Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved Software

Alert Description

Junos Software Service Release version 22.4R2-S2-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 22.4R2-S2-EVO is now available.

22.4R2-S2-EVO - List of Fixed issues 

PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=evo
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1741712Traffic loss would be seen for host generated traffic from QFX5130 and QFX5700 platforms
Product-Group=evo
On QFX5130 and QFX5700 platforms on LAG(Link Aggregation Group) interfaces with flexible-vlan-tagging enabled and extended-vlan-bridge and native-vlan-id configuration, traffic towards host would be sent out untagged to both native VLAN and non-native VLAN.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1736699Evolved is using old MAC address for forwarding leading to traffic drops
Product-Group=evo
On Junos Evolved platforms with VXLAN (Virtual Extensible LAN) configuration, traffic drops because the ICMP (Internet Control Message Protocol) response is going with old/stale MAC (Media Access Control) address.
PR NumberSynopsisCategory: DNX L2 related features
1745163Traffic loss observed on interface using ethernet-switching interface-mode trunk
Product-Group=evo
On Junos Evolved ACX7K routers, IRB (Integrated routing and bridging) traffic loss is observed on interface using ethernet-switching interface-mode trunk due to incorrect DEI (Drop Eligible Indicator) marking.
PR NumberSynopsisCategory: ACX MC-LAG Infrastructure
1752859Connectivity is lost when VLANs are removed on ACX Evolved platform
Product-Group=evo
On ACX Evolved platforms , connectivity is lost in DC style configuration with Multichassis link aggregation groups (MC-LAGs), when one of the vlan member is removed from Bridge Domains (BDs), it can create packet source duplication for all Bridge Domains .
PR NumberSynopsisCategory: DNX Multicast
1742792Transient Multicast traffic drop on ACX Evolved device
Product-Group=evo
Junos Evolved ACX Series devices does not allow transient multicast traffic to pass through due to Lo0 filter. Another filter rule needs to be added in order to allow multicast traffic.
PR NumberSynopsisCategory: DNX platform MPLS FRR features
1739112MPLS Tunnel creation failure is observed post continuous Network / Route churn / IGP flaps on Junos OS Evolved based ACX platforms
Product-Group=evo
MPLS Tunnel creation fails due to continuous Network / Route churn / IGP flaps on on Junos OS Evolved based ACX platforms. It caused by a resource exhaustion and leads to the traffic impact.
PR NumberSynopsisCategory: EVO ARP related PRs
1751006ARP dependency issue causes issue between IRB and the device
Product-Group=evo
On all Junos and Junos Evolved platforms, with integrated routing and bridging (IRB) interface with Virtual Router Redundancy Protocol (VRRP) configured, directly connected device on that IRB interface will not be able to reach the device and fails to program to PFE.
PR NumberSynopsisCategory: Issues related to EVO interface statistics.
1748236Child interfaces deleted from AE interfaces are still shown as part of AE
Product-Group=evo
On all Junos OS Evolved platforms, child interfaces deleted from AE (Aggregated Ethernet) interfaces are still shown as part of AE. This is a display issue and seen only when interface statistics for the AE interface is cleared within a few seconds of deactivating/deleting the child members. There is no impact on traffic.
PR NumberSynopsisCategory: Issues related to evo operations - libevo infra, typeinfo ..
1752267Traffic blackholes due to next-hops are stuck in the pending-delete in evo-aftmand
Product-Group=evo
On all Junos Evolved platforms, when repeated modifications are done for the routes changing next-hops, because of the non-cleanup of the previous next-hop information, next-hops are stuck in the pending-delete which leads to a traffic blackhole.
PR NumberSynopsisCategory: software upgrade infra issues
1731877Auto-sw-sync doesn't trigger upgrade/restart of routing engine
Product-Group=evo
On Junos Evolved PTX10008 and PTX10016 platforms, on releases after 21.2R1-EVO, on enabling auto-sw-sync with no user groups configuration, routing engine 1 (RE1) after joining the cluster, can not sync the versions present in master RE0.
1739286Installation of third party package on one RE and using auto-sync to add another RE into the dual RE setup may result in app not starting on the later inserting RE
Product-Group=evo
Setup is a dual-RE system where one RE is currently in use and auto-sw-sync is enabled on the running master RE. If a third-party package is now installed on the master RE and the other RE is later inserted into the system, auto-sw-sync is triggered. As part of the auto-sw-sync, the other RE may need to be rebooted to bring the current version on that RE in sync with the master. During reboot, we may occasionally hit a race condition where sysman starts first on the backup RE and tries to start third-party applications even before they get installed on the later inserted RE. This may particularly be a problem if the backup RE is switched over to be the master.
