Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 23.2R1-S1 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 23.2R1-S1 is now available.

23.2R1-S1 - List of Fixed issues 

PR NumberSynopsisCategory: NFX Series Platform Software
1756270nfx-3: non-root user is unable to access vnf through ssh, telnet and console
Product-Group=junos
nfx-3: non-root user is unable to access vnf through ssh, telnet and console
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1735843Crash on all Junos VMhost platforms due to deadlock panic
Product-Group=junosvae
On all Junos VMhost based platforms, due to heavy disk input/output (I/O) operations, a crash was observed.
PR NumberSynopsisCategory: A15 specific issue
1738188Failover can be seen on SRX5K cluster with SPC2 cards while executing RSI
Product-Group=junos
On all SRX5000 series platforms with SPC2 cards configured in a chassis cluster, when RSI is being collected which has the command 'i2csc fpc' in the script, an interrupt storm generates a CB (Control Board) alarm which triggers a failover. Intermittent traffic disruption could be seen till the failover is complete.
PR NumberSynopsisCategory: Border Gateway Protocol
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.
PR NumberSynopsisCategory: MX304 line card platform software
1739718Incomplete FPC Firmware details will be displayed
Product-Group=junos
On MX304 and MX platforms with MPC11 and LC9600, the CLI command 'show system firmware' may sometimes not display all the firmware details of FPC components. This prevents the FPC firmware components from being upgraded to the latest version when the firmware upgrade is performed.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Device Configuration Daemon
1731190The lt/vt/ut interfaces may not recover from the disable-pfe (admin down) state if the GRES switchover is done before restarting FPC
Product-Group=junos
On all Junos Platforms when a PFE (Packet Forwarding Engine) gets disabled to a CM (Chassis Manager) error disable-pfe action or any other reason and a GRES (Graceful Routing Engine Switchover) happens, the lt/vt/ut (Logical Tunnel/Virtual Tunnel/Uplink Tunnel) interfaces will not recover after the FPC (Flexible PIC Concentrator) restart even though the error condition is recovered resulting in traffic loss.
1742124DCD crash can be seen sometimes while pushing config using API
Product-Group=junos
On all Junos platforms, dcd crash can be seen when interface configuration is added using API and some Junos application (such as vrrpd, jdhcpd etc) send configuration for the same interface using Overlay files. This is because, in dcd the internal data structures are not updated correctly when config source is changed from API to Overlay which eventually leads to corruption. It does not cause any service impact.
PR NumberSynopsisCategory: Firewall Filter
PR NumberSynopsisCategory: CoS support on DNX
1732124EVPN instance traffic will be dropped when hierarchical-scheduler is enabled on the CE interface
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, in the EVPN scenario traffic will be disrupted if hierarchical-scheduler is enabled on the (Customer Edge) CE-facing interface.
PR NumberSynopsisCategory: AF interface in Node Virtualization
1724734Offline and online of GNF fabric planes impacts traffic forwarding
Product-Group=junos
In Junos node slicing scenario, offline of fabric planes causes the fabric probe to stop. For AF(Abstracted Fabric) interfaces, which are logical WAN interfaces over fabric for the GNFs to communicate, the fabric probe stop is used as a trigger to disable PFE so that the AF liveness mask is maintained at value before the probe stopped. This results in the subsequent online of planes to be not processed resulting in the ping drop and traffic impact.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1740561Traffic loss is seen due to anomalies after the recreation of IFLs
Product-Group=junos
On all Junos Evolved Platforms, in the EVPN-VXLAN DCI (Data center Interconnect) scenario, traffic loss is seen due to anomalies when any catastrophic interface change is done which results in the IFL (logical interface) deletion and recreation by the system.
PR NumberSynopsisCategory: Configd, ffp issues
1743038Commit confirm and commit race condition crashes the firewall functionality
Product-Group=junos
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1752374Subsequent commits hang will be seen, when transfer-on-commit fails
Product-Group=junos
On all Junos Evolved platforms, When transfer-on-commit is configured and it fails as the destination is unreachable or invalid, commit lock taken by automatic rollback commit is not released. Due to this, subsequent commits result in a hung state.
PR NumberSynopsisCategory: EX4400 PFE software
1732271Filter term dropping VRRP traffic when "then log" is configured
Product-Group=junos
On all Junos platforms, VRRP (Virtual Router Redundancy Protocol) packet goes to a wrong CPU queue when filter is added to match VRRP packet with "then log" action, resulting in VRRP functionality impact.
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1739559SRX4100/4200 accepts the datapath-debug configuration although it does not support it
Product-Group=junos
