Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX

Alert Description

Junos Software Service Release version 19.4R2-S6 is now available for download from the Junos software download site
Download Junos Software Service Release:
  1. Go to  Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select  Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.4R2-S6 is now available.

19.4R2-S6 - List of Fixed issues

PR Number Synopsis Category: EX2300/3400 PFE
1619970 Junos OS: EX2300 Series, EX2300-MP Series, EX3400 Series: A slow memory leak due to processing of specific IPv6 packets (CVE-2022-22180)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA11286 [juniper.net] for more information.
PR Number Synopsis Category: a20a40 specific issue
1600216 Traffic through one SPU may stop with potential packet drop issue with alarm as FPC Major Errors raised due to the PIC_CMERROR_TALUS_PKT_LOSS error
Product-Group=junos
On SRX5k series with SPC3 card, in rare cases an SPU may stop forwarding traffic. In this case, logs will show a "potential pkt drop issue" on all the cores of that SPU and an FPC Major Alarm would be raised due to the PIC_CMERROR_TALUS_PKT_LOSS error being reported.
PR Number Synopsis Category: Border Gateway Protocol
1607777 With rib-sharding enabled any commit will flap all BGP sessions with 4 byte peer-as (AS number 65536 or greater)
Product-Group=junos
On all Junos platforms, if both rib-sharding and 4-byte peer-as (AS number 65536 or greater) are configured then BGP peers with 4-byte peer-as might flap whenever any configuration change occurs.
1626367 Time delay to export prefixes to BGP neighbors might occur post applying peer-specific BGP export policies
Product-Group=junos
On all Junos and EVO Platforms, when BGP export policies were changed from deny all to the peer-specific export policies, it might take several hours for the RPD/BGP to finish the export evaluation.
PR Number Synopsis Category: Covers Application classification workflows apart from custo
1599053 Junos OS: SRX Series: If no-syn-check is enabled, traffic classified as UNKNOWN gets permitted by pre-id-default-policy (CVE-2022-22167)
Product-Group=junos
A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on the device. While JDPI correctly classifies out-of-state asymmetric TCP flows as the dynamic-application UNKNOWN, this classification is not provided to the policy module properly and hence traffic continues to use the pre-id-default-policy, which is more permissive, causing the firewall to allow traffic to be forwarded that should have been denied. Refer to https://kb.juniper.net/JSA11265 [juniper.net] for more information.
PR Number Synopsis Category: EVPN control plane issues
1528550 The rpd crash might be seen due to memory leak
Product-Group=junos
On all Junos platforms which support (Ethernet VPN) EVPN (Virtual Extensible LAN) VXLAN, when there is a policy applied for EVPN routes which has a route-filter/route-filter-list/prefix-filter/prefix-filter-list configured in it and there are EVPN T-5 routes(in 17.3 release) or T-2 MAC/IP or T-5 routes (19.4R1 release) in the network, then memory leak is observed. The rpd might crash due to memory leak over time and cause traffic impact.
PR Number Synopsis Category: jdhcpd daemon
1618977 Junos OS: The jdhcpd crashes upon receiving a specific DHCP packet (CVE-2022-22179)
Product-Group=junos
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of the jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11285 [juniper.net] for more information.
PR Number Synopsis Category: Layer 2 Control Module
1602588 Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS (CVE-2022-22172)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can lead to memory exhaustion and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA11278 [juniper.net] for more information.
1629011 Traffic drop might be reported on the interface after reboot or power cycle
Product-Group=junos
On Junos and EVO platforms, after reboot or power cycle, aggregated ethernet (AE) interfaces will have spanning tree protocol (STP) state discarding after the box comes up. It might cause traffic drop on the interface.
PR Number Synopsis Category: Layer2 forwarding on EX/NTF/PTX/QFX
1625292 Junos OS: Specific packets over VXLAN cause FPC reset (CVE-2022-22171)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause the PFE to reset. Refer to https://kb.juniper.net/JSA11277 [juniper.net] for more information.
1627617 The line card might crash and reload if the EVPN MAC entry is not deleted correctly
Product-Group=junos
On all Junos and EVO platforms, the line card might crash and reload in an EVPN-MPLS scenario when there is a MAC move from local to remote and the request to delete MAC entry is received from remote. Core files are generated and complete traffic loss might be observed until the line card reloads.
PR Number Synopsis Category: Paradise pfe ddos protection feature
1510788 DDOS ARP protocol option is renamed from arp-snoop to arp on PTX10002/QFX10002-60C switches.
Product-Group=junos
The DDOS ARP protocol option is renamed from arp-snoop to arp on PTX10002/QFX10002-60C switches. root@qfx10002-60c# set system ddos-protection protocols arp ? Possible completions: > aggregate Configure aggregate for all ARP traffic + apply-groups Groups from which to inherit configuration data + apply-groups-except Don't inherit configuration data from these groups > arp-snoop Configure ARP snoop traffic <<<<<<<<<<< > unclassified Configure unclassified ARP traffic
PR Number Synopsis Category: vMX Data Plane Issues
1624057 Packet loss may be seen when enabling output sampling on the source interface of Tunnel
Product-Group=junos
On vMX/MX150 platforms, when enabling output sampling on the source interface of any kind of Tunnels that flow cached, like GRE, L2TP, MPLSoGRE, etc, packet loss may be seen. If pinging from the remote tunnel IP address, the local tunnel responses the first ICMP echo request packet but not for the subsequent ICMP echo request packets. Similarly, other protocols packet loss over Tunnel will be seen as well.
PR Number Synopsis Category: RPD route tables, resolver, routing instances, static routes
1525363 Traffic loss might occur during VRF route resolution over indirect next hop.
Product-Group=junos
This applies to an L3VPN with the "chain-composite-nexthop" environment in which next-hops are indirect next-hops (such as labels). When committing a change in VRF configuration, the router may drop packets.
1599084 IPv4 static route might still forward traffic unexpectedly even when the static route configuration has already been deleted
Product-Group=junos
On all Junos and EVO platforms with "static defaults" configured under "routing-options" hierarchy, if IPv4 static route configuration is added, and then deleted, the IPv4 static route will not be removed from routing table and still forward traffic unexpectedly due to this issue.
PR Number Synopsis Category: ZT/YT pfe firewall software
1627986 FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR Number Synopsis Category: Trio pfe l3 forwarding issues
1569715 The MPLS traffic passed through the back-to-back PE router topology might match the wrong CoS queue.
Product-Group=junos
The MPLS traffic passed through the back-to-back PE router topology might match the wrong CoS queue. This occurs in a scenario involving back-to-back PE routers with CoS configurations where the LDP or RSVP LSP is a single-hop LSP due to penultimate hop popping (PHP) and a real outer label is not imposed. In such a scenario, the EXP bits in the inner label (the label corresponding to Layer 2 circuit, Layer 2 VPN, Layer 3 VPN, etc.) might not be propagated based on the configured EXP rewrite rule to the downstream router. This results in the egress PE router classifying traffic incorrectly, and traffic might be forwarded in an incorrect queue.
 

