Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.4R2-S2 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 22.4R2-S2 is now available.

22.4R2-S2 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1739730In EVPN-VXLAN scenario DHCP does not work for clients connected on the dot1x port
Product-Group=junos
On EX4300-48MP, in case of dot1x EVPN-VXLAN dynamic VLAN due to a HW setting which is used to assign VLAN to the authenticated dynamic VLAN, causes the DHCP offer to get tagged.
PR NumberSynopsisCategory: EX2300/3400 platform
1744141On EX2300/EX3400, unexpected error message during OAM boot
Product-Group=junos
It is not able to get active package date in OAM boot. Instead of getting active package date get the snapshot package date while in OAM/snapshot boot. Added set_pkgset & /packages/sets/$pkgset instead of /packages/sets/active. It will get package date correctly in normal boot, USB snapshot boot, and recovery snapshot boot.
PR NumberSynopsisCategory: NFX Series Platform Software
1756270nfx-3: non-root user is unable to access vnf through ssh, telnet and console
Product-Group=junos
nfx-3: non-root user is unable to access vnf through ssh, telnet and console
PR NumberSynopsisCategory: Accounting Profile
1692411Error messages are observed and incorrect values are returned for SNMP requests for pfe traffic statistics
Product-Group=junos
pfed: PFED_NOTIF_GLOBAL_STAT_UNKNOWN: xxxx in syslog The above log messages will be seen when we are using SNMP and if its trying to poll "show pfe statistics notification" through MIB OID - 1.3.6.1.4.1.2636.3.44.1.1.2.1.2.
1745175The mib2d process crashes during PIC offline/online
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the mib2d process can crash when the PIC (Physical Interface Cards) is offlined/onlined. Till the mib2d process restarts after the crash, any SNMP query for statistics from PFE (Packet Forwadring Engine) will not get a successful response.
PR NumberSynopsisCategory: BBE interface related issues
1734564Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled (CVE-2024-21587)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subscriber sessions to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75725 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1711727Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices (CVE-2024-21596)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75735 [juniper.net] for more information.
1742287Junos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crash (CVE-2024-21585)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessions and cause the routing protocol daemon (rpd) process to crash and restart, leading to a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75723 [juniper.net] for more information.
PR NumberSynopsisCategory: Captive Portal
1736937Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables (CVE-2023-36844)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Firewall Filter
1714988The Firewall filter with syslog action will not work when applied on the ingress of a loopback interface
Product-Group=junos
The firewall filter with syslog action on lo0 does not work as expected due to which logs are not seen on the log file.
PR NumberSynopsisCategory: Configd, ffp issues
1743038Commit confirm and commit race condition crashes the firewall functionality
Product-Group=junos
On dual-RE (Routing Engine) Junos Evolved platforms, when the commit is executed during the commit confirm timeout window, it causes the firewalld to stop working.
PR NumberSynopsisCategory: EX4400 PFE software
1736790EX4400 shaping rate not working as expected
Product-Group=junos
On EX platforms shaping rate on 100gig link over 70g not working as expected.
1747095LLDP will not work on HGoE VC mode with 40G VCP connections
Product-Group=junos
On EX4400/QFX5120 platforms, having High Gigabit over Ethernet (HGoE) Virtual Chassis (VC) mode in the master, when VC members are connected by 40G links, Link Layer Discovery Protocol (LLDP) Bridge Protocol Data Unit (BPDU) from VC master destined to the remote VC members (more than one-hop away) are dropped at VCP interface due to Virtual LANs (VLANs) membership check.
1747878Packet drop will be observed due to ARP resolution failure in EVPN-VXLAN scenario
Product-Group=junos
On Junos ACX/SRX/QFX/EX (BROADCOM based) platforms, ARP (Address Resolution Protocol) resolution is unsuccessful and packet drop will be seen, when interface mode - access is configured in EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) ERB (Edge Routed Bridging) scenario.
1749312Connectivity fails intermittently on 802.1x enabled ports
Product-Group=junos
On EX4100 and EX4400 platforms performing as Virtual Chassis, host authentication will get stuck in connecting state if 802.1x dynamic VLAN single supplicant mode is enabled on access switch port and complete traffic towards that port will be dropped.
