Alert Type
SRN - Software Release Notification
Risk
Risk Description
Low/Notification
Software Release Notification
Impact
Impact Description
Low/Notification
Software Release Notification
Product Affected
ACX EX MX NFX PTX QFX SRX vSRX
Alert Description
Junos Software Service Release version 21.4R3-S8 is now available for download from the Junos software download site
Download Junos Software Service Release:
Go to
Junos Platforms - Download Software page
Input your product in the "Find a Product" search box
From the Type/OS drop-down menu, select
Junos SR
From the Version drop-down menu, select your version
Click the Software tab
Select the Install Package as need and follow the prompts
Solution
Junos Software service Release version 21.4R3-S8 is now available.
21.4R3-S8 - List of Fixed issues
PR Number
Synopsis
Category: Border Gateway Protocol
1778879
Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA83011
[juniper.net]
for more information.
1787290
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/
JSA83015
[juniper.net]
for more information.
1803120
Junos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crash (CVE-2024-39543)
Product-Group=junos
A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to send specific RPKI-RTR packets resulting in a crash, creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/
JSA83004
[juniper.net]
for more information.
PR Number
Synopsis
Category: Track PRs in BGP BMP area & is part of BGP inside RPD.
1685510
With BMP RIB-IN and BMP RIB-OUT configured on MX or PTX Platforms, large number of BGP routes remain in Holddown state after route churn
Product-Group=junos
BGP route stuck in RIB even after BGP peers sent a withdrawal for it.
PR Number
Synopsis
Category: EVPN Layer-2 Forwarding
1807084
The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=junos
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR Number
Synopsis
Category: EX POE
1782445
PoE interfaces will not come up on EX4300-xxP switch after a reboot when part of a Virtual Chassis
Product-Group=junos
After rebooting a mixed Virtual Chassis (VC) of EX4300-xxP and EX4300-MP switches or rebooting a EX4300-xxP member, interfaces with Power over Ethernet (PoE) configured will not come up on EX4300-xxP members.
PR Number
Synopsis
Category: Express PFE L2 fwding Features
1798887
Traffic drops are observed in the EVPN-VXLAN environment having IPv4 and IPv6 address configured in underlay
Product-Group=junos
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
PR Number
Synopsis
Category: MX Inline Jflow
1798466
With scaled routes and flex-flow-sizing configured memory exhaustion will lead to an FPC crash
Product-Group=junos
On all Junos MX platforms with LC(Linecard) MPC (Modular Port Concentrator)4-9 installed, the Linecard crash can be seen in the corner case. This issue will be seen when Jflow is configured with the inline-services flex-flow-sizing enabled and 'flow-table-size' near the total capacity is configured. There will be a traffic impact due to the crash.
PR Number
Synopsis
Category: Flow Module
1719594
Junos OS: SRX Series: Specific traffic leads to a PFE crash (CVE-2024-21586)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/
JSA83195
[juniper.net]
for more information.
1742739
Virtual Routing Instance configured on ingress interface will drop the icmp traffic
Product-Group=junos
On all Junos platforms, when routing instance of type "virtual router" is configured on the interface the ping response packets will get dropped and no ping response will be received on the ingress interface.
1761542
In a chassis cluster setup the flowd crashes and SPC cards will fail
Product-Group=junos
On SRX platforms, in a chassis cluster setup configured in Active/Active mode, the fabric forward packet enters the flow module causing the flow processing daemon (flowd) to crash, impacting the traffic forwarding and failing the Services Processing Card (SPC).
PR Number
Synopsis
Category: SRX Firewall Authentication
1804149
A fwauthd process crash is seen when a user access group name of more than 64 characters is configured
Product-Group=junos
On all SRX platforms, the fwauthd process crash is seen when it processes a user access group name of size more than 64 characters received from authd process. There is no impact to forwarding traffic due to fwauthd crash.
