Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 19.3R3-S7 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.3R3-S7 is now available.

19.3R3-S7 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1671304Commit fails on EX4300 as EX4600 and EX4300 mixed virtual-chassis is not able to create more than 1024 IFLs
Product-Group=junos
Commit check fails on EX4300 when mixed mode virtual-chassis is configured between EX4600 and EX4300 and IFL (logical interface) is created on an aggregate interface having more than 1024 IFLs. Commit failure will be seen.
PR NumberSynopsisCategory: EX4300 Platform
1655530The dc-pfe might crash due to the VCCP flap
Product-Group=junos
On all Junos EX and QFX platforms configured with Virtual Chassis (VC), with the Virtual Chassis Control Protocol (VCCP) flaps or any configuration change which causes VCCP to flap, might lead to the process dc-pfe crash.
PR NumberSynopsisCategory: EX4300 routing implementation
1655654Few EX platforms does not generate ICMPv6 too big messages
Product-Group=junos
Few EX platforms may not generate ICMPv6 too long messages which could cause the path MTU (maximum transmission unit) discovery to fail. As a result, IPv6 session establishment may fail.
PR NumberSynopsisCategory: EX9200 Platform
1569230The 40G DAC connection between EX9253 and the peers might not come up
Product-Group=junos
DAC cable might not come up in 40G mode between EX9253 when any interface on PIC0 of FPC 0 or FPC 1 is connected to the peers.
PR NumberSynopsisCategory: EX2300/3400 PFE
1564941The DHCP client might not obtain IP address when dhcp-security is configured
Product-Group=junos
On EX2300 platforms, if enterprise Style (EP) and service provider (SP) style configurations are mixed on a trunk interface, the DHCP client under SP style configuration might not obtain IP address when dhcp-security is enabled on one of the trunk VLANs.
1633883The EX2300 may unexpectedly drop VOIP VLAN traffic after reboot
Product-Group=junos
On the EX2300 platform, the traffic drop may be observed on VOIP VLAN after the device reboot. Voice VLAN on EX2300 may not forward traffic correctly out of the interface when the device is either power-cycled / halted / power off or power on, and may not communicate with the default gateway.
1653260L2PT may not work for AE interfaces in Q-in-Q environment.
Product-Group=junos
This issue Affects all EX-2300,EX-3400,EX-4300MP,EX4600,EX4600-40F. L2PT may not work for AE interfaces in Q-in-Q environment.
PR NumberSynopsisCategory: QFX PFE CoS
1650051The fixed classifier may not work in MPLS and VXLAN scenario
Product-Group=junos
On QFX5100 platforms, traffic may not get classified based on a fixed classifier in MPLS as well as the VXLAN scenario.
PR NumberSynopsisCategory: Sflow on QFX 5100,5200, 5110
1598239Sflow impacts on ICMP traffic on QFX5XXX platforms
Product-Group=junos
On QFX5XXX platforms in sflow scenario, CPU/host bound ICMP traffic from or to the sampled interface might be dropped, which might have impact on services based on ICMP probes like RPM.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1675921Micro BFD session state in RE remain UP even peer side session is down.
Product-Group=junos
Any platforms with Micro BFD configured on member links of the LAG/ae interface, BFD Session state in RE remains as UP always even though PEER device has ceased.
PR NumberSynopsisCategory: Border Gateway Protocol
1611128Junos OS and Junos OS Evolved: In a BGP multipath scenario, when one of the contributing routes is flapping often and rapidly, rpd may crash (CVE-2022-22225)
Product-Group=junos
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker with an established BGP session to cause a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69875 [juniper.net] for more information.
PR NumberSynopsisCategory: Class of Service
1639518Queue flush failure logs are reported for 10G and 100G interfaces of MPC10E/MPC11E cards
Product-Group=junos
Queue flush failure logs are reported for 10G and 100G interfaces of MPC10E/MPC11E cards that are part of AE bundles post flapping of other member links.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for DNX
1537619On the ACX5448 routers, the Packet Forwarding Engine crashes on the show pfe ifd vty command.
