Alert Type
PSN - Product Support Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX
Alert Description
Junos Software Service Release version 19.4R2-S7 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 19.4R2-S7 is now available.
19.4R2-S7 - List of Fixed issues
PR Number
Synopsis
Category: EX2300/3400 platform
1627673
System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR Number
Synopsis
Category: Border Gateway Protocol
1556210
The rpd core might occur when BGP origin validation trace is enabled with scaled routes
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, with BGP origin validation traceoption is configured, if scaled routes (more than 5M) are added/withdrawn, rpd core might occur and BGP peers might flap.
PR Number
Synopsis
Category: Class of Service
1568661
FPC crash might be observed after the "show class-of-service" command
Product-Group=junos
When "show class-of-service scheduler-resources fpc" is issued, the FPC might crash and the core-dump is generated.
1649510
The cosd process might not be able to send unbinds for rewrites post a certain sequence of operations are performed
Product-Group=junos
On All Junos platforms, in certain conditions, a stale rewrite rule entry is left behind in the PFE and the corresponding kernel state is also wrong. The pre-conditions to note this phenomenon include a sequence of AE specific operations along with the presence of COS (class-of-service) configuration. For example, let us say, we have config-1, which defines a set of AE bundles and associates COS rewrite rules under the bundle. Now we perform a sequence of operations to delete AE bundle and then add it back as well. In between, we remove class-of-service and add back class-of-service to the AE bundle as well. Now, when we override this config-1 with a new config-2 that defines the same AE bundle but an updated rewrite rule (with additional forwarding classes and mappings), it is possible to see a previous rewrite rule still being used for AE specific IFLs. At times a stale unused rewrite rule is left behind if config-2 no longer uses the previous rewrite rule that came in from config-1. To recover from this problem, we need to restart cosd twice or do an NSR GRES followed by deactivate/activate of class-of-service.
PR Number
Synopsis
Category: L2NG Access Security feature
1568654
Junos OS and Junos OS Evolved: Local Privilege Escalation and Denial of Service
Product-Group=junos
A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. A second improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) was also discovered, allowing a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or additional Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11222
[juniper.net]
for more information.
1606794
Junos OS: In a scenario with dhcp-security and option-82 configured, the jdhcpd crashes upon receipt of a malformed DHCP packet (CVE-2022-22176)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11282
[juniper.net]
for more information.
PR Number
Synopsis
Category: OpenSSH and related subsystems
1612947
Junos OpenSSH leaves a dangling pointer
Product-Group=junos
On all Junos OS platforms, Junos OpenSSH might leave a dangling pointer that may cause the sshd to crash with core-dumps.
PR Number
Synopsis
Category: Device Configuration Daemon
1569399
,Traffic might be interrupted while adding xe-/ge- interfaces as member of aggregated Ethernet interface bundle
Product-Group=junos
On all Junos platforms, if a xe- or ge- interface has the "set interfaces disable" configuration, the interface is added as a member of an aggregated Ethernet interface bundle, and "delete interfaces disable" command is committed, then in some rare scenario it might result in vmcore and cause the system to reboot. This leads to traffic impact. After vmcore, system boots up and comes to normal state.
PR Number
Synopsis
Category: Firewall Filter
1625309
Packet loss might be reported after hitting the firewall filter on Junos platform
Product-Group=junos
On Junos platform, on the egress or ingress PFE instance, after hitting a firewall, it might lead to packet loss and impact service.
PR Number
Synopsis
Category: JUNOS Dynamic Profile Configuration Infrastructure
1607494
Commit related to dynamic profile configuration changes might fail upon executing "request vmhost reboot routing-engine both" on MX platforms
Product-Group=junos
On all MX platforms that support the VMHost routing engine, upon executing the command "request vmhost reboot routing-engine both" any commit related to dynamic-profile changes might fail.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1492365
The EVPN unicast traffic might stop after deactivating and reactivating the knob 'vlan-id none'
Product-Group=junos
When the deactivate and activate commands are issued in quick succession for the knob 'vlan-id none' in EVPN routing instance, internal components may get out of sync. That manifests MAC entries being present in the control plane but not in data plane. This issue will cause traffic loss.