PR Number
Synopsis
Category: IPSEC/IKE VPN
1794895
High CPU on SPU might lead to FPC reboot and VPN traffic impact by not failing over to the backup node
Product-Group=junos
On Junos SRX platforms with a cluster, when a high volume of traffic is observed, high CPU (Central Processing Unit) usage might be seen from the SPUs (Security Processing Units). The FPC (Flexible PIC Concentrator) may reboot, and the IKE SAs (Internet Key Exchange Security Associations) may be cleared and timed out, preventing the VPNs (Virtual Private Networks) from failing over and causing a traffic impact.
1815800
Small memory leak in ikemd process when deleting vpn tunnel.
Product-Group=junos
Small memory leak in ikemd process when deleting vpn tunnel.
PR Number
Synopsis
Category: Security platform jweb support
1736942
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
PR Number
Synopsis
Category: Layer2 forwarding on EX/NTF/PTX/QFX
1803898
Traffic flooding occurs when deactivating and activating interfaces in EVPN scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms, while deactivating/activating the interface, the first control MAC for a BD and IFL combination can get lost when L2alm'd ifbd Mac sequence num is different from what is sent by L2ald. This will lead to traffic flooding for the MAC which will be impacted.
PR Number
Synopsis
Category: PFE Peer Infra
1801535
CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log
Product-Group=junos
On all Junos platforms, CPU usage gets spiked for eventd due to flooding of pfe_khms_spurious_wakeup log. This log is not an error log but still printed under LOG_ERROR and flooded with default log level. This causes restart which will impact normal user traffic.
PR Number
Synopsis
Category: TCP/UDP transport layer
1703044
Protocol Flaps in event of master RE reboot with GRES enabled
Product-Group=junos
On Junos products that have redundant routing engine, protocol flap might be seen when rebooting master RE by CLI command.
PR Number
Synopsis
Category: QFX L2 PFE
1811701
Multiple services and protocols does not work on the backup member with 100G port used as VC interconnect port on QFX5110-48S
Product-Group=junos
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
PR Number
Synopsis
Category: QFX analyzer, sflow
1808041
The dcpfe process crash is seen in case of inline sampling
Product-Group=junos
When configuring inline sampling, if the sFlow collector is reachable through a unilist next-hop with an indirect child, the dcpfe process crashes.
PR Number
Synopsis
Category: SSL Proxy functionality on JUNOS
1753540
The flowd process will crash due to memory stress
Product-Group=junos
On Junos based SRX platforms in a low memory condition, the flowd process will crash because of memory corruption and crash files will be observed. Traffic flow will be impacted till the time flowd restarts.
PR Number
Synopsis
Category: Stout card (MPC7) fabric issues
1766578
The FPC Crash will be observed on Junos MX platforms
Product-Group=junos
On Junos MX platforms with dual RE, repeated reboots of a SCBE2/ SCBE3 (Switch Control Board) during FPC transition state can trigger multiple PCIe (Peripheral Component Interconnect) interface error alarms. This results in input/output failures for the fabric planes on that SCB ( SCBE2/ SCBE3), leading them to enter a faulty state. Consequently, the affected FPC crashes, impacting traffic on the line card.
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1684371
MPC linecard memory leak
Product-Group=junos
Due to a software bug that missing null check while coalescing of memory block, customer can observed memory leaking of the MPC, which will either block the PPPoE/DHCP/L2TP subscribers login, or cause the FPC core dump.
PR Number
Synopsis
Category: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1797496
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
Product-Group=junos
Config login class with allow/deny-configuration-regexps not working as expected with Routing-instances
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1730442
Device boots up even with incompatible configuration
Product-Group=junos
When 'no-validate' option is used during upgrade, presence of configuration not compatible with target software version leads to the device going into amnesiac state on first reboot. But when the device is rebooted again it boots up with the incompatible configuration and SSH (Secure Socket Shell) is restored.
1770643
RPD core seen when groups is activated before corresponding 'apply-groups' in configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when the group is activated after the corresponding 'apply-groups' statement configuration, rpd core is seen.