1755616automatic software synchronization mechanism doesn't function as expected
Product-Group=evo
On all Junos Evolved platforms, the auto-sw-sync mechanism doesn't function as expected. When Routing Engine is out of cluster and attempts to rejoin the cluster, synchronization fails to occur. Consequently, the current version from the master does not sync to the backup Routing Engine, resulting in new Routing Engine continuous reboot that denies access to break the cycle.
PR NumberSynopsisCategory: System Management daemon and related issues
1727524"/lib/systemd/system/docker.socket is marked executable" logs flood after system reboot
Product-Group=evo
On Evo platforms, after system reboot, "/lib/systemd/system/docker.socket is marked executable" logs flood in the messages log and stop after a few minutes.
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1718999TCP connection will be terminated when sent with incorrect MSS
Product-Group=evo
On all Junos Evolved platforms, Transmission Control Protocol (TCP) packets whose size is larger than its interface Maximum Transmission Unit (MTU) will be dropped impacting TCP connections.
PR NumberSynopsisCategory: EVO Socket replication
1736428BGP session flaps due to hold time expiration
Product-Group=evo
On all Junos Evolved platforms which supports dual RE (Routing Engine), BGP (Border Gateway Protocol) session flaps due to hold time expiration when BGP and NSR (Nonstop Active Routing) are enabled and the peers exchange routes at same time.
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=evo
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.
1713008Stale entries present in the lsdist table after ISO address change
Product-Group=evo
On all Junos and Junos OS Evolved platforms configured with IS-IS and MPLS traffic engineering database (TED), if there is an ISO address change on another Intermediate System (IS), there will be stale entries being present in the link-state distribution (lsdist) table even though they might have been deleted in IS-IS and TED. This has an impact on the routes, and thus the services, related to the stale entries present in the lsdist.
PR NumberSynopsisCategory: jdhcpd daemon
1722082DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=evo
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1727954On all Junos and Junos Evolved platforms the l2ald process memory usage is seen to increase over time
Product-Group=evo
On all Junos and Junos Evolved platforms service impact is seen due to a consistent increase in l2ald (Layer 2 Address Learning Daemon) memory usage. The extra memory is a result of tools to track memory usage added via PR1536530.
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=evo
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1727957The traffic drop is observed during the Graceful restart on Junos and Junos Evolved platforms
Product-Group=evo
On all Junos and Junos Evolved platforms, during the time of Graceful restart(GR), the routes in the Multiprotocol Label Switching(mpls).0 table will be updated even when the routing protocols are in the process of re-convergence and have not yet come out of GR. This causes inaccurate routes in the routing table and traffic drop is observed during GR.
PR NumberSynopsisCategory: RPD policy options
1706143Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=evo
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1748505The picd crash can be seen on all Junos Evolved platforms
Product-Group=evo
On all Junos Evolved platforms, picd crash can be seen when telemetry is running while FPC is coming up. It will keep all the interface down on that particular FPC.
PR NumberSynopsisCategory: PTX10K Timing/Sync-E issues tracking
1744746PTP disruption is seen as the slave goes re-acquiring on GM CC change from 7 -> 6
Product-Group=evo
On Junos Evolved platforms, when PTP (Precision Time Protocol) is configured and GM (Grand master clock) changes the clock class from 7 to 6 then the BC (Boundary clock) slave goes into the acquiring state disrupting the PTP propagation.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1737119The traffic blackhole will be observed when the SRTE shortcut is configured
Product-Group=evo
On Junos platforms, when the MPLS (Multiprotocol Label Switching) packet reaches the destination router, it will have a label that is unknown to the destination router due to a label POP operation miss at the ingress router resulting in the traffic black hole in the scenario SR-MPLS (Segment Routing With Multiprotocol Label Switching) + traffic engineering shortcut is configured.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on ZT/YT
1749946Subscribers are not coming online in new VLANs after modifying the VLANs range
Product-Group=evo
Fixed logic to update DVLAN dual tag range for same number of ranges This also fixes a logic to fix removal DVLAN dual tag topology from dual tag vlan ktree when dual tag ranges are getting updated and older ranges are getting removed.
 
