Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX NFX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 21.4R3-S8 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution


Junos Software service Release version 21.4R3-S8 is now available.

21.4R3-S8 - List of Fixed issues 

PR NumberSynopsisCategory: Border Gateway Protocol
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1787290Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.
1803120Junos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crash (CVE-2024-39543)
Product-Group=junos
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83004 [juniper.net] for more information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1685510With BMP RIB-IN and BMP RIB-OUT configured on MX or PTX Platforms, large number of BGP routes remain in Holddown state after route churn
Product-Group=junos
BGP route stuck in RIB even after BGP peers sent a withdrawal for it.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=junos
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: EX POE
1782445PoE interfaces will not come up on EX4300-xxP switch after a reboot when part of a Virtual Chassis
Product-Group=junos
After rebooting a mixed Virtual Chassis (VC) of EX4300-xxP and EX4300-MP switches or rebooting a EX4300-xxP member, interfaces with Power over Ethernet (PoE) configured will not come up on EX4300-xxP members.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1798887Traffic drops are observed in the EVPN-VXLAN environment having IPv4 and IPv6 address configured in underlay
Product-Group=junos
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
PR NumberSynopsisCategory: MX Inline Jflow
1798466With scaled routes and flex-flow-sizing configured memory exhaustion will lead to an FPC crash
Product-Group=junos
On all Junos MX platforms with LC(Linecard) MPC (Modular Port Concentrator)4-9 installed, the Linecard crash can be seen in the corner case. This issue will be seen when Jflow is configured with the inline-services flex-flow-sizing enabled and 'flow-table-size' near the total capacity is configured. There will be a traffic impact due to the crash.
PR NumberSynopsisCategory: Flow Module
1719594Junos OS: SRX Series: Specific traffic leads to a PFE crash (CVE-2024-21586)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA83195 [juniper.net] for more information.
1742739Virtual Routing Instance configured on ingress interface will drop the icmp traffic
Product-Group=junos
On all Junos platforms, when routing instance of type "virtual router" is configured on the interface the ping response packets will get dropped and no ping response will be received on the ingress interface.
1761542In a chassis cluster setup the flowd crashes and SPC cards will fail
Product-Group=junos
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).
PR NumberSynopsisCategory: SRX Firewall Authentication
1804149A fwauthd process crash is seen when a user access group name of more than 64 characters is configured
Product-Group=junos
On all SRX platforms, the fwauthd process crash is seen when it processes a user access group name of size more than 64 characters received from authd process. There is no impact to forwarding traffic due to fwauthd crash.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1794895High CPU on SPU might lead to FPC reboot and VPN traffic impact by not failing over to the backup node
Product-Group=junos
On Junos SRX platforms with a cluster, when a high volume of traffic is observed, high CPU (Central Processing Unit) usage might be seen from the SPUs (Security Processing Units). The FPC (Flexible PIC Concentrator) may reboot, and the IKE SAs (Internet Key Exchange Security Associations) may be cleared and timed out, preventing the VPNs (Virtual Private Networks) from failing over and causing a traffic impact.
1815800Small memory leak in ikemd process when deleting vpn tunnel.
Product-Group=junos
Small memory leak in ikemd process when deleting vpn tunnel.
PR NumberSynopsisCategory: Security platform jweb support
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1803898Traffic flooding occurs when deactivating and activating interfaces in EVPN scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while deactivating/activating the interface, the first control MAC for a BD and IFL combination can get lost when L2alm'd ifbd Mac sequence num is different from what is sent by L2ald. This will lead to traffic flooding for the MAC which will be impacted.
PR NumberSynopsisCategory: PFE Peer Infra
1801535CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR NumberSynopsisCategory: TCP/UDP transport layer
1703044Protocol Flaps in event of master RE reboot with GRES enabled
Product-Group=junos
On Junos products that have redundant routing engine, protocol flap might be seen when rebooting master RE by CLI command.
PR NumberSynopsisCategory: QFX L2 PFE
1811701Multiple services and protocols does not work on the backup member with 100G port used as VC interconnect port on QFX5110-48S
Product-Group=junos
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
PR NumberSynopsisCategory: QFX analyzer, sflow
1808041The dcpfe process crash is seen in case of inline sampling
Product-Group=junos
When configuring inline sampling, if the sFlow collector is reachable through a unilist next-hop with an indirect child, the dcpfe process crashes.
PR NumberSynopsisCategory: SSL Proxy functionality on JUNOS
1753540The flowd process will crash due to memory stress
Product-Group=junos
On Junos based SRX platforms in a low memory condition, the flowd process will crash because of memory corruption and crash files will be observed. Traffic flow will be impacted till the time flowd restarts.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1766578The FPC Crash will be observed on Junos MX platforms
Product-Group=junos
On Junos MX platforms with dual RE, repeated reboots of a SCBE2/ SCBE3 (Switch Control Board) during FPC transition state can trigger multiple PCIe (Peripheral Component Interconnect) interface error alarms. This results in input/output failures for the fabric planes on that SCB ( SCBE2/ SCBE3), leading them to enter a faulty state. Consequently, the affected FPC crashes, impacting traffic on the line card.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1684371MPC linecard memory leak
Product-Group=junos
Due to a software bug that missing null check while coalescing of memory block, customer can observed memory leaking of the MPC, which will either block the PPPoE/DHCP/L2TP subscribers login, or cause the FPC core dump.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=junos
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1730442Device boots up even with incompatible configuration
Product-Group=junos
When 'no-validate' option is used during upgrade, presence of configuration not compatible with target software version leads to the device going into amnesiac state on first reboot. But when the device is rebooted again it boots up with the incompatible configuration and SSH (Secure Socket Shell) is restored.
1770643RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1794536The device goes into configuration locked state due to stale mgd
Product-Group=junos
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1799512Traffic impact on SPC3-PIC due to high throughput and bursty traffic
Product-Group=junosvae
On Junos MX platforms equipped with SPC3 (Services Processing Card 3), when running on Talus 0x215 version and each SPC3-PIC (Physical Interface Card) handling significantly high throughput along with bursty traffic, will lead to tx_NoDp_drop' to be hit leading to packet drop.
 
