Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX

Alert Description

Junos Software Service Release version 18.4R2-S10 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 18.4R2-S10 is now available.

18.4R2-S10 - List of Fixed issues

PR NumberSynopsisCategory: EX2300/3400 PFE
1619970 Junos OS: EX2300 Series, EX2300-MP Series, EX3400 Series: A slow memory leak due to processing of specific IPv6 packets (CVE-2022-22180)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA11286 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX PFE CoS
1575049 Not able to configure policer with bandwidth-limit greater than 50g
Product-Group=junosvae
On AS7816/QFX5110/5120/5200/5210 platforms, it could not configure a policer with a "bandwidth-limit" greater than 50g for 100g port, even though it is supported in hardware. The traffic exceeding 50g cannot be policed on a 100g port.
1579178 The dcpfe process might crash while loading any scale configuration
Product-Group=junos
On QFX-series switch, while loading any scale configuration if the CPU utilization is increased close to 100%, in a rare instance dcpfe process might crash and lead to traffic impact.
PR NumberSynopsisCategory: "agentd" software daemon
1600412 The gNMI Telemetry might stop working after RE switchover
Product-Group=junos
In a dual RE (Routing Engine) system with GRES (Graceful Routing Engine Switchover) NSR (Nonstop Active Routing) enabled telemetry might stop working after RE switchover.
PR NumberSynopsisCategory: BBE state synchronization issues
1580528 Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message (CVE-2022-22160)
Product-Group=junos
An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11268 [juniper.net] for more information.
PR NumberSynopsisCategory: BBE Remote Access Server
1625858 Radius CoA (Change of Authorization) NAK may not be sent with the configured Source Address in a virtual-router environment
Product-Group=junos
On all Junos, when running a radius server in multiple routing instances, the CoA NAK messages uses the interface address instead of the configured source address for non-existent sessions. This issue happens when the Radius server is configured in different virtual routers with different settings.
PR NumberSynopsisCategory: Device Configuration Daemon
1569399 ,Traffic might be interrupted while adding xe-/ge- interfaces as member of aggregated Ethernet interface bundle
Product-Group=junos
On all Junos platforms, if a xe- or ge- interface has the "set interfaces disable" configuration, the interface is added as a member of an aggregated Ethernet interface bundle, and "delete interfaces disable" command is committed, then in some rare scenario it might result in vmcore and cause the system to reboot. This leads to traffic impact. After vmcore, system boots up and comes to normal state.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1599053 Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy (CVE-2022-22167)
Product-Group=junos
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on the device. While JDPI correctly classifies out-of-state asymmetric TCP flows as the dynamic-application UNKNOWN, this classification is not provided to the policy module properly and hence traffic continues to use the pre-id-default-policy, which is more permissive, causing the firewall to allow traffic to be forwarded that should have been denied. Refer to https://kb.juniper.net/JSA11265 [juniper.net] for more information.
PR NumberSynopsisCategory: EX driver issues
1600291 The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1610540 QFX5200 mib OID ifOutDiscards misbehaving and returning value 0 which is not expected 
Product-Group=junos
ifOutDiscards(Output Error Drops) returning value 0 for AE interface intermittently. Issue is observed when we receive both SYNC and ASYNC request at the same time for AE member link interface. SYNC request from mib2d(since ASYNC is not supported by QFX for AE) and ASYNC request is from sflowd. Before post-processing completes for the pending SYNC request if ASYNC request is created, ASYNC q_counters is taken for stats calculation and it results in 0.
PR NumberSynopsisCategory: ISIS routing protocol
1482983 The output of the show isis interface detail command might be incorrect if wide-metrics-only is enabled for IS-IS and the ASCII representation of the metric in decimal is more than 6 characters long.
Product-Group=junos
If 'wide-metrics-only' is enabled for any IS-IS level and a metric configured on the IS-IS enabled interface for that level has ASCII representation in decimal more than 6 characters long, this interface's metric for that level will be merged with 'priority' field value in the output of 'show isis interface detail'.
PR NumberSynopsisCategory: jdhcpd daemon
1488771 Layer 2 Ethernet Services For MX204 platform, the Vendor-ID is set as MX10001 in factory-default configuration and DHCP client. messages
Product-Group=junos
MX204 platform presents itself as MX10001 in Factory default config and DHCP client messages.
1594371 Junos OS: jdhcpd crashes upon receipt of a specific DHCPv6 packet (CVE-2022-22163)
Product-Group=junos
An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11271 [juniper.net] for more information.
