Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX running Junos Evolved software

Alert Description

Junos Software Service Release version 21.4R3-S8-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution


Junos Software service Release version 21.4R3-S8-EVO is now available.

21.4R3-S8-EVO - List of Fixed issues 

PR NumberSynopsisCategory: Border Gateway Protocol
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1787290Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.
1803120Junos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crash (CVE-2024-39543)
Product-Group=evo
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83004 [juniper.net] for more information.
PR NumberSynopsisCategory: PTX10003 Interface related issues
1810718On PTX10003 4x10GE/4x25GE interface drop the traffic in working lanes when new lane is configured with 400GE as neighbor interface
Product-Group=evo
On PTX10003 platform, whenever there is a change in MTU/VLAN configuration or bouncing interface channel 2/3 of 4x10GE or 4x25GE and if the immediate neighbor port is configured with 400GE, it leads to packet drop on 4x10GE and 4x25GE interfaces and issue is not observed when the immediate neighbor port is configured with 100GE.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO
PR NumberSynopsisCategory: DNX L2 related features
1802525The MPLS tunnel traffic arriving at the ingress interface would drop on ACX7K platforms when storm control is enabled
Product-Group=evo
On Junos Evolved ACX7K platforms configured with MPLS tunnel and Storm Control, the Layer 2 or MPLS tunnel-terminated known unicast traffic arriving at the ingress interface assigned with a high drop precedence by the interface-level classifier will get dropped on the interface where storm control profile is active. Due to this, MPLS tunnel traffic may get affected.
PR NumberSynopsisCategory: EVO ARP related PRs
1798446Traffic drops will be seen on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms, while changing the MAC (Media Access Control ) address on the peer side, the traffic drop will be observed if route is in non-default table.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1756208Junos OS Evolved: MAC table changes cause a memory leak (CVE-2024-39557)
Product-Group=evo
An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83017 [juniper.net] for more information.
1808779L2ald-agent core and IRB ifl stays Hardware-down after deletion of irb(with virtual-gateway-address config) , readding same virtual-gateway-address as IRB address and move back to irb with same virtual-gateway-address
Product-Group=evo
l2ald-agent core and IRB ifl may stay in hardware-down state after following irb config changes which involves assigning VGA IP directly to IRB IFL, commit, delete the VGA from IRB IFL and add it as virtual-gateway-address again.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=evo
On MX, QFX and PTX10K line of routers running Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1770643RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=evo
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1794536The device goes into configuration locked state due to stale mgd
Product-Group=evo
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
 
 

21.4R3-S8-EVO - List of Known issues 

PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1745528Untagged control traffic on L3 interface will be dropped on Junos OS Evolved based PTX platforms
Product-Group=evo
On all Junos OS Evolved based PTX platforms with physical interface/LAG (Link Aggregation Group) interface in L3 mode, the untagged control traffic on L3 interface gets dropped if lport value of L3 interface matches with lport value of L2 aggregated ethernet (AE) interface in trunk mode.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S7-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.4R1-EVO
1777003PTX10001-36MR: epp_epc_intr_shmem_err seen in logs
Product-Group=evo
PTX10001-36MR : epp_epc_intr_shmem_err seen in logs

Resolved In: evo:21.4R3-S6-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: BX PFE firewall issues
1772149Balerion-FT:Firewall: aftmand-bx cores continuously at JexprHandleFilter:: updatePfeInst, when attaching filter which has 5-tuples+FC+DP+TTL+Fragment+ifl matches
Product-Group=evo
If a filter does not compile due to an unsupported match combination (i.e. the set of matches configured in the filter is not supported by hardware), attaching this filter to an interface will cause aftmand-bx to crash.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: DNX Multicast
1691134Junos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenario (CVE-2024-39519)
Product-Group=evo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82983 [juniper.net] for more information.

Resolved In: evo:22.4R2-EVO evo:22.4R3-S2-EVO evo:23.1R1-EVO evo:23.2R2-S1-EVO evo:23.4R1-S1-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Express PFE MPLS for EVO platforms
1765107Unknown sensors are added in PFE on all Junos OS Evolved platforms
Product-Group=evo
On all Junos OS Evolved platforms, any client (in this case it was LDP), a route (with a sensor attached) is added and deleted immediately. This is a timing issue and easily reproducible.

Resolved In: evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D40-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: SNMP, mib2d issues
1788308[Junos OS Evolved] SNMP cold start trap is not sent out to external server upon system reboot
Product-Group=evo
On Junos OS Evolved platforms, SNMP cold start trap is observed on console log upon system reboot, but it is not sent out to external server.

Resolved In: evo:24.3R1-EVO evo:24.4R1-EVO junos:24.3R1
PR NumberSynopsisCategory: Express PFE MPLS Features
1780226MPLS traffic that reaches the RE does not get subjected to the loopback filter.
Product-Group=evo
MPLS traffic that reaches the RE does not get subjected to the loopback filter. This includes VRF traffic as well as MPLS packets in default (e.g. TTL-1) packets.

Resolved In:
PR NumberSynopsisCategory: ISIS routing protocol
1777702The rpd process crashes after multiple iterations of disable/enable ISIS protocol
Product-Group=evo
On all Junos and Junos Evolved platforms, the rpd process crashes after disabling/enabling the ISIS protocol using the set command. The issue is seen after 2-3 hours of continuous disabling, and enabling the ISIS process with a 90-sec interval between enabling and disabling.

Resolved In: evo:22.3X50-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1719162MPLS LSP stats will not increment post the rpd restart
Product-Group=evo
On all Junos and Junos OS Evolved platforms post rpd restart using cmd "restart routing immediately" mpls lsp statistics will not work.

Resolved In: evo:22.1R3-S6-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D36-EVO evo:22.3X80-D37-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1796344PacketIO PFE process will drop small fragments of TCP and UDP packets destined to the routing engine
Product-Group=evo
On platforms running PacketIO PFE process (MPC10E, MPC11E, MX10K-LC9600, MX304 and all Junos OS Evolved platforms), small fragments of TCP and UDP packets destined to the routing engine will be dropped.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S5-J4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Trio LU and LUSS SW driver
1735490Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash (CVE-2024-39539)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA82999 [juniper.net] for more information.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S10 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1

Modification History

First publication 2024-07-16