1752898In Q-in-Q push/pop configuration for double tagged protocol traffic it is seen that the third VLAN tag is getting swapped instead of getting pushed onto the stack
Product-Group=junos
On Junos EX4350/EX4650-48Y/QFX5120/QFX5120-32C/QFX5120-48Y/QFX5120-48T/EX4400/EX4100 platforms, it is observed that during Q-in-Q push/pop configuration when double tagged protocol traffic like BGP (Border Gateway Protocol) /RIP (Routing Information Protocol) /OSPF (Open Shortest Path First) etc. packets are send towards UNI (User to Network Interface), the third tag is not getting added using firewall rule instead a swap operation is being done and the packet is forwarded as double-tagged. As a result, next device drops the traffic because expectation on that node is triple tagged frames.
PR NumberSynopsisCategory: MX Inline Jflow
1716505Memory initialization of large blocks causes traffic congestion in PFE or feature configuration fails
Product-Group=junos
Memory initialization of large blocks of PFE (Packet Forwarding Engine) memory such as hash table initialization expands memory which fails due to over-utilization and causes traffic congestion or feature configuration failure.
PR NumberSynopsisCategory: ISIS routing protocol
1699076The rpd process might crash when SPF is recalculated
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) process can crash due to periodic SPF (Shortest Path first) recalculation when ISIS (Intermediate System to Intermediate System) connected or direct routes get deleted.
1713008Stale entries present in the lsdist table after ISO address change
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with IS-IS and MPLS traffic engineering database (TED), if there is an ISO address change on another Intermediate System (IS), there will be stale entries being present in the link-state distribution (lsdist) table even though they might have been deleted in IS-IS and TED. This has an impact on the routes, and thus the services, related to the stale entries present in the lsdist.
PR NumberSynopsisCategory: jdhcpd daemon
1706709Junos OS: jdhcpd will hang on receiving a specific DHCP packet (CVE-2023-36842)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75730 [juniper.net] for more information.
1722082DHCP binding is not happening in EVPN VXLAN topology with DHCP stateless relay (forward-only)
Product-Group=junos
In EVPN VXLAN topology with DHCP stateless relay (forward-only) configured at layer 3 gateways, Jdhcpd broadcasts snooped unicast offer packets. That leads to the offer getting dropped on its way to the client and then the IP negotiation fails.
1731784DHCPv6 security functionality gets effected as DHCPv6 security bindings are not present
Product-Group=junos
On all Junos and Junos Evolved platforms having DHCPv6 snooping configured, when DHCP-security is enabled on multiple vlans along with dhcp stateless relay enabled at that time, DHCPv6 security bindings are not happening.
PR NumberSynopsisCategory: Issues related to Junos Kernel Debug Streaming Daemon (jkdsd
1734718Junos OS: jkdsd crash due to multiple telemetry requests (CVE-2023-44188)
Product-Group=junos
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of Juniper Networks Junos OS allows a network-based authenticated attacker to flood the system with multiple telemetry requests, causing the Junos Kernel Debugging Streaming Daemon (jkdsd) process to crash, leading to a Denial of Service (DoS). Continued receipt and processing of telemetry requests will repeatedly crash the jkdsd process and sustain the Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA73152 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Network Address Translation
1702811Junos OS: MX Series and SRX Series: Processing of a specific SIP packet causes NAT IP allocation to fail (CVE-2024-21616)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75757 [juniper.net] for more information.
PR NumberSynopsisCategory: User Firewall related issues
1758332Junos OS: SRX Series and EX Series: Multiple vulnerabilities in J-Web can be combined to allow a preAuth Remote Code Execution (CVE-2023-36851)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity and access confidential information. Please refer to https://supportportal.juniper.net/JSA72300 [juniper.net] for more information.
PR NumberSynopsisCategory: Security platform jweb support
1747984Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution (CVE-2024-21591)
Product-Group=junos
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the device. Please refer to https://supportportal.juniper.net/JSA75729 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1727954On all Junos and Junos Evolved platforms the l2ald process memory usage is seen to increase over time
Product-Group=junos