It is possible to set and commit the datapath-debug configuration on platforms SRX4100/SRX4200 although datapath debugging is not supported on those platforms. because of this unsupported configuration being accepted the RE (Routing Engine) load can go high and cause traffic outage. The workaround is to remove the datapath-debug configuration and perform a commit.
PR NumberSynopsisCategory: Signature Database
1741887Multiple network issues are seen after the upgrade with lower IDP packet-log total-memory percentage
Product-Group=junos
On Junos SRX platforms, before the upgrade, if the IDP 'packet-log total-memory percentage/packet-log max-sessions' is configured lower than the default value of 10% then while upgrading, the boot time commit will fail and the device will go to an amnesiac state causing multiple issues.
PR NumberSynopsisCategory: ISIS routing protocol
1748223JVD-SP-METRO: Multi-instance isis route leaking for inet.3 is not working as expected
Product-Group=junos
It is observed, that when flex-algo SID's are leaked into default IS-IS instance, we clear the E-Flag while leaking (as expected), whereas when default-algo sid is leaked into default/core IS-IS instance, we don't clear the E-Flag. This is not expected
PR NumberSynopsisCategory: jdhcpd daemon
1731784Dhcp security bindings may not happen when DHCP security is enabled on multiple vlans along with dhcp stateless relay
Product-Group=junos
When DHCP security is enabled on multiple vlans along with dhcp stateless relay enabled at that time, dhcp security bindings may not happen.
PR NumberSynopsisCategory: JFlow bug tracker for SRX platforms
1716707J-flow sends wrong IP in sampling records when NAT is configured for traffic along with input sampling
Product-Group=junos
When NAT (Network Address Translation) is configured on interfaces along with sampling, the J-flow record will contain NAT'ed IP as opposed to the original IP.
PR NumberSynopsisCategory: Security platform jweb support
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
1738316JWEB: Certificate Management issues.
Product-Group=junos
JWEB: Device Administration > Certificate Management is not working as expected unable to create device certificate of types Local Self-Signed, SCEP, CMPv2 or CSR with J-Web interface Unable to delete the CA certificate On re-enrolling the local certificate via jweb, page shows re-enrollment failed though it has actually worked in device User has to use CLI to create/ delete/ re-enroll certificates: https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-configuring-ca-and-local-certificates.html
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1733543Traffic loss is seen when "lacp force-up" knob is configured
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic destined to the core is getting dropped when "lacp force-up" knob is configured on ae interface under EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) scenario.
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
1750146IRB state change not working correctly on local-remote option
Product-Group=junos
When IRB state change knob configured to compute IRB interface state based on local-remote interfaces, due to L2 interface state incorrect, IRB state computation may not be correct.
1754493"set services evpn global-parameters virtual-gateway v6-mac" is broken
Product-Group=junos
When "global-parameters virtual-gateway v4-mac" or "global-parameters virtual-gateway v6-mac" independently set, the commit fails. This PR address this issue.
PR NumberSynopsisCategory: Express Chip L3 software
1743978GRE over IPv6 will not work resulting in traffic impact post-upgrading the device
Product-Group=junos
On QFX10002-60C platform, GRE (Generic routing encapsulation) for IPv6 will not work resulting in traffic impact due to software issues post-upgrading the device from 20.x release or lower to 21.3x release or higher.
PR NumberSynopsisCategory: QFX PFE Class of Services
1726124The class of service subsystem crashed after the device is restarted or the switchover is performed
Product-Group=junos
On Junos QFX5100 and QFX5110 platforms in virtual chassis, the cosd crash is observed when the GRES (Graceful Routing Engine Switchover) is performed or the device is restarted, due to which the Class of Service (CoS) functionality will not work. It is a rare issue.
PR NumberSynopsisCategory: QFX L2 PFE
1741316The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
1743083QFX52XX: check loop detect fails after Restart L2ald
Product-Group=junos
Loop detect functionality will not work on QFX52XX platform.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1721297FPC crash on QFX5120-48Y
Product-Group=junos
If we observe any slowness in accessing the VTY and could see any hogging/scheduler slip messages in syslog. It is advised to run the debug commands manually, instead of running it via RSI.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1742147Memory leak observed when reconfiguring the flow routes
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if the nexthop of a flow route is the same as it was before when reconfiguring flow routes, memory leak occurs. High memory use of routing process daemon(rpd) is seen as a result of this leak. A kernel out of memory message is observed which results BGP flap.
PR NumberSynopsisCategory: SRX Argon module