Product-Group=junos
In 19.4 release when "show pfe ifd" command executed in the PFE, FPC crash is observed in ACX5448 platform. This issue is addressed in 19.4R2-S2.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1637181The srxpfe process might crash while installing IDP sigpack with scaled traffic on SRX platforms
Product-Group=junos
On SRX platforms, while installing IDP(Intrusion Detection and Prevention) sigpack in a loop (installing private IDP sigpacks for particular versions alternatively) srxpfe process might crash.
1638588AppID installation failure on the secondary HA node in case of failover
Product-Group=junos
On SRX platforms, installation of Application Identification service failed on the secondary HA node in case of failover due to checksum validation.
PR NumberSynopsisCategory: Manageability for Node Virtualization
1583324JDM server creation might fail on junos node slicing setup in in-chassis mode
Product-Group=junos
On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1621892Junos OS Evolved: The ssh CLI command always runs as root which can lead to privilege escalation (CVE-2022-22239)
Product-Group=junos
An Execution with Unnecessary Privileges vulnerability in Junos Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges to escalate their privileges on the device and potentially remote systems. Please refer to https://kb.juniper.net/JSA69895 [juniper.net] for more information.
PR NumberSynopsisCategory: SNMP, mib2d issues
1669510The snmpd core might be observed with filter-duplicates configuration
Product-Group=junos
On all Junos and EVO platforms configured with filter-duplicates, the snmpd core might be observed if the SNMP query is made simultaneously from NMS (Network Management System) as well from the CLI.
PR NumberSynopsisCategory: EVPN control plane issues
1659786The process rpd might crash when protocol EVPN is deactivated
Product-Group=junos
On all Junos and Junos OS Evolved platforms, with multiple activating/deactivating Ethernet Virtual Private Network (EVPN) or deactivating the Virtual Routing and Forwarding (VRF) instance with protocols EVPN for type 5 route, the process rpd might crash.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1674116The BFD packets will drop in an EVPN-VxLAN scenario due to incorrect layer3 offset being set in the host path
Product-Group=junos
On all QFX10000-60C platforms with Ethernet VPN-Virtual Extensible LAN (EVPN-VxLAN) scenario, the Bidirectional Forwarding Detection (BFD) packets are getting classified as packets of different protocols like Virtual Router Redundancy Protocol (VRRP), depending on the value at an incorrect offset which leads to BFD packet drop.
PR NumberSynopsisCategory: Flow Module
1629407SRX5000 Series with SPC3, SRX4000 Series, and vSRX: When PowerMode IPsec is configured, the PFE will crash upon receipt of a malformed ESP packet (CVE-2022-22201)
Product-Group=junos
An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69900 [juniper.net] for more information.
PR NumberSynopsisCategory: l2 flow module
1599891OSPF neighbor won't establish under Transparent mode when neighborship across different zone
Product-Group=junos
Some of the OSPF neighborship might not able to establish after system bootup when the neigborship connect to SRX via different zone under transparent mode
PR NumberSynopsisCategory: Firewall Network Address Translation
1645039Datapath daemon might crash resulting in total traffic and service failure
Product-Group=junos
On all SRX-Series devices, when policy configuration is modified and committed multiple times while the device is handling MS-RPC traffic with more than 1000 RPC port map entries present in the device, it may result in datapath daemon crash.
PR NumberSynopsisCategory: Firewall Policy
1656324Junos OS: SRX Series: Cache poisoning vulnerability in BIND used by DNS Proxy (CVE-2021-25220)
Product-Group=junos
An Insufficient Verification of Data Authenticity vulnerability in Juniper Networks Junos OS on the SRX Series devices within the BIND library used by DNS proxy allows an attacker to cause the cache to become poisoned with incorrect records which might lead to queries being made to the wrong servers, which might also result in false information being returned to clients. Please refer to https://kb.juniper.net/JSA69888 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1673391High Control Plane CPU utilisation while the kmd process is stuck after the core file
Product-Group=junos
On all SRX platforms, during key management (kmd) core file, with VPN/Internet Key Exchange (IKE) implemented and a high number of file descriptors open, the kmd process will reach above 80% CPU utilisation and stay for a long period of time if the kmd process is stuck after the core file is generated.
PR NumberSynopsisCategory: Security platform jweb support
1656805Junos OS: Vulnerability in J-Web may allow deserialization without authentication (CVE-2022-22241)
Product-Group=junos
An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. Please refer to https://kb.juniper.net/JSA69899 [juniper.net] for more information.