 

22.4R2-S2-EVO - List of Known issues 

PR NumberSynopsisCategory: NFX Series Platform Software
1756270nfx-3: non-root user is unable to access vnf through ssh, telnet and console
Product-Group=evo
nfx-3: non-root user is unable to access vnf through ssh, telnet and console

Resolved In: evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1765344The telemetry stops streaming data when the jsd CPU utilization goes high
Product-Group=evo
On Junos and EVO platforms when it enables telemetry and uses the gRPC dial-out method, jsd might be stuck with high CPU utilization, and stop streaming data.

Resolved In: evo:22.4R2-S1-J1-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: ACX IFL, IFF creation
1662174Ipv6 transit traffic statics output is missing
Product-Group=evo
Ipv6 transit traffic statics output is missing

Resolved In:
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1743461Changing speed and adding to AE in the same commit fails
Product-Group=evo
On all Junos OS Evolved platforms, If the changing of the speed and the creation of the ae interfaces is in the same commit, the commit fails with "Interface aeX with child links of mixed speed but link-speed mixed is not configured".

Resolved In: evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EVO Netstack Juniper Tunnel Driver Module
1713989Junos OS Evolved: Packets which are not destined to the router can reach the RE (CVE-2023-44195)
Product-Group=evo
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the NetworkStack agent daemon (nsagentd) of Juniper Networks Junos OS Evolved allows an unauthenticated network based attacker to cause limited impact to the availability of the system. Please refer to https://supportportal.juniper.net/JSA73160 [juniper.net] for more information.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-S4-EVO evo:21.4R3-S5-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:23.3R2-EVO
PR NumberSynopsisCategory: EVO Netstack Socket Intercept and NetIO libraries
1766212DNS resolution is not working for default instance when name server is reachable through mgmt_junos VRF
Product-Group=evo
DNS resolution is not working for default instance when name server is reachable through mgmt_junos VRF

Resolved In: evo:22.3R3-S2-EVO evo:22.4R3-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: PRs related to tunnels like GRE, IPIP in EVO control plane
1717782Traffic loss is observed with FTI over IRB as underlay.
Product-Group=evo
In case of FTI (Flexible Tunnel Interface) over IRB (Integrated Routing and Bridging) over ethernet, underlay ifl (logical interface) was pointing to IRB instead of ethernet interface leading to packet loss.

Resolved In: evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S6-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO
PR NumberSynopsisCategory: Configd, ffp issues
1743038Commit confirm and commit race condition crashes the firewall functionality
Product-Group=evo
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.