1737442Intermittent core-dumps is received when SMB protocol is enabled on AAMW policy and PFE memory is exhausted
Product-Group=junos
On SRX platforms, When Server Message Block(SMB) protocol is enabled on advanced anti-malware(AAMW) policy and PFE memory is exhausted in that condition, SMB and SMTP is calling the same fallback API results high memory utilization. There are two types of cores is generated one is from AAMW plugin and the other is from DNS plugin. Both of them are because memory is exhausted and these high memory utilization can cause PFE process crash which results network outage for a while.
PR NumberSynopsisCategory: SRX branch platforms
1729959"show system firmware" shows available version as 0 after upgrading to BSD12 image
Product-Group=junos
The cli command "show system firmware" doesn't show available bios versions in bsd12 for branch SRX devices. The issue is because the uboot binary file path is different in bsd12. This issue is fixed but however will not be a part of the twig : JUNOS_232_R1_BRANCH.
1739219with multiple reboot srx300 going into panic: sleeping thread
Product-Group=junos
This is a corner case. Yet to be root-caused. But the chance of repro is quite rare.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1736965AR:Firewall: PFE wedged , while switching from SW-SEG-FLT -> FLT -> SW-SEG-FLT filter
Product-Group=junos
Filters marked with fast-lookup-filter knob terms shall not be added more than 256 terms in the existing filter with less than 256 terms. Instead, create a new filter if required more than 256 terms in the same filter and replace the filter in the same commit.
1743930Traffic drop is observed after the addition or removal of the "filter-specific" knob under the policer
Product-Group=junos
On MX platforms with MPC10, MPC11 and JNP10K-LC9600 linecards, when both regular & hierarchical/tricolor policer is configured on the logical interface (ifl), after the addition or removal of "filter-specific" knob under this combination of policer traffic drop is observed.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1721404MFT : "no-reduced-srh" SRV6 encap mode is not working as expected on MX304.
Product-Group=junos
With no-reduced-srh configured, MX304 removes the last SID value from the SRH. Expectation is Last SID should be retained in SRH when "no-reduced-srh" is configured. There is no impact to the traffic. Traffic flow fine, since the "SEGMENT-LIST" and "LAST ENTRY" are encoded properly in the packet.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1742123Inline-monitoring will not work as expected when more than one instances are configured
Product-Group=junos
On all Junos MX and EX9200 platforms, when more than one instances of the "inline-monitoring" service are placed under firewall filter, all prefixes point to the firewall filter first term regardless of the match condition which results in inline-monitoring not working as expected.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1731564VPLS traffic gets blackholed by qualified-bum-pruning mode
Product-Group=junos
On all MX and EX9K platforms, qualified-bum-pruning-mode completely blackholes VPLS (Virtual Private LAN Service) traffic with network-services configured in enhanced-ip mode.
1736667Intermittent flooding of traffic every 40 sec
Product-Group=junos
On MX/EX92K Junos platforms with line cards running MPC families up to MPC9, Layer2 unicast traffic flow sent on FPC where Pseudowire Subscriber Interfaces (PS interface) is not anchored and the packet contains DMAC as one of the MACs learned behind that PS IFL. Packets with DMAC as that of the Mac learned behind PS IFL is getting flooded from the FPCs where PS IFL is not anchored every 40sec. The impact is that every 40sec traffic sent towards a known MAC will be flooded as this destination MAC was unknown. This traffic shouldn't be flooded arriving at incorrect destinations.
PR NumberSynopsisCategory: Ephemeral Database
1732379MGD core found @ db_commit_ephemeral xml_commit jsop_commit
Product-Group=junos
When MGD opens the ephemeral database in the merge view. Upon completion, if the merge_view is closed, and the candidate ephemeral database is reopened. If MGD can not find the underlying database the MGD process dumps its core.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289The 'load replace' operation might result in mustd and mgd crash
Product-Group=junos
On Junos and Junos Evolved platforms with apply-group configured, mustd and mgd crash might be observed when the 'load replace' operation is performed due to which all the apply-groups will get deleted internally, and respective hierarchies will not be notified.
1745565The mgd process crash is observed when 'show' is executed from the configuration mode
Product-Group=junos
On all Junos platforms, when 'show' is executed from the configuration mode, a mgd process crash is observed which has no functionality impact.
PR NumberSynopsisCategory: Issues related to XML, JSON handling
1736286OpenConfig data obtained with gNMI GetRequest in json format displays module prefix
Product-Group=junos
When OpenConfig data is queried using using gnmi GetRequest in json format, appropriate module prefixes will get displayed for the first container object from the respective module.
 