1618977 Junos OS: The jdhcpd crashes upon receiving a specific DHCP packet (CVE-2022-22179)
Product-Group=junos
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of the jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11285 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1594516 Junos OS: J-Web allows a locally authenticated attacker to escalate their privileges to root. (CVE-2021-31372)
Product-Group=junos
An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. Refer to https://kb.juniper.net/JSA11237 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer 2 Control Module
1602588 Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS (CVE-2022-22172)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11278 [juniper.net] for more information.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1570148 A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
PR NumberSynopsisCategory: TCP/UDP transport layer
1472367 Junos OS: FreeBSD-EN-18:11.listen: TCP during bind, listen or connect and UDP during bind may experience Denial of Service for IPv6 based sockets. (CVE-2018-6925)
Product-Group=junos
In Juniper Networks Junos OS there are various cases in the IPv6 socket code where the protocol control block's state flags are modified during a syscall, but are not restored if the operation fails. Please refer to https://kb.juniper.net/JSA11178 [juniper.net] for more information.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1609630 BFD over GRE tunnel interface stuck in "init" state with GRES enabled
Product-Group=junos
On all JUNOS platforms, when disabling the physical interface where GRE tunnels is established and performing a GRES (Graceful Routing Engine Switchover). After GRES, enabling the physical interface will cause BFD to become stuck in init state.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1599751 rpd core might be observed due to memory corruption
Product-Group=junos
On all Junos and Evo devices, when connection between Internal Junos Modules (Routing Module & Periodic Packet Manager Module) resets, data structure representing that connection is not completely reset/freed. Due to this next time, when the connection is re-established, there is a possibility of re-using the old/stale data structure and this could lead to memory corruption and thereby rpd core.
PR NumberSynopsisCategory: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1479930 The lasers may keep lasting after the device reboots
Product-Group=junos
On the QFX5210-64C platforms, the laser on the optic "QSFP+-4X10G-LR" may still keep lasting after rebooting even the port is disabled via CLI command before restarting.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1518142 CPU packet Queues inconsistencies is seen
Product-Group=junos
On QFX5000/AS7816 Series platforms, if the L3 interfaces with L2/L3 on the same IFD has VxLAN configuration, the ARP/ICMPv6 packets are put into the different Queues.
PR NumberSynopsisCategory: QFX5100 Platform optics
1561181 The tunable optics SFP+-10G-T-DWDM-ZR does not work.
Product-Group=junos
On EX4600/EX4650/QFX5110 devices with tunable optics SFP+-10G-T-DWDM-ZR used, the configured wavelength value does not take effect when connecting two EX/QFX across a mux (multiplexer) using tunable optics SFP+-10G-T-DWDM-ZR.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1619997 Disabled VCP (Virtual chassis port) will be UP after the optic on it is reseated
Product-Group=junos
On all EX and QFX platforms, disabled VCP(Virtual Chassis Port) using the command "request virtual-chassis vc-port set interface vcp-xx/xx/xx disable member XX" will be up after the optic on it is reseated. It should keep disabling VC on the port. After it is UP and then a Master switchover is performed, the port will be disabled.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1635009 Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos and EVO platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to KB37775 [juniper.net] for more details.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1426120 On MX204 or MX10003, MPC reboot or Routing Engine mastership switchover might occur.
Product-Group=junos
On MX204 and MX10003 platforms, if there's high rate of fragmented traffic received on the em3 interface, em3 watchdog timeout might occur. It could cause MPC reboot or RE mastership switchover.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1559786 It fails if the xml output from command "request vmhost mode test | display xml rpc" is picked and used in netconf
Product-Group=junos
On vmhost platforms, if the xml output from command "request vmhost mode test | display xml rpc" is picked and used in netconf, it will fail set vmhost mode custom test layer-3-infrastructure cpu count MIN set vmhost mode custom test layer-3-infrastructure memory size MIN set vmhost mode custom test nfv-back-plane cpu count MIN set vmhost mode custom test nfv-back-plane memory size MIN set vmhost mode custom test vnf cpu count MIN
PR NumberSynopsisCategory: VSRX platform software
1603199 Junos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks. (CVE-2021-31386)
Product-Group=junos
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. Refer to https://kb.juniper.net/JSA11254 [juniper.net] for more information.

