Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, PTX, QFX running Junos Evolved Software

Alert Description


Junos Software Service Release version 21.1R3-S2-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 21.1R3-S2-EVO is now available.

21.1R3-S2-EVO - List of Fixed issues

PR NumberSynopsisCategory: Border Gateway Protocol
1643089The rpd crash files may be seen on MX and PTX platforms
Product-Group=evo
The rpd (routing process daemon) process might crash in the BGP (Border Gateway Protocol) rib-sharding scenario on all Junos and Junos Evolved MX and PTX platforms. The rpd crash may cause service impact. However, the rpd restarts and recovers by itself.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1651932An error might be seen when the member link on an AE bundle is deleted
Product-Group=evo
On all EVO PTX platforms, gRPC connection between the "evo-aftmand" process and the "cda" process maybe disconnect with the messages "[Error] CDA: exprGrpcAsyncApi: failed cq read", and "GOAWAY with error code ENHANCE_YOUR_CALM". When the disconnection happens, the Junos Evolved system can no longer retrieve status or programs forwarding ASICs. This is a catastrophic failure.
PR NumberSynopsisCategory: bug tracker for evo
1649163EVO:ACX When fixed classifier is detached all default classifiers should be re-attached
Product-Group=evo
When you configure classifiers on an interface, the default classifiers are removed. This may cause traffic matching default classifier to not being classified
PR NumberSynopsisCategory: Issues related to debug utilties - objmon,objshell/Dashboard
1602272Junos OS and Junos OS Evolved: python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API via timed processing of valid PKCS#1 v1.5 ciphertext. (CVE-2020-25659)
Product-Group=evo
A vulnerability in the python cryptographic library as used in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to perform timing oracle attacks against RSA decryption. Please refer to https://kb.juniper.net/JSA11245 [juniper.net] for more information.
PR NumberSynopsisCategory: PRs related to software Agentd daemon on EVO
1672783PDT: TI-S/MOP: Brackla router was not coming up, due to picd, mgd-pfe application failures.
Product-Group=evo
This issue is applicable to PTX10003. Downgrade from 21.4R2-EVO to 20.4R3-EVO fails and few Apps are not started.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1646010IRB might not send out arp-reply if "no-arp-suppression" is configured
Product-Group=evo
On all Junos platforms, when "no-arp-suppression" is configured, the Layer 2 Address Learning Manager (L2ALM) will not respond to Address Resolution Protocol (ARP) request for Integrated Routing and Bridging (IRB) IP, and traffic to IRB will be lost.
PR NumberSynopsisCategory: Express PFE CoS Features
1648760EVO snmpwalk do not return value for index 0
Product-Group=evo
EVO - snmpwalk over leaf of jnxCosQstatTable do not return value for index 0
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1658913Valid software licenses might not be in sync between members in the Virtual chassis.
Product-Group=evo
Software licenses will now be synced to all members of Virtual chassis. - Warnings and alarm to be seen only on global master member in VC. - show system license. command will be executed only on global master member. - Issue is specific to all MX VC setup for all Junos. For all other members it will display the following message: root@> show system license error: This command can only be used on the master routing engine.
PR NumberSynopsisCategory: Multicast Listener Discovery
1656311The rpd process crash might be observed with PIM configured
Product-Group=evo
On all Junos and Junos OS Evolved platforms, if the interface is enabled with Protocol Independent Multicast (PIM) (enables Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) implicitly) and the same interface is configured under a non-forwarding instance, then the process rpd crash might be observed.
PR NumberSynopsisCategory: next gen multicast for L3VPNs
1647149The routing protocol process might stop working when de-activating and activating the same provider tunnel from one to another instance in a single commit
Product-Group=evo
On all platforms when de-activating and activating the same provider tunnel from one to another instance in a single commit, the routing protocol process might stop working.
PR NumberSynopsisCategory: Issues related to Junos Automation, Commit/Op/Event and SLAX
1634027Automation Infra may fail when the interface is pre-configured with flexible-vlan-tagging
Product-Group=evo
On all Junos and Evolved(EVO) platforms, when two interfaces are configured in the device under the same commit action and if one of the interfaces is pre-configured with flexible-vlan-tagging knob, it might impact the automation infra which includes commit, op, event, and JET scripts to fail.
PR NumberSynopsisCategory: Issues related to confg mgmt, ffp, load-action, commit procs
1659783The configuration might roll back after performing "commit confirmed" and then reboot
Product-Group=evo
On all Junos OS and Junos OS Evolved platforms, the configuration might roll back after performing "commit confirmed" and then a reboot.
PR NumberSynopsisCategory: Issues related to mgd, DAX API, DDL/ODL infrastructure, Juno
1598123Interface configuration may get stuck and may not update after several ephemeral commits
Product-Group=evo
After several ephemeral commits interface configurations may get stuck and may not get updated on all Junos platforms.
1627323Junos Fusion Satellite EX4300 upgrade fails from Aggregate Device MX104
Product-Group=evo
Junos Fusion Satellite Device (SD) EX4300 upgrade fails from Aggregate Device (AD) MX104 with dual-RE.
1641025Unable to access configure exclusive mode after mgd process is killed
Product-Group=evo
On all Junos OS and Junos OS Evolved devices, when copy-config, get-configuration, and discard-change RPCs run in two parallel NETCONF sessions and the database is also accessed in parallel by two NETCONF sessions, it leads to database corruption and mgd-related services might crash.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1646480The vrrpd core might be observed after interface state change
Product-Group=evo
On all Junos/EVO platforms with VRRP (Virtual Router Redundancy Protocol) implemented, if "startup-silent-period" is configured as 1sec and if state of any interfaces included in VRRP-group changes, it might result in vrrpd (VRRP daemon) crash, impacting the related services. However, configuring startup-silent-period between 2 and 2000sec and restarting vrrpd will help to restore the services.
 
 

21.1R3-S2-EVO - List of Known issues

PR NumberSynopsisCategory: Express PFE L3 Multicast
1669740Multicast traffic drop might be seen on specific PTX10k platforms
Product-Group=evo
On specific PTX10k products (PTX10008/ PTX10016/ PTX10001-36MR/ PTX10K-LC1202-36MR), multicast packets get dropped when any replication applications (Multicast, P2MP (Point to Multipoint)) are used and it is flooded on interfaces spread across more than 15 PFEs (Packet Forwarding Engines). This issue might impact a forwarding plane.
PR NumberSynopsisCategory: ISIS routing protocol
1610983Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received (CVE-2022-22196)
Product-Group=evo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS); Please refer to https://kb.juniper.net/JSA69509 [juniper.net] for more information.

Modification History

First Publication 2022-09-21