 

23.2R1-S1 - List of Known issues 

PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1735843Crash on all Junos VMhost platforms due to deadlock panic
Product-Group=junos
On all Junos VMhost based platforms, due to heavy disk input/output (I/O) operations, a crash was observed.

Resolved In: junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1692769[NPI Templeton] [Supportability] - Macros for EVPN/VXLAN traces
Product-Group=junos
CVBC PR 1751073 created to track it. The release note to be updated accordingly

Resolved In: evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1730927PDT:Google: DCPFE core found during AE flap test on PTX1k
Product-Group=junos
During heavy network churn (interface flaps, session flaps etc.) PFE crash may be seen when streaming both SR and SRTE stats on PTX JUNOS platforms. Issue is not seen when only SR stats or SRTE stats are enabled.

Resolved In: 
PR NumberSynopsisCategory: User Firewall related issues
174558823.2: Add FQDN-name counter in the show services user-identification identity-management status output
Product-Group=junos
Adding the missing "FQDN-name" counter to the "show services user-identification identify-management status"

Resolved In: junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1691036NTP time drift
Product-Group=junos
NTP time drift on the affected Junos releases. Earlier implementation of kvmclock with vDSO (virtual Dynamic Shared Object) which helps avoid the system call overhead for user space applications had problem of time drift, the latest set of changes takes care of initializing the clock after all auxiliary processors are launched so that the clock initialization is accurate.

Resolved In: junos:23.1R2 junos:23.3R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1700462mspmand crashes after loading a new image
Product-Group=junos
Once the device is loaded with the new image, PIC tries to boot up. mspmand is one of the processes inside PIC, crashes sometimes

Resolved In: 
PR NumberSynopsisCategory: SRX branch platforms
1732378flowd-octeon.elf.core was seen rarely in srx380 cluster
Product-Group=junos
The flowd core is seen very rarely where we see PCIe parameters are 0 during the initialization. The RCA is yet to be ascertained

Resolved In: 
1739202Branch SRX devices WD resets rarely if booted with USB stick
Product-Group=junos
Use `gpart commit da0` to save changes or `gpart undo da0` to revert them. GEOM_PART: integrity check failed (da0, MBR) g_access(961): provider diskid/DISK-6385731155800547948 has error 6 set The error logs following which there is a watchdog reset is caused because of the operation on the USB disk due to usbautoinstall script during the start-up, the issue can be avoided by not having USB pen drive connected to the device during the start-up. The issue shall be fixed in 23.2R1-S1 and 23.2R2

Resolved In: junos:23.2R2
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1703062Dynamic Vxlan (PIM based) Traffic convergence takes a little longer post ISSU.
Product-Group=junos
On MX platforms (with ukern based FPCs), dynamic VxLAN (PIM based) traffic convergence takes a little longer post ISSU.

Resolved In: 
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1718893There are some BGP peers that remain down due to a firewall filter attached to the interface lo0
Product-Group=junos
On specific line cards and devices, fast-lookup-filter is not working on the router's loopback interface. Some BGP peers remain down with a firewall filter attached to the lo0 interface.

Resolved In: junos:20.3X75-D46

 

Modification History

First Publication 2023-09-15