Resolved In: evo:22.2R3-S2-EVO evo:22.3R2-S2-EVO evo:22.3X50-EVO evo:22.4R1-S2-J3-EVO evo:22.4R2-J1-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1734091Traffic drop is observed in EVPN-VXLAN CRB scenario
Product-Group=evo
On all Junos Evolved platforms, in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) CRB (centrally-routed bridging) scenario, post reboot of chassis or on clearing BGP (Border Gateway Protocol) neighbor on spine nodes ARP (Address Resolution Protocol) entries which are remotely learned when IRB (integrated routing and bridging) ifl is down and when it comes up, these entries are present in the ARP table but the corresponding destination routes are missing in the forwarding table. Due to which traffic drop is observed.

Resolved In: evo:21.4R3-S6-EVO evo:22.3R3-S1-EVO evo:22.3X80-D35-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO
PR NumberSynopsisCategory: PRs for LC1202 Platform and Interface
1734235PTP will get stuck in acquiring state which leads to improper time synchronization after system reboot
Product-Group=evo
On Junos OS Evolved PTX10004/PTX10008/PTX10016/PTX10K-LC1201/PTX10K-LC1202/JNP10K-LC1202 platforms with SyncE (Synchronous Ethernet) and PTP (Precision Time Protocol) after system reboot, SyncE ref will not get locked and the PTP will get stuck in acquiring state and time synchronization will not be proper.

Resolved In: evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1759618License-service crash is seen on Junos OS Evolved platforms
Product-Group=evo
On Junos OS Evolved platforms, when license with unknown feature ID/platform reserved feature ID is added via configuration set system license keys key and then if License-service is restarted or system is rebooted or software upgrade is done then license service crashes and crash files are seen. This is a non service impacting issue.

Resolved In: evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: OSPF routing protocol
1704521On all Junos and Junos OS Evolved platforms, the TI-LFA and Legacy LFA are mutually exclusive, and the commit check will fail and blocks LFA on one instance
Product-Group=evo
On all Junos and Junos OS Evolved platforms, if configuring LFA (Loop-Free Alternate)/RLFA (Remote LFA)/PPLFA (Per-prefix LFA) in the routing-instance and TI-LFA (topology independent LFA) in the master instance, along with Segment Routing and node-link-protection with post-convergence, the commit check fails and blocks LFA on one instance.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.4R2-S1-J4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1702687The ppmd process crash will be seen after GRES
Product-Group=evo
On all Junos and Junos OS Evolved platforms with dual Routing Engines, after back-to-back GRES is performed, the ppmd process crashes.

Resolved In: evo:22.3X50-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1745509rpd core at #2 0x00007f9b2512742c in __assert_fail_base (fmt=0x7f9b2528bae8 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n", assertion=0x55be37507a48 "nh_idx_t_getval(nhid) == nh_idx_t_getval(rt_nexthops_nhid(rtnh))", file=0x55be375077e8 "../../../../../../../../src/layer3/usr.sbin/ rpd/lib/krt/common/krt_ack.c", line=1306, function=) at assert.c:92
Product-Group=evo
RPD core is sometimes seen if there are many unilist nexthop with identical key values but different metric in Evo, esp when ACK is requested for those nexthops

Resolved In: evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1585855< ok/> response is getting generated along with < rpc-error>
Product-Group=evo
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.

Resolved In: evo:22.2R3-S1-EVO evo:22.3R2-S2-EVO evo:22.3X50-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.3X75-D36 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R1 junos:23.2R1
PR NumberSynopsisCategory: ACX724 interfaces/optics issues
17598041G connection between ACX7024 and other platform may not come up due to auto-negotiation
Product-Group=evo
ACX7024 ports support 10G/1G/25G multi-rate. When peering with other platform or other vendor devices, For example using SFP-LX10 for 1G connection, the link may remain physically down The reason is Auto-negotiation is not supported in ACX7024 PFE due to Broadcom limitation. In order to make it work, user has to explicitly configure speed/duplex on both sides, and disable auto-negotiation on the peer side

Resolved In:

 


 

Modification History

2024-02-05 Updated to disclose JSA PRs which have been fixed but not published 
First publication 2023-10-04