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1479930
The lasers may keep lasting after the device reboots
Product-Group=junos
On the QFX5210-64C platforms, the laser on the optic "QSFP+-4X10G-LR" may still keep lasting after rebooting even the port is disabled via CLI command before restarting.
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1518142
CPU packet Queues inconsistencies is seen
Product-Group=junos
On QFX5000/AS7816 Series platforms, if the L3 interfaces with L2/L3 on the same IFD has VxLAN configuration, the ARP/ICMPv6 packets are put into the different Queues.
PR Number
Synopsis
Category: QFX5100 Platform optics
1561181
The tunable optics SFP+-10G-T-DWDM-ZR does not work.
Product-Group=junos
On EX4600/EX4650/QFX5110 devices with tunable optics SFP+-10G-T-DWDM-ZR used, the configured wavelength value does not take effect when connecting two EX/QFX across a mux (multiplexer) using tunable optics SFP+-10G-T-DWDM-ZR.
PR Number
Synopsis
Category: QFX5100 Virtual Chassis
1619997
Disabled VCP (Virtual chassis port) will be UP after the optic on it is reseated
Product-Group=junos
On all EX and QFX platforms, disabled VCP(Virtual Chassis Port) using the command "request virtual-chassis vc-port set interface vcp-xx/xx/xx disable member XX" will be up after the optic on it is reseated. It should keep disabling VC on the port. After it is UP and then a Master switchover is performed, the port will be disabled.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1635009
Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos and EVO platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to
KB37775
[juniper.net]
for more details.
PR Number
Synopsis
Category: MX10002 Platform SW - Platform s/w defects
1426120
On MX204 or MX10003, MPC reboot or Routing Engine mastership switchover might occur.
Product-Group=junos
On MX204 and MX10003 platforms, if there's high rate of fragmented traffic received on the em3 interface, em3 watchdog timeout might occur. It could cause MPC reboot or RE mastership switchover.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1559786
It fails if the xml output from command "request vmhost mode test | display xml rpc" is picked and used in netconf
Product-Group=junos
On vmhost platforms, if the xml output from command "request vmhost mode test | display xml rpc" is picked and used in netconf, it will fail set vmhost mode custom test layer-3-infrastructure cpu count MIN set vmhost mode custom test layer-3-infrastructure memory size MIN set vmhost mode custom test nfv-back-plane cpu count MIN set vmhost mode custom test nfv-back-plane memory size MIN set vmhost mode custom test vnf cpu count MIN
PR Number
Synopsis
Category: VSRX platform software
1603199
Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks. (CVE-2021-31386)
Product-Group=junos
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. Refer to https://kb.juniper.net/
JSA11254
[juniper.net]
for more information.
18.4R2-S10 - List of Known issues
PR Number
Synopsis
Category: Border Gateway Protocol
1585265
The rpd might crash in BGP multipath scenario if the single-hop EBGP peer goes down
Product-Group=junos
On all platforms running Junos OS or Junos OS Evolved during BGP multipath scenario, if an interface for a single-hop EBGP peer goes down, the rpd might crash on the backup Routing Engine due to a rare timing issue. When this issue occurs, redundancy might be impacted.
1620463
The rpd may crash and restart when NSR is enabled
Product-Group=junos
On all Junos with NSR (nonstop routing) enabled the rpd crash and restart may occur when RPKI (Resource Public Key Infrastructure) records are being replicated between the primary and backup RE (Routing Engine) and some of the records are withdrawn over the RPKI session.
