Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX PTX QFX platforms running Junos Evolved Software
Alert Description
Junos Software Service Release version 22.3R2-S2-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 22.3R2-S2-EVO is now available.
22.3R2-S2-EVO - List of Fixed issues
PR Number
Synopsis
Category: MX YT-ZF Linecards Interface Software Category
1706517
Delay in an interface on LC9600 to come up due to repeated flaps
Product-Group=evo
There is a delay in an interface on LC9600 to come up sometimes due to SerDes re-initing triggered by repeating flaps. Each plane is made of one or several Fabric ASICs (Application-Specific Integrated Circuits). The Fabric ASIC is connected to all the PFE (Packet Forwarding Engine) with dedicated links called SerDes. The issue caused a delay in turning up the link from 30 seconds to 80 seconds depending on if the link partner undergoes the same delay. Traffic will not pass on the port until the link is up again.
PR Number
Synopsis
Category: Border Gateway Protocol
1696870
BGP scheduler slips during sub-optimal prefix-walk while deleting selected prefixes from a large set.
Product-Group=evo
On all Junos and Junos Evolved platforms, you might see the BGP scheduler slip while deleting a large set of prefixes.
1739919
Junos OS and Junos OS Evolved: A BGP session will flap upon receipt of a specific, optional transitive attribute (CVE-2023-0026)
Product-Group=evo
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71542
[juniper.net]
for more details.
PR Number
Synopsis
Category: BGP Openconfig and Sensor
1714087
Traffic loss is seen on telemetry streaming in BGP sharding environment
Product-Group=evo
On all Junos and Junos Evolved platforms RPD core is seen on telemetry streaming with BGP sharding enabled.
PR Number
Synopsis
Category: PFE L2 forwarding features on BT based platforms
1736699
Evolved is using old MAC address for forwarding leading to traffic drops
Product-Group=evo
On Junos Evolved platforms with VXLAN (Virtual Extensible LAN) configuration, traffic drops because the ICMP (Internet Control Message Protocol) response is going with old/stale MAC (Media Access Control) address.
PR Number
Synopsis
Category: VPWS, L2 CKT, EVPN-VPWS
1722270
Occasional FPC crash and traffic loss is observed with a scaled number of FIB routes
Product-Group=evo
When there are four thousand routes or more on the forwarding table of the PFE (Packet Forwarding Engine) and when interface adds and deletes are being executed it leads to FPC (Flexible PIC Concentrator) crash and traffic loss.
PR Number
Synopsis
Category: Ethernet OAM (LFM)
1714149
Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet (CVE-2023-36848)
Product-Group=evo
An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (ppmd) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11, and LC9600) allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA71659
[juniper.net]
for more information.
PR Number
Synopsis
Category: Application controller related issues
PR Number
Synopsis
Category: EVO linux defects & enhancement requests
1719603
EVO devices may lose remote access in certain scenarios
Product-Group=evo
In Junos OS Evolved, the xinetd config file was not updated correctly. This could lead to a situation where external login services (such as SSH, NETCONF over SSH, or Telnet) were not accessible. Due to a software defect, an internal function deleted the files required for SSH based services, eg "xinetd-external.conf". Thus services like SSH or Netconf will stop working In some cases when a box was booting, the "xinetd-external.service" came up before the initial boot-time MGD commit would create the file. This caused the service to come up without a config file. Since remote login over may be disabled: SSH Telnet NETCONF over SSH NETCONF over TLS so you may need to log in via the serial console. Following error will be observed in the system: xinetd[6588]: open( /etc/xinetd-external.conf ) failed: No such file or directory (errno = 2) xinetd[6588]: 6588 {init_services} couldn't get configuration. Exiting... xinetd[7537]: xinetd Version 2.3.15 started with libwrap options compiled in. xinetd[7537]: Started working: 2 available services
PR Number
Synopsis
Category: Configd, ffp issues
1743038
Commit confirm and commit race condition crashes the firewall functionality
Product-Group=evo
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.
PR Number
Synopsis
Category: OSPF routing protocol
1702456
Junos prefers SRMS advertised label over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix
Product-Group=evo
On all Junos and Junos Evolved platforms, when IPv4 prefix advertisement received by an IS-IS/OSPF router in the Extended IP reachability TLV and SR mapping server (SRMS) advertisement for the same prefix received through the segment identifier (SID) label Binding TLV, then SRMS advertised label preferred over IS-IS/OSPF SID label advertised via opaque-AS Extended-Prefix. Traffic will be sent via wrong path due to this issue.
1732500
The adjacent PE Node SID label will drop from routing table when MicroLoop-Avoidance is enabled in OSPF-SR
Product-Group=evo
On all Junos and Junos OS Evolved platforms when OSPF MicroLoop-Avoidance(MLA) is enabled on Segment Routing(SR) speaking node connected to LDP speaking node and this same SR node has to do SR-LDP stitching, the LDP route on the LDP facing interface will be withdrawn and eventually withdraws the node SID label if there has either LDP speaking node facing link flapping or the rpd is restarted.
PR Number
Synopsis
Category: RPD route tables, resolver, routing instances, static routes
1716153
Multipath route is not getting compute and skip the multipath eligibility check
Product-Group=evo
On all Junos platforms, multipath route will not be formed correctly when a BGP route is received from RR (Route Reflector) and preference decided based on cluster list length.
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1693630
In JUNOS EVO "show | display inheritance" does not work correctly for LSPs with whitespace in the name
Product-Group=evo
An LSP with whitespace in the name does not display correctly when viewing the configuration using 'show | display inheritance'
1730336
The rpd crashes and the commit operation fails while pushing a large configuration with the "extend-size" knob enabled
Product-Group=evo
On all Junos platforms, when the 'extend-size' knob is configured and a scaled configuration is committed, the rpd daemon crash is seen and the commit operation fails.
