Alert Type

SRN - Software Release Notification
MediumSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved platforms

Alert Description

Junos Software Service Release version 22.4R3-S3-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution


22.4R3-S3-EVO - List of Fixed issues 

PR NumberSynopsisCategory: "agentd" software daemon
1808259Openconfig data type value is streaming in gnmi update as float_val instead of bytes_val
Product-Group=evo
On all Junos Evolved platforms configured with Openconfig telemetry, when streaming the GNMI leaves updates for data type value "ieeefloat32"will be seen streaming as type "float_val" instead of "bytes_val". There is no traffic impact due to this, and just a display issue.
PR NumberSynopsisCategory: Border Gateway Protocol
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1787290Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.
PR NumberSynopsisCategory: PTX10003 Interface related issues
1810718On PTX10003 4x10GE/4x25GE interface drop the traffic in working lanes when new lane is configured with 400GE as neighbor interface
Product-Group=evo
On PTX10003 platform, whenever there is a change in MTU/VLAN configuration or bouncing interface channel 2/3 of 4x10GE or 4x25GE and if the immediate neighbor port is configured with 400GE, it leads to packet drop on 4x10GE and 4x25GE interfaces and issue is not observed when the immediate neighbor port is configured with 100GE.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1799760MPLS payload traffic coming over EVPN-MPLS tunnel is dropped on PTX Junos OS Evolved platforms
Product-Group=evo
On Junos OS Evolved PTX platforms, if MPLS payload packet is received on Ethernet Virtual Private Network-Multi-Protocol Label Switching (EVPN-MPLS) tunnel, then that traffic will be dropped.
PR NumberSynopsisCategory: Express PFE L3 Multicast on BX platforms
1810774Traffic drop is observed on Junos OS Evolved PTX platforms
Product-Group=evo
On Junos OS Evolved PTX10004/PTX10008/PTX10016 platforms running 22.4 or 23.1 release, any forwarding traffic will be dropped.
PR NumberSynopsisCategory: ACX BFD specific issues
1732443IPv6 EBGP sessions can flap or delay in neighbour establishment could be seen due to Hold Timer Expired Error
Product-Group=evo
On all Junos OS Evolved ACX series platforms, when IPv6 BGP (Border Gateway Protocol) sessions are configured, session flap or delay in neighbour establishment is seen when BGP IPv6 control packets with TTL=1 are moved to ttl-exception queue instead of the L3 high priority queue. This results in loss of traffic and service disruption due to flap or delay in session establishment.
PR NumberSynopsisCategory: DNX L2 related features
1802525The MPLS tunnel traffic arriving at the ingress interface would drop on ACX7K platforms when storm control is enabled
Product-Group=evo
On Junos Evolved ACX7K platforms configured with MPLS tunnel and Storm Control, the Layer 2 or MPLS tunnel-terminated known unicast traffic arriving at the ingress interface assigned with a high drop precedence by the interface-level classifier will get dropped on the interface where storm control profile is active. Due to this, MPLS tunnel traffic may get affected.
PR NumberSynopsisCategory: DNX VPLS
1805586ACX7K || Post instance renaming, VPLS MACs stopped exchanging over MPLS CORE/LSI interface
Product-Group=evo
During renaming of routing-instance some BD objects are not properly handled and are reaching PFE during delete. Because of which LSI interface is not getting created in the hardware as its waiting for the BD updates which already got deleted.
PR NumberSynopsisCategory: EVO ARP related PRs
1798446Traffic drops will be seen on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms, while changing the MAC (Media Access Control ) address on the peer side, the traffic drop will be observed if route is in non-default table.
PR NumberSynopsisCategory: management ethernet related issues - mgmt-ethd daemon
1796934legacy inet6 address seen under vmb0 while modifying mgmt-0 IPv6 address with dadfailed
Product-Group=evo
In case of master-only inet6 address uses for re[01]:mgmt-0 interfaces, if there is inet6 address modification, the legacy inet6 address might still reside when do "ip -6 add show dev vmb0" under OS shell. The output of CLI command "show interfaces re[01]:mgmt-0" shows the inet6 address correctly.
PR NumberSynopsisCategory: software upgrade infra issues
1803511[Junos OS Evolved] - Time-zone info changes to default UTC after upgrade is done with restart-upgrade
Product-Group=evo
On all Junos OS Evolved platforms, Time-zone info changes to default UTC after upgrade is done with restart-upgrade
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1808779L2ald-agent core and IRB ifl stays Hardware-down after deletion of irb(with virtual-gateway-address config) , readding same virtual-gateway-address as IRB address and move back to irb with same virtual-gateway-address
Product-Group=evo
l2ald-agent core and IRB ifl may stay in hardware-down state after following irb config changes which involves assigning VGA IP directly to IRB IFL, commit, delete the VGA from IRB IFL and add it as virtual-gateway-address again.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1750699Observing routes missing in few scale VRF configuration after doing "Interface Flap"
Product-Group=evo
In scaled scenario (1 million BGP routes and 1000 VRF's), interface flap will impact relearning routes with few VRFs and the routes are missing. Clearing BGP neighbors should recover the issue. Issue is applicable to all EVO platforms.
PR NumberSynopsisCategory: Configd, ffp issues
1802837DHCP relay functionality is broken on Junos OS Evolved platforms when 'prefix-list' with 'apply-path' for DHCP relay is used
Product-Group=evo
On all Junos OS Evolved platforms the DHCP (Dynamic Host Configuration Protocol) relay will not work as expected when two consecutive wildcards are used in prefix-list apply-path in the loopback filter and "set policy-options prefix-list pf-dhcp-servers apply-path "forwarding-options dhcp-relay server-group <*> <*>" is configured.
PR NumberSynopsisCategory: Express PFE MPLS Features
1752262TTL value of the explicit null label is ignored on certain PTX platforms
Product-Group=evo
TTL value of the explicit null label is ignored on certain PTX platforms.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1797996BGP learning or convergence performance degradation.
Product-Group=evo
Addresses delays in processing millions of routes by optimizing memory usage and improving learning/deleting route operations, reducing few-second delays.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1776596Interface stay in link DOWN state when using third party optics
Product-Group=evo
On Junos OS Evolved platforms and MX ULC based line cards, interfaces will stay DOWN when using third party vendor optics, due to an incorrect programming of EEPROM when plugged into the device.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1817214[Junos OS Evolved] PTX10004/8/16 - Fan Tray Failure alarm gets raised with either Fan Tray OIR, RE mastership switch or System reboot
Product-Group=evo
On all Junos OS Evolved PTX10004/8/16 platforms, fans go into failed state with either Fan Tray OIR, RE mastership switch or System reboot. user@PTX10016-re0> show system alarms no-forwarding xx alarms currently active Alarm time Class Description 2024-06-05 11:58:16 JST Major Fan Tray 0 Failure 2024-06-05 11:58:16 JST Major Fan Tray 1 Failure Use the below command to check the fan status. user@PTX10016-re0> show chassis fan
PR NumberSynopsisCategory: PTX10K Timing/Sync-E issues tracking
1787869Difference in TOD between EEC and PTP FPGA.
Product-Group=evo
Difference in TOD (Time Of the Day) between EEC (Ethernet Equipment Clock) and PTP FPGA (Precision Time Protocol Field Programmable Gateway Array). The difference causes the PTP packets originating from PTP FPGA to pass through FPC with higher CF (correction field) approximately 1 second.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=evo
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR NumberSynopsisCategory: Issues related to NETCONF
1792362RPC request for file copy with routing instances is failing
Product-Group=evo
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
PR NumberSynopsisCategory: VCCP related PRs for virtual-chassis in MX
1801522AE child links in back member is in detached state
Product-Group=evo
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberSynopsisCategory: ACX hwd/chassisd software related issues.
1801225Junos OS Evolved ACX platforms is powered down randomly due to incorrect read of temperature sensor
Product-Group=evo
On ACX platforms running Junos OS Evolved, the device gets powered down due to incorrect reading of a temperature sensor, impacting all the services running on the box.
 