On all Junos and Junos Evolved platforms service impact is seen due to a consistent increase in l2ald (Layer 2 Address Learning Daemon) memory usage. The extra memory is a result of tools to track memory usage added via PR1536530.
1743282The l2ald crashes when there is recursive deletion of IFBD or when BGP neighborship is cleared in EVPN-VXLAN multi-homed configuration
Product-Group=junos
On all Junos and Junos OS Evolved platforms, in a rare scenario, due to timing issue, the l2ald (Layer 2 Address Learning Daemon) crashes and traffic is being blackholed due to recursive deletion of IFBD (Interface Family Bridge Domain) or when BGP (Border Gateway Protocol) neighborship is cleared when EVPN (Ethernet Virtual Private Network) - VXLAN (Virtual Extensible Local Area Network) with multi-homed is configured.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1698889The rpd process will crash when rpd is restarted
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching) statistics is configured without LSP (Label-Switched Path) configuration, the rpd process will crash and impact the routing protocols. This leads to traffic disruption due to the loss of routing information.
1738774Traffic blackhole due to an additional label when CCNH is toggled
Product-Group=junos
On all Junos and Junos Evolved platforms, with scaled Border Gateway Protocol (BGP) routes, when Chained Composite Next Hops (CCNH) is toggled, a few next-hops end up creating additional labels causing a traffic blackhole.
PR NumberSynopsisCategory: MX Timing software
1746541MPC10E line card crashes when it reboots after FPC firmware upgrade
Product-Group=junos
On MX240/MX480/MX960 platforms, if Precision time protocol (PTP) is configured, MPC10E line card crashes continuously after FPC firmware upgrade and when MPC10E line card is rebooted. Due to this issue, the clksyncd module also crashes.
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1763706Routing Protocol session down with native VLAN configuration on MX platforms
Product-Group=junos
On certain Junos MX platforms, the IS-IS (Intermediate System to Intermediate System) sessions will not come up/keep flapping when the native VLAN (Virtual Local Area Network) is configured on the associated l3 interface. There will be traffic loss due to the routing protocols being down and the workaround for the issue is to remove the native VLAN configuration.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1742088Device is not able to boot up from the recovery OAM volume
Product-Group=junos
OAM (Operation Administration and Maintenance) snapshot recovery not working as expected, post "request system reboot oam" system should boot OAM recovery mode, but system is rebooting back with current installed image.
PR NumberSynopsisCategory: "ifstate" infrastructure
1735685Control plane flap, data drop, unexpected behavior of PFE or device is observed when file storage is impacted in a continuous ksyncd process crash scenario
Product-Group=junos
On all Junos platforms configured with GRES (Graceful Routing Engine Switchover), file storage in the system will get affected when the ksyncd process crashes continuously and result in control plane flap, data drop or unexpected behavior of PFE (Packet Forwarding Engine) or device.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1723145Routing Engine-initiated PING failed over MPLS interface
Product-Group=junos
The Routing Engine-generated packets that have an MTU size greater than the inet MTU size get dropped when going out on an interface with MPLS chain-composite-next-hop configured.
PR NumberSynopsisCategory: TCP/UDP transport layer
1700438The TCP sessions for BGP are closed on the backup RE
Product-Group=junos
On all Junos Platforms, if the interface configuration is altered to switch from one routing instance to another it might result in the closing of BGP session on the Backup Routing Engine.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1712352Master and Backup RE synchronization issue will be seen if chassisd is restarted on Master RE
Product-Group=junos
On all Junos platforms with GRES (Graceful Routing Engine Switchover) and NSR (Non Stop Routing) enabled, Master and Backup RE (Routing-Engine) synchronization issues will be seen when chassisd (Chassis process) is restarted on Master RE. The ksyncd (Kernel Synchronization) process crash will be observed on the backup RE. If failover happens post this event, traffic would be impacted. This is a rare issue.
PR NumberSynopsisCategory: OSPF routing protocol
1704521On all Junos and Junos OS Evolved platforms, the TI-LFA and Legacy LFA are mutually exclusive, and the commit check will fail and blocks LFA on one instance
Product-Group=junos
On all Junos and Junos OS Evolved platforms, if configuring LFA (Loop-Free Alternate)/RLFA (Remote LFA)/PPLFA (Per-prefix LFA) in the routing-instance and TI-LFA (topology independent LFA) in the master instance, along with Segment Routing and node-link-protection with post-convergence, the commit check fails and blocks LFA on one instance.