 

21.4R3-S8 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1695771Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.

Resolved In: evo:21.4R3-S4-EVO evo:22.2R3-S4-EVO evo:22.3R2-S1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
1818760FPC crashes due to memory corruption with DHCP option 82 enabled
Product-Group=junos
On Junos EX2300, EX3400, EX4300MP, EX4100, EX4400 and QFX5K platforms, it is observed that the FPC (Flexible Physical Interface Card Concentrator) crashes when there is memory over run due to some specific DHCP (Dynamic Host Configuration Protocol) packets utilising option 82. As a result, traffic gets dropped. This is a rare scenario.

Resolved In: junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Virtual-chassis platform/chassisd infrastructure PRs for MX
1798681CHASSISD_IFDEV_RTSLIB_FAILURE: ifdev_create: rtslib_ifdm_add failed (No such file or directory) after creating a virtual interface tunnel
Product-Group=junos
The error messages in question are not-service affecting and would not be noticed by regression scripts.

Resolved In: junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: ACX LAG infrastructure
1789949The egress ports on ACX710 incorrectly tagging traffic expected to be untagged over CCC/VPLS interfaces
Product-Group=junos
On Junos ACX710 platforms, untagged packets egressing out of CCC(Circuit Cross Connect)/VPLS(Virtual Private LAN Service) interfaces that perform no-op (No-Operation) at the egress port are incorrectly tagged impacting the traffic to CE (Customer Edge) device.

Resolved In: junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: EX4100 VC
1648310For EX4100 and EX3400 Virtual Chassis switches, Ping is not working for some irbs after Master reboot and traffic loss is observed
Product-Group=junos
The message was not sent to the member from the master . mac-peristence-timer does not work correctly in releases 21.4R3-S5, 21.4R3-S8. The fix is available from 22.2 release onwards.

Resolved In: junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: EX interfaces issues
1734938On EX3400, when the physical LED is green, show chassis Led status for SFP-T may show as OFF.
Product-Group=junos
On EX3400, when the physical LED is green, show chassis Led status for SFP-T may show as OFF.

Resolved In:
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1792128Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1808353Interface not processing traffic after "monitor traffic interface" command is issued for an interface
Product-Group=junos
Starting and stopping the "monitor traffic interface" or tcpdump, traffic may be dropped. However, keeping the "monitor traffic interface" or tcpdump running, ensures that traffic will function properly.

Resolved In: junos:23.2R2-S2 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: BSDX Software installation issues
1783119Delays may occur during the upgrade process due to UFS status set to mode enable
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config

Resolved In: junos:21.2R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Flow Module
1762801Packet routed to wrong destination on Junos SRX platforms when TCP proxy and reverse-route-packet-mode-vr is configured
Product-Group=junos
On Junos SRX platforms, when (Transmission Control Protocol TCP) proxy and reverse-route-packet-mode-vr option is enabled, flow daemon (flowd) uses incorrect routing table information for reverse packet route lookup causing the packet to route to wrong destination.

Resolved In: junos:21.4R3-S6 junos:23.2R2 junos:23.4R1 junos:24.1R1
1791633Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.

Resolved In: junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Security platform jweb support
1736942Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/JSA72300 [juniper.net]

Resolved In: junos:19.1R3-S11 junos:19.2R3-S8 junos:19.3R3-S9 junos:19.4R3-S13 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S5 junos:21.4R3-S8 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1 junos:23.4R2
PR NumberSynopsisCategory: Layer 2 Control Module
1686097The l2ald crash seen after zeroize
Product-Group=junos
One time l2ald (Layer 2 Address Learning Daemon) crash will be seen once the box comes up after zeroize. There will be no service impact due to this.

Resolved In: junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR NumberSynopsisCategory: lldp sw on MX platform
1811545The LLDP neighborship does not recover on ae interfaces
Product-Group=junos
When LLDP is configured on interface all and there are ae interfaces configured, to disable LLDP on one of the ae "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, ae is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.