PR Number
Synopsis
Category: Express PFE FW Features
1652762
Configuring gre-key in firewall filter may breaks the dscp classification
Product-Group=junos
On PTX series platforms, the DSCP classification may not work for gre-key filter. Differentiated Services Code Point (DSCP) is a means of classifying and managing network traffic and of providing quality of service (QoS) in Layer 3 IP networks. When the Range field of gre_key flt_type (promote gre-key) is incorrectly mapped to the legacy TOS (Type of service) field for DSCP, the classification may fail and the filter might not work properly.
PR Number
Synopsis
Category: Express PFE Services including JTI, TOE, HostPath, Jflow
1637364
True Outgoing Interface in ECMP traffic is not getting reported correctly by jflow
Product-Group=junos
On Junos PTX series, True Outgoing Interface(OIF) reporting might not happen correctly for ECMP traffic when ingress sampling is configured on AE interface.
PR Number
Synopsis
Category: ISIS routing protocol
1556575
Junos OS and Junos OS Evolved: An IS-IS adjacency might be taken down if a bad hello PDU is received for an existing adjacency causing a DoS (CVE-2021-31362)
Product-Group=junos
A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading to a Denial of Service (DoS) condition. Refer to https://kb.juniper.net/
JSA11224
[juniper.net]
for more information.
PR Number
Synopsis
Category: Adresses ALG issues found in JSF
1577814
Junos OS: MX Series: Receipt of specific packet on MS-MPC/MS-MIC causes line card reset (CVE-2021-31351)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (DoS). Refer to https://kb.juniper.net/
JSA11216
[juniper.net]
for more information.
PR Number
Synopsis
Category: Security platform jweb support
1591621
Junos OS: J-Web can be compromised through reflected XSS attacks (CVE-2022-22181)
Product-Group=junos
A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context of their session within J-Web. Refer to https://kb.juniper.net/
JSA69517
[juniper.net]
for more information.
1591626
Junos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web session (CVE-2022-22182)
Product-Group=junos
A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. Refer to https://kb.juniper.net/
JSA69519
[juniper.net]
for more information.
PR Number
Synopsis
Category: lacp protocol
1640240
Aggregated Ethernet interface remains up instead of down after deleting loopback and ae interface ip on neighbor while verifying BFD sessions on router
Product-Group=junos
Aggregated Ethernet child interfaces with LACP configurations are not timing out even if peer is gone and not sending any bridge protocol data unit (BPDU).
PR Number
Synopsis
Category: MX2010 platform software
1477924
Observed messages spmb0 cmty_sfb_temp_check: sfb[0] is powered OFF and spmb0 cmty_sfb_voltage_check_one: sfb[0] is powered OFF are flooding even though SFBs are online in MX2010.
Product-Group=junos
With JUNOS 19.3R2 and higher, syslogs such as "spmb0 cmty_sfb_temp_check: sfb[0] is powered OFF" & "spmb0 cmty_sfb_voltage_check_one: sfb[0] is powered OFF" are flooding even though SFB2s are online in MX2008/MX2010/MX2020
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1570148
A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
1581171
The upgrade might fail when the space is enough for the new Junos file but is tight
Product-Group=junos
On all platforms with FreeBSD 11 or 12 based Junos, the upgrade might fail with the message "Error: not enough space to unpack " when the space is enough for the new Junos file but is tight. The issue is because space_available uses K bytes while space_required uses byte when calculates the space. The space_required might become bigger than space_available even when the real space_available is bigger than the space_required. Hence the message "Error: not enough space to unpack " is seen during the upgrade.
1601904
The process rpd may slip due to a FreeBSD defect
Product-Group=junos
The process rpd may slip due to a FreeBSD defect. See [FreeBSD id=227689](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=227689) for more information.
1639991
Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR Number
Synopsis
Category: TCP/UDP transport layer
1552603
The BGP session replication might fail to start after the session crashes on the backup Routing Engine.