PR NumberSynopsisCategory: Issues related to PKI daemon
1739342Memory leak in PKID
Product-Group=junos
PKID process shows memory usage increase over time after a larger number of certificate verifications. The issue can be recovered by the CLI command "restart pki-service".
PR NumberSynopsisCategory: DHCP related Issues
1711525DHCPv6 packets could not be forwarded if it contains the trailer or extra bytes out of the IP stack
Product-Group=junos
On all Junos QFX5K and EX platforms with DHCPv6 (Dynamic Host Configuration Protocol) relay configuration, IPV6 (Internet Protocol) assignment could not take place as the DHCPv6 solicit packets containing extra bytes in DHCPv6 header trailer are not getting forwarded to the DHCP server.
PR NumberSynopsisCategory: QFX L2 PFE
1741316The traffic drop is observed due to the MAC source address being learned from the wrong direction
Product-Group=junos
On Junos EX4300/QFX5100/QFX5110/QFX5200/QFX5210 platforms with VXLAN (Virtual Extensible Local Area Network) enabled, when the ARP (Address Resolution Protocol) request is sent from the device, the MAC (Media Access Control) address is learned from the wrong direction which results in the traffic drop.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1733022QFX5120 reboots due to deletion of EP style interface with native vlan configured
Product-Group=junos
QFX5120 will reboot without causing a dcpfe crash upon the deletion of EP style (Enterprise Style), and trunk interfaces with multiple IFLs and native VLAN configured.
PR NumberSynopsisCategory: RPD infrastructure issues related to NSR, GRES, switchover, 
1727957The traffic drop is observed during the Graceful restart on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, during the time of Graceful restart(GR), the routes in the Multiprotocol Label Switching(mpls).0 table will be updated even when the routing protocols are in the process of re-convergence and have not yet come out of GR. This causes inaccurate routes in the routing table and traffic drop is observed during GR.
PR NumberSynopsisCategory: RPD policy options
1706143Issue in committing more than 23, 4-byte AS on Junos and Junos Evolved platforms
Product-Group=junos
On all Junos and Junos Evolved platforms, when a 4 byte autonomous system (AS) number is committed with more than 23 as-path in as-path-prepend policy it gives "rpd string" error and the configuration commit fails.
PR NumberSynopsisCategory: Resource Reservation Protocol
1723229The rpd process crash is observed when RSVP LSP at Juniper transit/ingress router receives RESV message with RESVCONF object in multi vendor deployment
Product-Group=junos
On all Junos and Junos OS Evolved platforms (For QFX5100, only in Virtual Chassis-VC setup) with RSVP (Resource Reservation Protocol) LSP (Label-Switched Path) configured in multi vendor deployment and Juniper router is acting as a transit/ingress router and RESV (Reservation Request) message is received with RESVCONF object from other vendors, rpd process crash will be observed.
PR NumberSynopsisCategory: SW PRs for SCBE3 chassisd
1745442Traffic impact is observed on Junos MX platforms due to the chassisd crash
Product-Group=junos
On Junos MX240/MX480/MX960 platforms with SCBE3 (Enhanced Switch Control Board), when RE (Routing Engine) is switched over by any event, the chassisd crash is seen on the new master RE due to which all the line cards will reset and the traffic will be impacted.
PR NumberSynopsisCategory: Bug and Review Tracking for Segment routing traffic eng
1737119The traffic blackhole will be observed when the SRTE shortcut is configured
Product-Group=junos
On Junos platforms, when the MPLS (Multiprotocol Label Switching) packet reaches the destination router, it will have a label that is unknown to the destination router due to a label POP operation miss at the ingress router resulting in the traffic black hole in the scenario SR-MPLS (Segment Routing With Multiprotocol Label Switching) + traffic engineering shortcut is configured.
PR NumberSynopsisCategory: SRX Argon module
1738656Traffic drop caused by PFE memory leak on SRX platforms
Product-Group=junos
On Junos SRX platforms enrolled into ATP (Advanced Threat Prevention) cloud, memory leak is observed in the PFE (Packet Forwarding Engine) while deletion of few of the signatures which have no hash value. This memory leak results in traffic loss.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1721936Junos OS: SRX Series: flowd will crash when "tcp-encap" is enabled and specific packets are received (CVE-2024-21606)
Product-Group=junos
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75747 [juniper.net] for more information.
PR NumberSynopsisCategory: Stout cards (MPC7, MPC8, MPC9) microkernel issues
