Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX PTX and QFX running Junos Evolved Software
Alert Description
Junos Software Service Release version 20.4R3-S10-EVO is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 20.4R3-S10-EVO is now available.
20.4R3-S10-EVO - List of Fixed issues
PR Number
Synopsis
Category: Bi Directional Forwarding Detection (BFD)
1698373
A few BFD sessions might flap after FPC reload and stabilization
Product-Group=evo
On all Junos platforms and Junos Evolved with scaled BFD sessions, FPC reload/restart results in few BFD session flap.
PR Number
Synopsis
Category: Border Gateway Protocol
1709837
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=evo
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA72510
[juniper.net]
for more information.
PR Number
Synopsis
Category: PTX10003 Interface related issues
1615000
evo-aftmand process causing increase in memory utilization
Product-Group=evo
On some Junos and Junos Evolved platforms the evo-aftmand (Advanced Forwarding Toolkit manager) process might consume high memory over a period of time leading to an increase in the shared memory utilization.
PR Number
Synopsis
Category: Issues related to EVO dependency layer including object graphs, incompletes, anomalies and nkdb
1777613
Lost connectivity to management IP address after abnormal Routing Engine (RE) shuts down, and new Master RE won't own the IP either.
Product-Group=evo
Master-only IP address is missing on mgmt-0 interface after the master Routing-Engine abnormally shuts down, which causes the router not be accessible remotely via mgmt-0 IP address.
PR Number
Synopsis
Category: EVO linux defects & enhancement requests
1745190
Junos OS Evolved: IPython privilege escalation vulnerability (CVE-2022-21699)
Product-Group=evo
IPython, shipped with Juniper Networks Junos OS Evolved, is subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same system. Please refer to https://supportportal.juniper.net/
JSA75721
[juniper.net]
for more information.
PR Number
Synopsis
Category: show route table commands, tracing, and syslog facilities
1658834
Junos OS and Junos OS Evolved: In a BGP rib sharding scenario an rpd crash will happen shortly after a specific CLI command is issued (CVE-2023-28980)
Product-Group=evo
A Use After Free vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA70606
[juniper.net]
for more information.
20.4R3-S10-EVO - List of Known issues
PR Number
Synopsis
Category: PFE L2 forwarding features on BT based platforms
1761599
Control traffic impacted
Product-Group=evo
Untagged control traffic will get dropped on a physical interface with coinciding lport value (1 less) and this physical interface has to be in l3 mode or its part of AE interface which is in l3 mode.
Resolved In:
evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:23.2R2-EVO
PR Number
Synopsis
Category: Express BT PFE L3 Features
1756452
FPC unreachable due to running out of Guid space
Product-Group=evo
FPC unreachable due to running out of Guid space and any stats pooling makes Guid space run out faster.
Resolved In:
evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:22.4R3-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.4R2 junos:24.1R1
PR Number
Synopsis
Category: DNX L2 related features
1782190
Traffic disruption is seen when IRB is present within ERPS protected bridge domain
Product-Group=evo
On Junos Evolved ACX7K platforms, whenever ARP (Address Resolution Protocol) refresh takes place, ARP packet will flood on both blocked (backup path) and unblocked (working path) ports in a ring node. ARP packet is being allowed in the block port, causing traffic disruption.
Resolved In:
evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR Number
Synopsis
Category: Application controller related issues
1629823
anomalies/leaks might be seen for some of the DDX objects upon switchover
Product-Group=evo
anomalies/leaks might be seen for some of the DDX objects upon switchover.
Resolved In:
evo:21.4R3-S6-EVO evo:22.1R1-EVO
PR Number
Synopsis
Category: SNMP, mib2d issues
1704878
Neighbor device details not listed under snmp walk [ipNetToMediaPhysAddress]
Product-Group=evo
On Junos Evolved platforms, SNMP walk table (ipNetToMediaPhysAddress) is not updated when a neighbour entry is configured.
Resolved In:
evo:21.4R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.4R1-EVO evo:23.4R2-EVO
PR Number
Synopsis
Category: ZT/YT pfe l3 forwarding issues
1774127
Memory leak for deactivation/activation of SCU
Product-Group=evo
On MX platforms with MPC10, MPC11, LC9600, and MX304-LMIC16, the heap memory leaks every time the SCU (source-class-usage) policy is removed i.e. removed and re-applied resulting in restart of the line card. Heap leak is proportional to the number of source classes or indices being removed by related policy.
Resolved In:
evo:23.4R2-EVO evo:24.1R1-EVO junos:20.4R3-S10 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J9 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:23.4R2 junos:24.1R1
PR Number
Synopsis
Category: Trio pfe bridging, learning, stp, oam, irb software
1781673
L2 control packets may be dropped on JUNOS devices in VPLS scenario on certain MX platforms
Product-Group=evo
On certain Junos MX platforms, in the VPLS (Virtual Private LAN Service ) scenario, the L2 (Layer 2) control packets with a multicast destination MAC (Media Acess Control) address are dropped if they arrive on the VPLS core-facing interface placed on MPC (Modular PIC Concentrator)10/MPC11 linecards or MX304 router
Resolved In:
evo:23.2R2-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:21.2R3-S7 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.4R3-S1 junos:23.2R2 junos:23.4R2 junos:24.1R1
Modification History
First publication 2024-02-29
20.4R3-S10-EVO: Software Release Notification for JUNOS Evolved Software