 

22.4R3-S3-EVO - List of Known issues 

PR NumberSynopsisCategory: EVO platform software
1808014CI/CD:22.4R3-S2-EVO:PSM 0 Status remains on check state ptx10001-36mr while testing with 22.4R3-S2
Product-Group=evo
prior to release 23.3R1 where PR: 1724850 is fixed, when PSM inputs are not connected, the state of the PSM is shown as check state. Workaround: Connect the power to PSM0.

Resolved In:
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1778668[EVO] Log message for DDoS violation information shows default time and date wrong when its violation state is cleared by "clear ddos-protection protocols states".
Product-Group=evo
Log message for DDoS violation information shows default time and date wrong when its violation state is cleared by "clear ddos-protection protocols states" on EVO. It can be seen when "clear ddos-protection protocols states" command is used. In case of clearing DDoS vilolation state by passing recovery time, it cannot be seen.

Resolved In: evo:22.4R3-S1-J1-EVO evo:22.4R3-S2-J1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
1792173Traffic loops and convergence issues in a scaled multicast churn scenario
Product-Group=evo
On PTX10008, PTX10016 and PTX10001-36MR platforms, incorrect internal processing at the Packet Forwarding Engine (PFE) leads to congestion.

Resolved In: evo:21.4R3-S7-EVO evo:21.4X6-EVO evo:22.2R3-S4-EVO evo:23.2R2-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.4R2 junos:24.1R2 junos:24.2R1
PR NumberSynopsisCategory: BX PFE firewall issues
1772149Balerion-FT:Firewall: aftmand-bx cores continuously at JexprHandleFilter:: updatePfeInst, when attaching filter which has 5-tuples+FC+DP+TTL+Fragment+ifl matches
Product-Group=evo
If a filter does not compile due to an unsupported match combination (i.e. the set of matches configured in the filter is not supported by hardware), attaching this filter to an interface will cause aftmand-bx to crash.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1771121JDI_REG:EVO:ultron-xl: jdhcpd.re.re0 cored at trace_file_close_internal (traceptr=0x7efc443b2bb0) at ../../src/junos_trace.c:188
Product-Group=evo
When DHCP trace options are enabled, there is a possibility that jdhcpd could core. It is recommended to enable them only for debugging purpose and disable it immediately once debugging is done.