1656808Junos OS: XPath Injection vulnerability in J-Web (CVE-2022-22243)
Product-Group=junos
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. Refer to https://kb.juniper.net/JSA69899 [juniper.net] for more information.
1656809Junos OS: Unauthenticated XPath Injection vulnerability in J-Web (CVE-2022-22244)
Product-Group=junos
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality. Refer to https://kb.juniper.net/JSA69899 [juniper.net] for more information.
1656810Junos OS: Path traversal vulnerability in J-Web (CVE-2022-22245)
Product-Group=junos
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file due to validation checks built into Junos OS. Successful exploitation of this vulnerability could lead to loss of filesystem integrity. Refer to https://kb.juniper.net/JSA69899 [juniper.net] for more information.
PR NumberSynopsisCategory: lacp protocol
1635935Traffic loss may be seen on QFX10K due to congestion
Product-Group=junos
During congestion PPMAN(Periodic packet management) run short of resource leading to PDUs (Protocol Data Units) getting failed to be sent. Due to PPMAN queue starvation across TX/RX path, LACP sessions may not get a chance to transmit PDUs which can further lead to peer lacp timeout, aggregated ethernet interface flap and traffic loss.
1640240Aggregated Ethernet interface remains up instead of down after deleting loopback and ae interface ip on neighbor while verifying BFD sessions on router
Product-Group=junos
Aggregated Ethernet child interfaces with LACP configurations are not timing out even if peer is gone and not sending any bridge protocol data unit (BPDU).
PR NumberSynopsisCategory: Label Distribution Protocol
1680574In an LDP -> BGP LU stitching scenario, Multiple LSPs will not be installed in the forwarding table, even if BGP Multipath and ECMP are enabled
Product-Group=junos
On all Junos and Junos OS Evolved Platforms, when BGP LU (Labeled Unicast) routes are exported to LDP (Label Distribution Protocol) to perform LDP->BGP-LU stitching, LDP installs only one NH(Next Hop) in the forwarding table instead of multiple NHs, even when BGP Multipath and ECMP are enabled. This issue will be seen for both EBGP (External Border Gateway Protocol) and IBGP (Internal Border Gateway Protocol) multipaths on PTX platforms and for only iBGP multipaths on all other platforms.
PR NumberSynopsisCategory: lldp sw on MX platform
1669677LLDP neighborship might fail if the chassis-id format of the LLDP packet is xx:xx:xx:XX:XX:xx'
Product-Group=junos
On all Junos platforms, Link Layer Discovery Protocol (LLDP) neighborship fails if the chassis-id format of the LLDP packet is xx:xx:xx:XX:XX:xx'
PR NumberSynopsisCategory: Multiprotocol Label Switching
1673348CPU utilization of rpd process may reach 100% while reporting LSP states to pccd if the IS-IS update churn is high
Product-Group=junos
On all Junos and Junos Evolved platforms where PCEP (Path Computation Element Protocol) is provisioned, after IS-IS (Intermediate System-Intermediate System) PDU (Protocol Data Unit) flooding, rpd (routing protocol daemon) re-computes LSPs (Label Switched Path) and sends those to the pccd (path computation client daemon) which in turn reports those to PCE (Path Computation Element) for processing. If the update churn is high, this may cause the rpd to reach or get stuck at 100% CPU utilization.
PR NumberSynopsisCategory: Track Mt Rainier RE platform software issues
1656746The configuration of management interface might not work
Product-Group=junosvae
On NG-RE (Next Generation Routing Engine) based platforms with Linux version WRL9 and LTS19, after system reboot the management interface configurations might not be applied to the interface.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1644616GARP reply doesn't update ARP entry though gratuitous-arp-reply option is configured.
Product-Group=junos
Receiving GARP reply doesn't help update ARP entry though gratuitous-arp-reply option is configured. As a result, traffic loss might be seen depending on the timing.
PR NumberSynopsisCategory: Kernel Composite Next Hop (composite / l3vpn) Infrastructure
1608991Public nexthops cleanup fails for "mpls" family nexthops on MX platforms
Product-Group=junos
On MX platforms, when GRES is performed multiple times, public nexthops cleanup failed for "mpls" family nexthops and system might not be GRES ready (init_err connection_errsoft_mask_err).