1745565
The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=evo
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR Number
Synopsis
Category: Issues related to NETCONF
1585855
< ok/> response is getting generated along with < rpc-error>
Product-Group=evo
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.
PR Number
Synopsis
Category: ACX724 interfaces/optics issues
1733956
Getting False Alarm "Optics does not support configured speed" for 1G SFP-LX
Product-Group=evo
The system is triggering a false alarm when SFP-LX is used and the interface speed is configured 1G.
22.3R2-S2-EVO - List of Known issues
PR Number
Synopsis
Category: AFT l2lam
1722102
QFX5130 EVO vxlan: QFX5130 always sends NS(Neighbor Solicitation) with link local address
Product-Group=evo
On QFX platform series which is working on EVO and vxlan function, it sends IPv6 NS(Neighbor Solicitation) with link local address even through target IP is global address.
Resolved In:
evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.1R2 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR Number
Synopsis
Category: MX304 Routing Engine issues
1686577
New CLI commands addition to support RE and Chassis power-cycle
Product-Group=evo
New CLI commands addition to support RE and Chassis power-cycle under request vmhost hierarchy. These are the "request vmhost power-cycle-re", and "request vmhost power-cycle-cb".
Resolved In:
evo:22.3R3-EVO evo:22.3X50-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:22.3R2-S1 junos:22.3R3 junos:22.4R1-S2 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1
PR Number
Synopsis
Category: DNX L2 related features
1745163
On ACX7K routers traffic may get affected on interface using ethernet-switching interface-mode trunk due to incorrect DEI marking.
Product-Group=evo
On ACX7K routers traffic may get affected on interface using ethernet-switching interface-mode trunk due to incorrect DEI marking.
Resolved In:
evo:22.3R3-S1-EVO evo:22.4R2-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO
PR Number
Synopsis
Category: DNX Multicast
1705680
The transit Multicast traffic is getting dropped on Junos Evolved ACX platforms
Product-Group=evo
On Junos Evolved ACX platforms configured with a Firewall filter on the Loopback(lo0) interface and Multicast enabled, the transit Multicast traffic is getting punted to the Central Processing Unit(CPU) and gets dropped. It has a service impact.
Resolved In:
evo:22.2R3-EVO evo:22.3R3-EVO evo:22.4R1-S1-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO
PR Number
Synopsis
Category: ACX IFL, IFF creation
1742712
ACX7100 with 400G FR Optics may see Corrected FEC Errors
Product-Group=evo
ACX7100 with 400G FR Optics may see Corrected FEC Errors. The errors are normal and do not indicate any issue with the optics or the fiber.
Resolved In:
PR Number
Synopsis
Category: Gnats category for dynamic rendering infrastructure
1681777
Invalid XML output can be seen for RPC get response
Product-Group=evo
If the configured data has special characters in it, then rpc get output will not escape these special characters and display the data as it is. For example, if we have configured qos class as , then ---- > the response should have default as response value .
Resolved In:
evo:21.4R3-S4-EVO evo:22.2R2-J6-EVO evo:22.2R2-S2-J2-EVO evo:22.3R2-S1-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.4R1-EVO evo:23.1R1-EVO junos:21.2R3-S5 junos:21.2X32-D20 junos:21.4R3-S4 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R1 junos:23.1R1
PR Number
Synopsis
Category: EVO L2 Control Plane PRs
1705712
Traffic loss would be seen as prefix gets stuck in Hold state
Product-Group=evo
On Junos OS Evolved platforms with EVPN-VXLAN (Ethernet VPN Virtual Extensible LANs) feature, traffic loss would be observed as host prefix gets stuck in Hold state due to any network event which causes the route to delete and add in a quick succession.
Resolved In:
evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R2 junos:23.1R1 junos:23.2R1
PR Number
Synopsis
Category: mgd, ddl, odl infra issues
1703745
The system won't come up in a working state post reboot for upgrade validation fails to detect invalid host-name
Product-Group=evo
On all Junos Evolved platforms, running with Junos Evolved OS image prior to 22.1R1-EVO and if it is having the system host-name configured with an underscore then when upgrading the system to a Junos Evolved OS image 22.1R1-EVO or higher, config validation does not detect the invalid host-name with an underscore and validation will pass, but post reboot service mgd-init-service will fail to come up, due to which upgrade will fail and as a result system won't come up in a working state.
Resolved In:
evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:22.4R3 junos:23.1R1 junos:23.2R1
PR Number
Synopsis
Category: PTX10K Diagnostics related PRs
1725658
Enabling Cell BIST Support for LC1201 and LC1202 new HBM components
Product-Group=evo
With the new HBM component, a software upgrade is needed to support the new hardware for the LC1201, LC1202. (See
TSB71797
[juniper.net]
)
Resolved In:
evo:22.1R3-S3-EVO evo:22.2R3-S1-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1638847
The mustd process crash might be observed with persist-group-inheritance
Product-Group=evo
On all Junos and Junos Evolved platforms configured with persist-group-inheritance, which is enabled by default from 19.4R3 onwards, might lead to mustd process crash in highly scaled configuration.
Resolved In:
evo:22.3X50-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:20.3X75-D52 junos:20.4R3-S8 junos:21.2R3-S6 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1-S1 junos:23.1R2 junos:23.2R1
Modification History
First publication 2023-09-05
22.3R2-S2-EVO: Software Release Notification for JUNOS Evoled Software