Resolved In:
PR NumberSynopsisCategory: DNX Multicast
1816540OSPFv3 neigborship forming issue on IRB when mld-snooping enabled on the BD where IRB hosted
Product-Group=evo
OSPFv3 neighborship is not getting established on IRB when mld snooping is enabled for the BD on which IRB is hosted.

Resolved In: evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: EVO ARP related PRs
1776871Functionality provided by arp/ndp publish argument doesn't work on all Junos OS Evolved platforms
Product-Group=evo
Functionality provided by publish argument for static arp and static ndp configuration is not working on all Junos OS Evolved platforms.

Resolved In: evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: EVO Netstack DDoS (ddosd and JTD)
1723007[Junos OS Evolved] DDoS syslog always shows FPC0 irrespective of where the DDoS is detected
Product-Group=evo
On all EVO platforms, only FPC 0 is shown in syslog for all FPC DDoS violations.

Resolved In: evo:21.4R3-S4-EVO evo:22.3X50-EVO evo:22.4R3-S1-J1-EVO evo:22.4R3-S2-J1-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:24.3R1-EVO
PR NumberSynopsisCategory: EVO ETHOAM Category
1769373lfmd fails to send notification about CRC error is seen on link
Product-Group=evo
On all Junos OS Evolved platforms, when LFM(Link Fault Management) is configured on a link and discovery state of LFM is in send any then if any CRC (Cyclic Redundancy Check) error or frame error is seen on the link, lfmd fails to send these error notification to alert peer about these errors, due to which peer nodes will not re-route the packets and hence traffic loss may be seen.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Firewall related development
1798975[PTX10004 EVO] Max configurable value of policer if-exceeding "bandwidth-limit" is 100Gbps
Product-Group=evo
Max configurable value of policer if-exceeding "bandwidth-limit" is 100Gbps on PTX10004 EVO. It is 25.6Tbps on PTX10001-36MR/PTX10008/10016 platforms.

Resolved In: evo:22.4R3-S1-J1-EVO evo:22.4R3-S2-J1-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1762065monitor interface or show interface does not display the interface description
Product-Group=evo
Enhancement in EVO platform for the command "monitor interface" and "show interface" include interface description

Resolved In: evo:22.3R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO
1803441Traffic drop will be observed when the IFLs have vlan-id-list above the vlan-bundling limit
Product-Group=evo
On all Junos Evolved ACX platforms, there will be a drop in the traffic when the IFLs have vlan-id-list above the vlan-bundling limit. Hence a commit warning must be implemented when number of vlan-bundling is above the hardware limit.

Resolved In: evo:23.2R2-S1-EVO
PR NumberSynopsisCategory: EVO RPD agent PRs
1802000The rpd process crashes when Routing Instance type is changed from L2 to L3 or vice versa
Product-Group=evo
On all Junos OS Evolved platforms, when a layer 2 RI (Routing Instance) is changed to layer 3 RI or vice versa without changing the name of the RI in a single commit, due to a rare timing issue, the rpd process can crash. During the rpd crash and restart, the routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.

Resolved In: evo:22.3X80-D43-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:24.2R2
PR NumberSynopsisCategory: Port Mirroring feature on express PFE
1770432"evo-aftmand-bt[15138]: [t:15257] [Error] Jexpr: Invalid pfeId " error logs seen on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms with remote port-mirror configuration where output interface is set as a FTI interface and is not bound to firewall, route changes toward this tunnel destination may lead to unexpected error messages of evo-aftmand-bt.

Resolved In: evo:22.2R3-S3-EVO evo:22.2R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:22.2R3-S3
PR NumberSynopsisCategory: All Guardian (ACX7509) Platform related issues
1803114Interface connected to SFP-T optics fails to come up post switchover
Product-Group=evo
On certain ACX Junos OS Evolved platforms, the ports equipped with SFP-T will not come up when picd restarts or when picd becomes active on back-up RE (Routing Engine) due to switchover.

Resolved In: evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1719162MPLS LSP stats will not increment post the rpd restart
Product-Group=evo
On all Junos and Junos OS Evolved platforms post rpd restart using cmd "restart routing immediately" mpls lsp statistics will not work.

Resolved In: evo:22.1R3-S6-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: Issues related to control plane security
1741624Junos OS Evolved: A high rate of SSH connections causes a Denial of Service (CVE-2024-39562)
Product-Group=evo
A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by blocking SSH access for legitimate users. Continued receipt of these connections will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75724 [juniper.net] for more information.

Resolved In: evo:21.4R3-S7-EVO evo:22.3R2-S2-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:23.4R1-S1-EVO junos:23.1R2 junos:23.2R2 junos:23.3R1
PR NumberSynopsisCategory: Trio LU and LUSS SW driver
1735490Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash (CVE-2024-39539)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA82999 [juniper.net] for more information.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S10 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1769911Netconf: File copy with password less authentication is failing with rpc request
Product-Group=evo
Netconf: File copy with password less authentication is failing with rpc request

Resolved In:
 

Modification History

First publication 2024-07-16