Resolved In: evo:22.3X50-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S7-J17 junos:21.2R3-S8-J2 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: Odin Timing software
1745604[TWM Clocking Solution] - chassis clock status should not move to "holdover" while switching between PTP path alone
Product-Group=junos
[TWM Clocking Solution] - chassis clock status should not move to "holdover" while switching between PTP path alone

Resolved In: junos:20.4R3-S10 junos:21.2R3-S7 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1592495Recovery snapshot creation fails due to a lack of storage on the OAM partition
Product-Group=junos
On EX2300/EX3400/EX2300-48MP platforms, the recovery snapshot creation fails due to a lack of storage on the Operations, Administration, and Management (OAM) partition.

Resolved In: junos:23.4R2 junos:24.1R1 junos:24.2R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1720240RPD process crashes on all Junos and Junos OS Evolved platforms after adding static route to the VRF in some scenarios
Product-Group=junos
When static route is added to the VRF (Virtual Routing and Forwarding), and mc-ip (multicast-ip) and the PIM (Protocol Independent Multicast) instance get deleted in some scenarios, the RPD process crash is seen on all Junos and Junos OS Evolved platforms.

Resolved In: evo:22.2R3-S2-EVO evo:22.3R3-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1
1795964The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.

Resolved In: evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: qfx-sw-mclag
1742613Race condition where FLOOD ROUTE DEL event can cause l2ald crash.
Product-Group=junos
When system comes up with BULK L2 config, a subsequent CONFIG delete in a way that L2ALD is still not finished processing the config create, could lead to a race condition where FLOOD ROUTE DEL event can cause l2ald crash.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1783397The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.

Resolved In: junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:24.1R1 junos:24.2R1 junos:24.2R2
1798684On Junos QFX5K, EX4100, EX4300, EX4400 and EX4650, type 5 tunnel traffic loss observed when the last IRB configuration is deleted
Product-Group=junos
On all Junos QFX5K, EX4100, EX4300, EX4400 and EX4650 platforms with EVPN-VxLAN (Ethernet Virtual Private Network-Virtual Extensible LAN), deleting the last IRB (Integrated Routing and Bridging) configuration while still having type 5 tunnels installed results in type 5 tunnel traffic loss when type 5 tunnel MAC (Media Access Control ) is same as global/chassis IRB MAC.

Resolved In: junos:23.4R2 junos:24.2R2 junos:24.3R1
1806114Multicast nexthop delete causes nexthop stale entries which fail when the same nexthop is reused in VXLAN VLAN creation
Product-Group=junos
On all Junos QFX5K and EX4K platforms, when L3 multicast nexthop entries are deleted when configured with IRB or switched from non-default to default VRF, stale entries from the multicast NH (NextHop) delete cause reusing of stale nexthop in VXLAN (Virtual Extensible LAN) and subsequent creation of VXLAN VLAN fails.

Resolved In: junos:22.2R3-S4 junos:22.4R3-S2 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1694522High memory utilization on switch after the code upgrade to 20.4 or later
Product-Group=junos
There is increase in memory footprint across different demons after an image upgrade resulting increase in the system memory.

Resolved In:
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1757704JUNOS_REG: QFX5110-48S : "mge" interface is going down after performing soft OIR
Product-Group=junos
this is an issue with SOFT OIR, which is used for internal debugging purposes.

Resolved In:
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1796344PacketIO PFE process will drop small fragments of TCP and UDP packets destined to the routing engine
Product-Group=junos
On platforms running PacketIO PFE process (MPC10E, MPC11E, MX10K-LC9600, MX304 and all Junos OS Evolved platforms), small fragments of TCP and UDP packets destined to the routing engine will be dropped.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S5-J4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1802341Filter will be configured with incorrect vlan-IDs and commit error will not be displayed
Product-Group=junos
On mx10008 platform, filter will be configured with incorrect vlan-IDs and commit error will not be displayed if vlan-ID is not configured in the range of 0-4095 which is syntactically incorrect.

Resolved In: evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1645119Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=junos
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/JSA82992 [juniper.net] for more information.

Resolved In: evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R1-S1-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:22.1R2-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S1 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1 junos:23.2R2-S1
PR NumberSynopsisCategory: web filterig issues
1772232[SRX] Flowd core is generated by UTM web-filtering
Product-Group=junos
On SRX platform, flowd core might be generated when when TCP flow session for HTTP traffic is in error state due to some reason and UTM WF trying to apply fallback action.

Resolved In: junos:20.4R3-S10 junos:21.2R3-S8 junos:22.2R3-S4 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
1806786UTM Web filtering does not work for HTTPS traffic sent from Google Chrome browser or MS Edge v124
Product-Group=junos
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.

Resolved In: junos:21.2X32-D20 junos:21.2X32-D30 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: usf nat related issues
1802242Interim logs for deterministic NAT are not generated as per the modified time interval
Product-Group=junos
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.

Resolved In: junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1

 

Modification History

First publication 2024-07-19