 


18.4R2-S10 - List of Known issues

PR NumberSynopsisCategory: Border Gateway Protocol
1585265 The rpd might crash in BGP multipath scenario if the single-hop EBGP peer goes down
Product-Group=junos
On all platforms running Junos OS or Junos OS Evolved during BGP multipath scenario, if an interface for a single-hop EBGP peer goes down, the rpd might crash on the backup Routing Engine due to a rare timing issue. When this issue occurs, redundancy might be impacted.
1620463 The rpd may crash and restart when NSR is enabled
Product-Group=junos
On all Junos with NSR (nonstop routing) enabled the rpd crash and restart may occur when RPKI (Resource Public Key Infrastructure) records are being replicated between the primary and backup RE (Routing Engine) and some of the records are withdrawn over the RPKI session.
PR NumberSynopsisCategory: MPC5/6E PFE ISSU software
1542882 The JNH memory leak could be observed on MPCs or MICs
Product-Group=junos
On all Junos platforms with Trio-based line cards, a Junos next-hop (JNH) memory leak might be observed. This issue is due to the counters applications under firewall filters taking the additional memory space from the shared JNH pool. In an extreme scenario, this could also lead to FPC crash.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1591264 Traffic loss might be seen under EVPN scenario when MAC-IP moves from one CE interface to another
Product-Group=junos
On all Junos/Junos Evolved platforms with EVPN scenario, the number of MAC-IP binding counters may reach the limit when MAC-IP is moved between interfaces. Since MAC-IP counters are not decremented when entry is deleted due to this defect, repeated moves will result in a limit (default value is 1024) that will be reached even though there are fewer entries. Meanwhile, traffic loss could be seen.
1609322 Few ARP/ND/MAC entries for Vlans are missing with MAC-VRF configuration
Product-Group=junos
In all Junos and Evo platforms, in EVPN-VXLAN scenario, with "proxy-macip-advertisement" knob configured, few ARP/ND/MAC entries may get missing.
PR NumberSynopsisCategory: EX4400 platform
1613702 FPC might crash after device restart in EVPN-VXLAN scenario
Product-Group=junos
On EX or QFX platforms with Ethernet VPN (EVPN) and Virtual Extensible LAN (VxLAN) enabled, FPC(Flexible PIC Concentrator) might crash after the device is restarted. Traffic loss is observed until the FPC is restarted and services are restored.
PR NumberSynopsisCategory: Express PFE FW Features
1432116 The FPC might crash when a firewall filter is modified.
Product-Group=junos
In QFX10K/PTX series platforms, if a firewall filter with multiple match conditions is configured on interfaces which are Up and the firewall filter is modified (either a new action is added or the condition is added/removed etc.), the FPC might crash and restart. It might affect the service/traffic.
PR NumberSynopsisCategory: to track replication related interface bugs
1606779 When MTU is configured on an interface a rare ifstate timing issue could occur at a later point resulting in ksyncd process crash on backup RE
Product-Group=junos
On all Junos platforms with MTU and xSTP configured on an interface, a rare ifstate timing issue could occur at a later point resulting in ksyncd process crash on backup RE. When ksyncd crashes on backup RE, a live kernel core is also dumped on both the REs.
PR NumberSynopsisCategory: Interface Information Display
1574035 if-media-type missing from interface XML output on MX Series routers
Product-Group=junos
Extensible Markup Language (XML) is a standard for representing and communicating information. The Junos OSCLI and the Junos OS infrastructure communicate using XML. The operational command "show interface | display xml" displays the interface parameters in XML format. This output displays the media type if-media-type along with other parameters for the platforms like QFX Series switches. However, for MX Series routers, if-media-type parameter is not displayed in the output from day one. With the fix of this PR, the XML output for MX Series routers displays the if-media-type parameter for 1Gb interfaces only.
PR NumberSynopsisCategory: QFX L2 PFE
1560086 On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
Product-Group=junos
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
1595029 After loaded 4093 irb configs, found that few vlans stuck in destroyed state
Product-Group=junosvae
Qfx5100 overall and FPC CPU utilisation may be high incase of 4093 Irb with full port density(32/24). It may differ by max 4-5% compare to same system having very less port density (1 or 2 ports). Some of FPC threads takes more CPU in such scenario (Ethernet/QSfp) etc.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1489374 Packets drop might be seen when multicast MAC with static ARP is configured on one IRB interface
Product-Group=junos
On EX2300/EX3400/EX4300/EX4600/QFX5K platforms, if multicast MAC with static ARP is configured on one IRB interface, the packets which destination is the IP address of static ARP might not get out of the interface. So traffic drop might be seen.
PR NumberSynopsisCategory: QFX5100 Platform optics
1606003 QFX5100 : Generate an optical power after detached and attached QSFP on disabled interface.
Product-Group=junos
On QFX5100, optical power is seen after detached and attached QSFP on disable interface.

 


Modification History

First publication 2022-01-14