PR NumberSynopsisCategory: Kernel Multicast Infrastructure
1555274Multicast traffic in MVPN setup might be blackholed on some PTX platforms acting as transit LSR
Product-Group=junos
On PTX3000/PTX5000/PTX10008/PTX10016 platforms in MVPN setup with aggregated Ethernet(AE) having 2 interfaces on 2 different PFE's, if protocol status of one AE member interface goes down (mBFD Down or disabling lacp on the peer), but physical state remains Up, multicast traffic might be blackholed.
PR NumberSynopsisCategory: PFE Peer Infra
1667674The FPC might fail to initialize on Junos platforms
Product-Group=junos
On all Junos platforms, in a very corner case, the FPC (Flexible PIC Concentrators) might fail to initialize and remains in a stuck state when an FPC is installed or rebooted.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1609630BFD over GRE tunnel interface stuck in "init" state with GRES enabled
Product-Group=junos
On all JUNOS platforms, when disabling the physical interface where GRE tunnels is established and performing a GRES (Graceful Routing Engine Switchover). After GRES, enabling the physical interface will cause BFD to become stuck in init state.
PR NumberSynopsisCategory: OSPF routing protocol
1659366The memory leak and process rpd crash might be observed when the peer interface flaps continuously in the Segment Routing
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with Segment Routing, when the peer interface flaps continuously, the memory leak might be observed which might lead to the process rpd crash.
PR NumberSynopsisCategory: Issues related to PKI daemon
1642410Junos OS: SRX Series: Upon processing of a genuine packet the pkid process will crash during CMPv2 auto-re-enrollment (CVE-2022-22218)
Product-Group=junos
On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS) by crashing the pkid process. Please refer to https://kb.juniper.net/JSA69901 [juniper.net] for more information.
PR NumberSynopsisCategory: QFX L2 PFE
1649637The local-minimum-links feature not working as expected on QFX5100 VC platforms
Product-Group=junos
On the QFX5100 VC(Virtual-Chassis) platform, the AE(Aggregated Ethernet) interface might not go down on a single interface flap in the bundle even though the knob "local-minimum-links" is configured on the device.
1660787CoS might not get applied on VC ports
Product-Group=junosvae
CoS configs are not getting applied on vcp port in QFX5100 VC.
1676772VLAN translation mapping gets deleted when one of the member interface removed from LAG
Product-Group=junos
On all QFX5k, EX4650 and EX4600 platforms, if port has VLAN translation configuration and LAG interfaces connected on same FPC then incoming traffic can drop if one member of LAG interface is deleted/removed.
PR NumberSynopsisCategory: Related to sw defects for K2-RE
1662913The watchdog timeout is encountered and the system reboots after the 'request system halt' command executed
Product-Group=junos
On all platforms with RE-1800 & RE-2000, after the 'request system halt' command is executed, the watchdog timeout is encountered and causes the routing engine (RE) to fail to boot.
PR NumberSynopsisCategory: RPD policy options
1666001ACX5448-D policy with install-nexthop, called in forwarding-table will not install next-hops properly with respect to the routing table
Product-Group=junos
ACX5448-D fails to install the next hop when a next-hop policy is configured in the forwarding table.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1593821Fabric errors will be generated after swapping MPC10E with MPC7E in the same slot
Product-Group=junos
In MX240/MX480/MX960 routers with SCB3E scenario, if MPC7E is swapped with MPC10E in the same slot or the MPC10E is inserted into an empty slot, the fabric link-training for the line-card impacted will failure and fabric links will not come up. This will cause not be able to send traffic over fabric.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1674585The 'kmd' process may crash due to SA re-negotiation failure during IKE phase-1
Product-Group=junos
On platforms running Junos 16.2 onwards releases, if for some reason IKE (Internet Key Exchange) phase-1 SA (Security Association) re-keying fails, 'kmd' process may crash and the IPSec (Internet Protocol Security) tunnels may also get torn down. Most of the time, the reason is that the initiator changes its offerings after the initial successful key exchange.