Product-Group=junos
On certain Junos platforms with Dual-REs (platforms capable of installing Junos packages with name format as "junos*install"), BGP replication may fail to start under GRES/NSR setup after a crash on backup Routing Engine. NSR starts un-replicating the socket since backup Routing Engine is no longer present. Massive unreplicated request leads to memory buffer getting full with multiple BGP sessions (e.g., 20 BGP peers). Hence BGP unreplicated request returned with an error. Besides, the kernel is left with stale data. It does not allow the JSR (Juniper Socket Replication, BGP in this case) when backup RE comes up due to the stale data. BGP-NSR (Nonstop Routing) is broke under the conditions. Traffic outage will be observed after performing GRES.
1595649
Junos OS: Upon receipt of specific sequences of genuine packets destined to the device the kernel will crash and restart (vmcore) (CVE-2021-0283, CVE-2021-0284)
Product-Group=junos
A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/
JSA11200
[juniper.net]
for more information.
PR Number
Synopsis
Category: Paradise pfe ddos protection feature
1564807
Junos OS: Upon receipt of specific packets BFD sessions might flap due to DDoS policer implementation in Packet Forwarding Engine (CVE-2021-0280)
Product-Group=junos
On PTX platforms and QFX10K Series with Paradise (PE) chipset-based line cards, DDoS protection configuration changes made from the CLI will not take effect as expected beyond the default DDoS (Distributed Denial of Service) settings in the Packet Forwarding Engine (PFE). This may cause BFD sessions to flap when a high rate of specific packets are received. Refer to https://kb.juniper.net/
JSA11184
[juniper.net]
for more information.
PR Number
Synopsis
Category: vMX Data Plane Issues
1641119
IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On vMX/MX150/NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
PR Number
Synopsis
Category: vMX Platform Infrastructure related issue tracking
1643932
VRRP and ISIS fails to converge after interface flap
Product-Group=junos
On VMX platforms with i40e drivers, VRRP and ISIS might fail to converge after the interface flaps which might affect multicast services.
PR Number
Synopsis
Category: Related to sw defects for K2-RE
1662913
The watchdog timeout is encountered and the system reboots after the 'request system halt' command executed
Product-Group=junos
On all platforms with RE-1800 & RE-2000, after the 'request system halt' command is executed, the watchdog timeout is encountered and causes the routing engine (RE) to fail to boot.
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1515941
Indirect NH change in EVPN network can cause Remote PE FPC?s to crash
Product-Group=junos
It is the standard design of EVPN that to reach remote PE, indirect NH is created to send traffic to remote PE through the egress MPLS interface. During the instance of a protocol /interface flap or a commit , will cause indirect NH to get deleted / created as per standard behavior. This change may trigger this PR and cause the FPC?s to crash on the remote PE. In such a scenario , it will be impossible to predict which PE device caused this, if the ifl index on the impacted remote PE changes after crash.
PR Number
Synopsis
Category: VMHOST platforms software
1605971
VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
19.4R2-S7 - List of Known issues
PR Number
Synopsis
Category: Flow Module
1607782
Junos OS: SRX Series: Denial of service vulnerability in flowd daemon upon receipt of a specific fragmented packet (CVE-2022-22185)
Product-Group=junos
A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a Denial of Service (DoS) by sending a specific fragmented packet to the device, resulting in a flowd process crash, which is responsible for packet forwarding. Continued receipt and processing of this specific packet will create a sustained DoS condition. Refer to https://kb.juniper.net/
JSA69493
[juniper.net]
for more information.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1416334
19.1R1: ISSU: During ISSU from 18.4R1 to 19.1, traffic through IPSEC VPN fails.
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 devices, during in-service software upgrade (ISSU), the IPsec tunnels flap, causing a disruption of traffic. The IPsec tunnels recover automatically after the ISSU process is completed.
Modification History
First publication 2022-06-22
19.4R2-S7: Software Release Notification for JUNOS Software