1727427FPC crash observed when the ASIC usage is high
Product-Group=junos
On platforms with MS-MPC/MPC1/2/3/4/5/6/7/8/9/JNP10K-LC2101/JNP10003-LC2103/JNP10K-LC480 line cards and EX9200/EX9204/EX9208/EX9214/EX9251/EX9253 series devices, route churn (add or deletes) when the ASIC usage crosses a threshold (ASIC usage is high) which leads to a FPC crash.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1664694Not all MAC addresses are learnt for some VPLS instances
Product-Group=junos
On MX platforms with specific line cards(MPC10, MPC11 & LC9600), when the CLI "clear vpls mac-table" is executed, all the MAC addresses are not learned for some VPLS instances. This will lead to traffic loss due to MAC table not having all the MAC addresses.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1703910The line card abruptly reboots when ISSU is performed
Product-Group=junos
On platforms supporting MPC3E/MPC4E/T4000-FPC5/EX9200-4QS/EX9200-2C-8XS/EX9200-MPC/EX9200-32XS/SRX5K-SPC-4-15-320/SRX5K-MPC, the line card abruptly rebooted with a process crash when ISSU (In-Service Software Upgrade) is performed without properly disabling Jflow.
PR NumberSynopsisCategory: Trio pfe qos software
1726698On certain Junos MX platforms queue buffer-size temporal computation is not happening correctly
Product-Group=junos
On certain Junos MX platforms, if a queue's buffer size is configured as temporal value and the transmit-rate/guaranteed-rate is not configured as absolute value at COS (Class of Service) schedulers or traffic-control-profile level, then a very low queue depth buffer gets allocated to the queue. This will lead to aggressive tail-drops on the queue.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1689224Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected (CVE-2024-21607)
Product-Group=junos
An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause partial impact to the integrity of the device. There is no downstream impact as in this case the firewall filter which doesn't function correctly is meant to protect the device itself. Please refer to https://supportportal.juniper.net/JSA75748 [juniper.net] for more information.
1724563Traffic drop would be observed while restarting the chassis-control
Product-Group=junos
On MX platforms with MPC1 to MPC9 line cards, while restarting chassis-control, the line card crashes as the watchdog timer panics due to an internal thread being too busy seemingly finding if a particular term-based filter has a term with then port-mirror-instance <> for a particular instance name.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1740606Host communication does not work in EVPN-L2VPN-CCC setup
Product-Group=junos
On Junos MX platforms, in Ethernet Virtual Private Networks-Layer 2 Virtual Private Networks-Circuit Cross-Connect (EVPN-L2VPN-CCC) setup, the integrated routing and bridging (IRB) interface over access logical tunnel (LT) interface is configured, it is sending vlan tagged packet on the access port and not removing it causing the host communication to break.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1720591In a rare case FPC crashes and reboots generating a core
Product-Group=junos
On all Junos platforms, in a rare scenario, GRES (Graceful Routing Engine switchover) may result in LACP (Link Aggregation Control Protocol) on the new master being down which may cause an FPC crash.
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1562848The mustd process may crash on all platforms
Product-Group=junos
With a large-scale configuration, in rare cases, the mustd process might crash. The mustd process, which is responsible for configuration constraint checks, might crash on commit, leading to commit failure.
PR NumberSynopsisCategory: Ephemeral Database
1751141Load replace via XML NetConf will not work
Product-Group=junos
On all Junos and Junos OS Evolved platforms, the load replace operation through XML NetConf will fail.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1740289The 'load replace' operation might result in mustd and mgd crash
Product-Group=junos
On Junos and Junos Evolved platforms with 'apply-group' configured, the mustd and mgd processes might crash when the 'load replace' operation is performed. When this happens, 'apply-groups' will get deleted internally and the respective hierarchies will not be notified.
PR NumberSynopsisCategory: Issues related to NETCONF
1585855< ok/> response is getting generated along with < rpc-error>
Product-Group=junos
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.
PR NumberSynopsisCategory: X-Men interface software related issues.
1705035Configuration CLI to set temperature tresholds for ZR/ZRM optics is hidden
Product-Group=junos
On ACX7100-32C and ACX7100-48L platforms the configuration option to set temperature tresholds for ZR/ZRM optics is hidden.
 