PR NumberSynopsisCategory: security-intelligence feature on SRX
1638923Kernel panic might be seen during boot
Product-Group=junos
On Junos platforms kernel panic might be seen during the boot sequence.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1673176"gethostbyname: Host name lookup failure" is displayed during commit
Product-Group=junos
On all SRX Series devices with J-Web enabled, "gethostbyname: Host name lookup failure" is displayed during commit. This issue is a display issue and doesn't have any service impact.
PR NumberSynopsisCategory: PTX/QFX100002/8/16 Fabric software
161594290% traffic got dropped when the number of Switch Interface Board (SIB) plane is reduced from 4 to 3 on PTX10008 and PTX10016
Product-Group=junos
On PTX10008 and PTX10016 routers, when the number of Switch Interface Board (SIB) planes is reduced from 4 to 3, traffic might drop by 90%.
PR NumberSynopsisCategory: MX10K platform
1628050MX10008 - Commit fail seen while testing family mpls filter is configured with ip-version match.
Product-Group=junos
MX10008 - firewall filter "set firewall family mpls filter term from ip-version ipv4 destination-address ..." does not work on the MX10008 or MX10016. Using such configuration causes a commit error.
 
 

19.3R3-S7 - List of Known issues

PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1243146PFE with delegated non-inline BFD sessions may cause these BFD sessions to flap
Product-Group=junos
MX/PTX routers running Junos 15.1 or later with non-inline delegated BFD sessions such as microBFD are susceptible to BFD session flaps. The flaps are seen due to intensive RE - PFE traffic or additional threads causing PPM Data thread (especially with auth as it requires more intensive processing) starvation
PR NumberSynopsisCategory: Border Gateway Protocol
1635339BGP multipath computation for the prefix may cause the rpd to crash
Product-Group=junos
On all Junos and Junos Evolved platforms, rpd (routing processor daemon) crash can be seen when there is a computation of the BGP (Border Gateway Protocol) multipath prefix. This is a rare timing issue which is observed only when BGP multipath is configured with list-nexthop and there is a peer cleanup and re-establishment. There might be a service impact because of the rpd crash, however, the system recovers to functional state by itself.
PR NumberSynopsisCategory: QFX52xx platforms Interface running EVO
1545455The chip on FPC line card might crash when the system reboots.
Product-Group=junos
On the FPCs with Broadcom chip, if the jinsightD (health-mon) is not disabled ("set system processes health-mon disable"), the FPC might crash during the system booting. Traffic loss is seen during the FPC crash and restart.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1657659Junos OS Evolved: PTX Series: Multiple FPCs become unreachable due to continuous polling of specific SNMP OID (CVE-2022-22211)
Product-Group=junos
A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows an unprivileged attacker to cause Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69916 [juniper.net] for more information.
PR NumberSynopsisCategory: Control Plane for Node Virtualization
1685453Service impact is seen when all the PICs on the GNF failed to come online after a chassisd restart
Product-Group=junos
On MX platforms supporting node-slicing (MX480, MX960, MX2010, MX2020 & MX2008) have an issue that when GNF (Guest Network Function) chassisd restarts, the FPC doesn't restart as expected which causes the PIC (Physical Interface Card) to be offline.
PR NumberSynopsisCategory: EVPN control plane issues
1600310Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance
Product-Group=junos
When using the logical tunnel (lt-) interface to stitch EVPN-MPLS and EVPN-VxLAN, bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. This is due to the AD (Auto-Discovery) route per ESI with VxLAN encapsulation community which is ignored on MPLS routing instance.
PR NumberSynopsisCategory: IDP policy
1657056The flowd core might be observed when IDP policy rulebase changes
Product-Group=junos
A change in IDP lsys policy configuration while the system is processing traffic may cause a flowd coredump in rare cases.
PR NumberSynopsisCategory: LSQ
1258258Out-of-sequence packets are seen with the LSQ interface.
Product-Group=junos
Out-of-sequence packets are seen with the LSQ interface.