19.4R2-S6 - List of Known issues

PR Number Synopsis Category: EVPN control plane issues
1600310 Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance
Product-Group=junos
When using the logical tunnel (lt-) interface to stitch EVPN-MPLS and EVPN-VxLAN, bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. This is due to the AD (Auto-Discovery) route per ESI with VxLAN encapsulation community which is ignored on MPLS routing instance.
PR Number Synopsis Category: Layer2 forwarding on EX/NTF/PTX/QFX
1602407 Junos OS: Specific packets over VXLAN cause FPC memory leak and ultimately reset (CVE-2022-22170)
Product-Group=junos
A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause heap memory to leak and on exhaustion the PFE to reset. Refer to https://kb.juniper.net/JSA11277 [juniper.net] for more information.
PR Number Synopsis Category: FreeBSD Kernel Infrastructure
1533861 Device might be stuck in boot-loop after zeroize with the image in OAM volume
Product-Group=junos
On all Junos platforms, after performing command "request system zeroize", the device might be stuck in boot-loop and reboots continuously, when trying to recover through OAM, the device unable to install the downloaded image from OAM recovery mode.
PR Number Synopsis Category: RPD policy options
1616167 The rpd process might get stuck at 100% when EVPN vrf-target is enabled and after any configuration change
Product-Group=junos
On all Junos and EVO platforms with EVPN (Ethernet VPN)/EVPN-VXLAN (Virtual Extensible LAN Protocol) implemented, any configuration (related/unrelated) change with the knobs 'vrf-target auto' and/or 'protocols evpn vni-options vni vrf-target ' being enabled might result in CPU spike and thus, rpd (routing protocol process) gets stuck at 100%. Traffic could be blackholed during the incident happening and could be back to normal once CPU usage is decremented after an interval.
 

Modification History

First publication 2022-02-03