 

22.4R2-S2 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 platform
PR NumberSynopsisCategory: MX YT-ZF Linecards Fabric Software Category
1758348Traffic loss will be observed during the ungraceful removal of a switch fabric board
Product-Group=junos
On MX10K platforms with LC2101, when ungraceful Switch Fabric Boards (SFB) offline operation is performed results in a Packet Loss Duration (PLD) higher than 2000 milliseconds, leading to observed packet loss

Resolved In: evo:22.4R3-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1705938The BGP sessions will flap after the RE switchover
Product-Group=junos
On all Junos and Junos OS Evolved platforms with dual RE (Routing Engine) or VC (Virtual Chassis) with NSR enabled scenarios, in some rare BGP scaled scenarios upon RE switchover the new Master RE will send out a route refresh message to all the peers, which is not expected. This will eventually lead to the BGP session flap.

Resolved In: evo:21.4R3-S5-EVO evo:22.3R3-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.2R3-S5 junos:21.4R3-S5 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
1709837Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: EX4100 PFE
1744190Virtual Chassis formation will not happen automatically on all EX platforms except EX4400 after zeroize
Product-Group=junos
Virtual Chassis members are not forming Virtual Chassis on all EX platforms except EX4400 due to cross connection of VC links in specific ring topology setup after zeroize. Each device will function as standalone.

Resolved In: junos:21.4R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: EX4400 PFE software
1761220The 'input-vlan-map push' operation will not work on double-tagged frames
Product-Group=junos
On Junos EX/QFX5120 platforms with QinQ setup packets with multicast payloads such as OSPF (Open Shortest Path First)/ISIS (Intermediate. System to Intermediate System), when 'input-vlan-map push' is configured to push an outer VLAN (Virtual Local Area Network) tag on to a double-tagged frame, the egressing frame will be tagged incorrectly. Instead of a push operation, the outer VLAN tag of the ingressing double-tagged frame will be swapped and sent out. This results in unexpected behavior or traffic loss as such protocol packets will not have the expected VLAN tag information.

Resolved In: junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Express PFE L3 Multicast
1756923A heap memory leak will be seen when P2MP LSP MBB events happened
Product-Group=junos
On PTX3000 and PTX5000 platforms, nodes having Point-to-MultiPoint (P2MP) MPLS label switched path (LSP) passing through them will show a slow increase in Flexible PIC Concentrators (FPC) heap memory utilization when there are P2MP LSP Make-Before-Break (MBB) events happened and when adaptive load balancing (ALB) is enabled on the aggregated ethernet (AE) interface. FPC may crash if the memory leak persists for an extended period.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S7 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1751260Directly connected neighbour via AE becomes unreachable if the member interfaces of AE are swapped and if one AE has VLAN and the other doesn't
Product-Group=junos
On MPC10E line cards based MX platforms with AE (Aggregated Ethernet) interface configured with Link Aggregation Control Protocol (LACP), subscriber management and auto-configure statement enabled, ping to neighbour fails post swapping member-interfaces between two AE (one with VLAN configuration and the other without VLAN configuration). Traffic forwarding on respective interfaces will be impacted as interface is moved from AE having VLAN to AE not having VLAN.

Resolved In: junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: ISIS routing protocol
1723172The rpd process crash is observed when TI-LFA feature is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms with TI-LFA (Topology-Independent Loop-Free Alternate) feature enabled, when IP address is removed from one interface and is assigned to another interface in the same commit, the rpd process crashes affecting routing control plane.

Resolved In: evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.4R3 junos:22.4R3-S1 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Security platform jweb support
1763260Junos OS: SRX Series and EX Series: J-Web - unauthenticated access to temporary files containing sensitive information (CVE-2024-21619)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. Please refer to https://supportportal.juniper.net/JSA76390 [juniper.net] for more information.