PR Number
Synopsis
Category: MPC5/6E PFE ISSU software
1542882
The JNH memory leak could be observed on MPCs or MICs
Product-Group=junos
On all Junos platforms with Trio-based line cards, a Junos next-hop (JNH) memory leak might be observed. This issue is due to the counters applications under firewall filters taking the additional memory space from the shared JNH pool. In an extreme scenario, this could also lead to FPC crash.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1591264
Traffic loss might be seen under EVPN scenario when MAC-IP moves from one CE interface to another
Product-Group=junos
On all Junos/Junos Evolved platforms with EVPN scenario, the number of MAC-IP binding counters may reach the limit when MAC-IP is moved between interfaces. Since MAC-IP counters are not decremented when entry is deleted due to this defect, repeated moves will result in a limit (default value is 1024) that will be reached even though there are fewer entries. Meanwhile, traffic loss could be seen.
1609322
Few ARP/ND/MAC entries for Vlans are missing with MAC-VRF configuration
Product-Group=junos
In all Junos and Evo platforms, in EVPN-VXLAN scenario, with "proxy-macip-advertisement" knob configured, few ARP/ND/MAC entries may get missing.
PR Number
Synopsis
Category: EX4400 platform
1613702
FPC might crash after device restart in EVPN-VXLAN scenario
Product-Group=junos
On EX or QFX platforms with Ethernet VPN (EVPN) and Virtual Extensible LAN (VxLAN) enabled, FPC(Flexible PIC Concentrator) might crash after the device is restarted. Traffic loss is observed until the FPC is restarted and services are restored.
PR Number
Synopsis
Category: Express PFE FW Features
1432116
The FPC might crash when a firewall filter is modified.
Product-Group=junos
In QFX10K/PTX series platforms, if a firewall filter with multiple match conditions is configured on interfaces which are Up and the firewall filter is modified (either a new action is added or the condition is added/removed etc.), the FPC might crash and restart. It might affect the service/traffic.
PR Number
Synopsis
Category: to track replication related interface bugs
1606779
When MTU is configured on an interface a rare ifstate timing issue could occur at a later point resulting in ksyncd process crash on backup RE
Product-Group=junos
On all Junos platforms with MTU and xSTP configured on an interface, a rare ifstate timing issue could occur at a later point resulting in ksyncd process crash on backup RE. When ksyncd crashes on backup RE, a live kernel core is also dumped on both the REs.
PR Number
Synopsis
Category: Interface Information Display
1574035
if-media-type missing from interface XML output on MX Series routers
Product-Group=junos
Extensible Markup Language (XML) is a standard for representing and communicating information. The Junos OSCLI and the Junos OS infrastructure communicate using XML. The operational command "show interface | display xml" displays the interface parameters in XML format. This output displays the media type if-media-type along with other parameters for the platforms like QFX Series switches. However, for MX Series routers, if-media-type parameter is not displayed in the output from day one. With the fix of this PR, the XML output for MX Series routers displays the if-media-type parameter for 1Gb interfaces only.
PR Number
Synopsis
Category: QFX L2 PFE
1560086
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
Product-Group=junos
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
1595029
After loaded 4093 irb configs, found that few vlans stuck in destroyed state
Product-Group=junosvae
Qfx5100 overall and FPC CPU utilisation may be high incase of 4093 Irb with full port density(32/24). It may differ by max 4-5% compare to same system having very less port density (1 or 2 ports). Some of FPC threads takes more CPU in such scenario (Ethernet/QSfp) etc.
PR Number
Synopsis
Category: QFX L3 data-plane/forwarding
1489374
Packets drop might be seen when multicast MAC with static ARP is configured on one IRB interface
Product-Group=junos
On EX2300/EX3400/EX4300/EX4600/QFX5K platforms, if multicast MAC with static ARP is configured on one IRB interface, the packets which destination is the IP address of static ARP might not get out of the interface. So traffic drop might be seen.
PR Number
Synopsis
Category: QFX5100 Platform optics
1606003
QFX5100 : Generate an optical power after detached and attached QSFP on disabled interface.
Product-Group=junos
On QFX5100, optical power is seen after detached and attached QSFP on disable interface.
Modification History
First publication 2022-01-14
18.4R2-S10: Software Release Notification for JUNOS Software Version 18.4R2-S10