PR NumberSynopsisCategory: Kernel Multicast Infrastructure
1653920Traffic blackhole might be seen due to next-hop install failure on Junos PTX platforms
Product-Group=junos
On Junos PTX platforms there might be a traffic blackhole which happens because of next-hop installation failure for multicast RSVP(Resource Reservation Protocol) P2MP(Point to Multipoint) traffic. This issue might only be encountered in a scaled RSVP P2MP environment after a network event which might cause reconvergence.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1676912IS-IS packet drop observed for packets having GRE over FTI-VXLAN header
Product-Group=junos
All Junos platforms face the issue of IS-IS (Intermediate System-to-Intermediate System) packet drop where the packet headers are GRE (Generic routing encapsulation) over FTI-VXLAN (Flexible Tunnel Interface-Virtual Extensible LAN). Such packets are dropped at sender side kernel in the egress direction due to incorrect handling.
PR NumberSynopsisCategory: Express Chip L3 software
1540793The Packet Forwarding Engine might crash due to NH memory exhaustion with unicast next hop changes.
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, unicast next hop memory is not freed after unicast next hop changes. Once memory is consumed, the Packet Forwarding Engine might crash.
PR NumberSynopsisCategory: Path computation client daemon
1675816In a rare case, 'pccd' will crash when the PCEP connection is down
Product-Group=junos
On all Junos and Junos Evolved platforms, on the intermediate device when connection towards Path Computation Element (PCE) is down, Path Computation Element Protocol (PCEP) session will be down resulting in pccd crash. Routing protocols are not impacted but pccd crashes.
PR NumberSynopsisCategory: Protocol Independant Multicast
1676154The rpd crash can be seen in MoFRR scenario
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd ( routing protocol daemon) can crash when PIM (Protocol Independent Multicast), MoFRR (Multicast only Fast Reroute) configuration is present and some network churn event such as continuous interface cost changes, resulting in a change of active and backup paths for ECMP (Equal Cost Multi-Path) happens. There will be service impact because of the rpd crash but the system self-recovers until the next crash.
PR NumberSynopsisCategory: Related to sw defects for K2-RE
1669892USB installation package loads with 32-bit smartd binary version
Product-Group=junos
When 64-bit image had been installed from USB image, the smartd binary points to 32-bit version.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1501624Memory corruption might happen if SSL proxy is enabled on SRX platforms
Product-Group=junos
On all SRX platforms, if Secure Sockets Layer (SSL) proxy is enabled, when the device is running low on memory, there might be invalid free for certificate cache which will result in memory corruption and random cores.
PR NumberSynopsisCategory: MX10002 Platform SW - Platform s/w defects
1631010,The FPC might crash after enabling MACsec
Product-Group=junos
On MX10003/MX2K with MPC8/9 line cards/PTX10001-20C/ACX6360 platforms, when MACsec (Media Access Control Security) is enabled on ports, FPC might crash with PFEMan (PFE Management) core, which would impact the related traffic. However, the issue could be self-recovered. The issue could be very rare.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1559174,Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11, PTX10003, PTX10008: Line card may crash and restart when traffic is hitting a firewall filter having a term with syslog action configured (CVE-2021-0264)
Product-Group=junos
A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card to crash and restart, creating a Denial of Service (DoS). Continued receipt and processing of packets matching the firewall filter can create a sustained Denial of Service (DoS) condition. Please refer to https://kb.juniper.net/JSA11155 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1570676When traffic towards client gets fragmented PPP/LNS Radius downlink accounting inaccurate with peer LCP negotiated MRU.
Product-Group=junos
When traffic towards client gets fragmented PPP/LNS Radius downlink accounting inaccurate. As of now this is unsupported.
PR NumberSynopsisCategory: PTX/QFX100002/8/16 Fabric software
161594290% traffic got dropped when the number of Switch Interface Board (SIB) plane is reduced from 4 to 3 on PTX10008 and PTX10016
Product-Group=junosvae
On PTX10008 and PTX10016 routers, when the number of Switch Interface Board (SIB) planes is reduced from 4 to 3, traffic might drop by 90%.
PR NumberSynopsisCategory: Xellent Platform issues
1568294Another port will also be shutdown after shutting down one port on PTX10002-60C/QFX10002-60C
Product-Group=junos
On PTX10002-60C/QFX10002-60C platform, after disabling the standalone/non-channelized port (e.g. port 6, 16,26,36,46,56), then another port on that port group will aslo be disabled. For example, disable et-0/0/36, port et-0/0/30 is going to down as well. This issue is only exposed when using DAC cables.

Modification History

First Publication 2022-10-26

Related Information

Software Release Notification workflow