Resolved In: junos:19.3R3-S9 junos:19.4R3-S13 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Layer 2 Control Module
1743632After this PR fix, to enable the xSTP support in ephemeral DB, below config command needs to be used: "set protocols layer2-control ephemeral-db-support"
Product-Group=junos
After this PR fix, by default xSTP will not be supported in ephemeral-db mode. "set protocols layer2-control ephemeral-db-support" needs to be used to enable the xSTP support in ephemeral-db mode.

Resolved In: evo:23.4R1-EVO evo:24.1R1-EVO junos:21.4R3-S6 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: QFX L2 PFE
1711860The dcpfe process will crash due to memory fragmentation
Product-Group=junos
On Junos and Junos OS Evolved platforms, the dcpfe (Dense Concentrator Packet Forwarding Engine) process crash will be observed due to memory fragmentation issue. This is a very rare case and would impact traffic as due to dcpfe failure the PFE restarts, so the interfaces will flap.

Resolved In: evo:23.4R1-EVO junos:23.4R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1742763Traffic drop will be observed after extended-vni-list configuration change with EVPN-VXLAN scenario
Product-Group=junos
On Junos QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4100/EX4300-MP/EX4400-XX platforms having Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) configured if extended-vni-list configuration is deleted, the network interface is flapped and when extended-vni-list is added back due to this traffic using the Flood NH (BUM) on the device will be lost.

Resolved In: junos:20.4R3-S9 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Issues related to dynamic-tunnels routing infrastructure
1749601Traffic is getting dropped when using GRE NH-based dynamic tunnel is up with GRE Key
Product-Group=junos
On all Junos and Junos OS Evolved platforms that support MPLS(Multi-Protocol Label Switching) over GRE (Generic Routing Encapsulation) and have dynamic tunnel configured the traffic can get dropped. This issue is seen when IPv4 traffic is sent and the NH (Next Hop) is a GRE-based dynamic tunnel with a GRE key, the traffic can get dropped even though the tunnel is in up state.

Resolved In: evo:22.2R3-S3-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1745509rpd core at #2 0x00007f9b2512742c in __assert_fail_base (fmt=0x7f9b2528bae8 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n", assertion=0x55be37507a48 "nh_idx_t_getval(nhid) == nh_idx_t_getval(rt_nexthops_nhid(rtnh))", file=0x55be375077e8 "../../../../../../../../src/layer3/ usr.sbin/rpd/lib/krt/ common/krt_ack.c", line=1306, function=) at assert.c:92
Product-Group=junos
RPD core is sometimes seen if there are many unilist nexthop with identical key values but different metric in Evo, esp when ACK is requested for those nexthops

Resolved In: evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: MX10003/MX204 Linux issues (including driver issues)
1753908Device crash and control plane traffic gets impacted on Junos platforms
Product-Group=junos
On all Junos platforms, due to a timing issue, when monitor traffic is enabled on loopback interface (for debug purpose), in the presence of local TCP (Transmission Control Protocol) packet flow, it is observed that the device crashes and traffic gets impacted.

Resolved In: junos:20.4R3-S10 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1726731After the device reboot BGP sessions configured with authentication will be down
Product-Group=junos
On all EX4100 platforms, after the device reboot, BGP (Border Gateway Protocol) peers with authentication remain down as the keyadmin utility is not invoked causing the kernel database to not populate with MD5 configuration.

Resolved In: junos:22.1R3-S4 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R2 junos:23.3R1 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: web filterig issues
1725359Memory leak is observed on all Junos SRX platforms with http-persist and http-reassembly configuration
Product-Group=junos
On all Junos SRX platforms with http-persist and http-reassembly configuration when firewall policy is attached with enhanced or redirect WF (Web Filtering) policy, memory leak will be observed in PFE (Packet Forwarding Engine) which leads to traffic drop.

Resolved In: junos:22.2R3-S2 junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: VMHOST platforms software
 
 

Modification History

2024-02-05 - Updated to include SIRT issues, which have been included but withhold
First publication 2023-10-16