1794536
The device goes into configuration locked state due to stale mgd
Product-Group=junos
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
PR Number
Synopsis
Category: usf flow and datapath issue on SPC3
1799512
Traffic impact on SPC3-PIC due to high throughput and bursty traffic
Product-Group=junosvae
On Junos MX platforms equipped with SPC3 (Services Processing Card 3), when running on Talus 0x215 version and each SPC3-PIC (Physical Interface Card) handling significantly high throughput along with bursty traffic, will lead to tx_NoDp_drop' to be hit leading to packet drop.
21.4R3-S8 - List of Known issues
PR Number
Synopsis
Category: EX2300/3400 PFE
1695771
Traffic loss is seen when a MAC moves from dot1x port to non-dot1x port
Product-Group=junos
On all Junos and Junos OS Evolved platforms is having dot1x enabled interface. When two or more MAC addresses are learnt on a dot1x port, and if one of them is shifted to a non-dot1x port, the MAC address that was moved is still seen as a MAC-based VLAN entry on the Layer2 Address Learning Manager (l2alm). This could lead to network traffic being lost.
Resolved In:
evo:21.4R3-S4-EVO evo:22.2R3-S4-EVO evo:22.3R2-S1-EVO junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S5 junos:21.3R3-S4 junos:21.4R3-S4 junos:22.1R3-S2 junos:22.2R3 junos:22.3R2-S1 junos:22.3R3 junos:22.4R2 junos:23.1R2 junos:23.2R1
1818760
FPC crashes due to memory corruption with DHCP option 82 enabled
Product-Group=junos
On Junos EX2300, EX3400, EX4300MP, EX4100, EX4400 and QFX5K platforms, it is observed that the FPC (Flexible Physical Interface Card Concentrator) crashes when there is memory over run due to some specific DHCP (Dynamic Host Configuration Protocol) packets utilising option 82. As a result, traffic gets dropped. This is a rare scenario.
Resolved In:
junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: Virtual-chassis platform/chassisd infrastructure PRs for MX
1798681
CHASSISD_IFDEV_RTSLIB_FAILURE: ifdev_create: rtslib_ifdm_add failed (No such file or directory) after creating a virtual interface tunnel
Product-Group=junos
The error messages in question are not-service affecting and would not be noticed by regression scripts.
Resolved In:
junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: ACX LAG infrastructure
1789949
The egress ports on ACX710 incorrectly tagging traffic expected to be untagged over CCC/VPLS interfaces
Product-Group=junos
On Junos ACX710 platforms, untagged packets egressing out of CCC(Circuit Cross Connect)/VPLS(Virtual Private LAN Service) interfaces that perform no-op (No-Operation) at the egress port are incorrectly tagged impacting the traffic to CE (Customer Edge) device.
Resolved In:
junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: EX4100 VC
1648310
For EX4100 and EX3400 Virtual Chassis switches, Ping is not working for some irbs after Master reboot and traffic loss is observed
Product-Group=junos
The message was not sent to the member from the master . mac-peristence-timer does not work correctly in releases 21.4R3-S5, 21.4R3-S8. The fix is available from 22.2 release onwards.
Resolved In:
junos:22.2R1 junos:22.3R1
PR Number
Synopsis
Category: EX interfaces issues
1734938
On EX3400, when the physical LED is green, show chassis Led status for SFP-T may show as OFF.
Product-Group=junos
On EX3400, when the physical LED is green, show chassis Led status for SFP-T may show as OFF.
Resolved In:
PR Number
Synopsis
Category: Express PFE L2 fwding Features
1792128
Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=junos
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
Resolved In:
evo:24.2R2-EVO evo:24.3R1-EVO junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: SRX4100/SRX4200 platform software
1808353
Interface not processing traffic after "monitor traffic interface" command is issued for an interface
Product-Group=junos
Starting and stopping the "monitor traffic interface" or tcpdump, traffic may be dropped. However, keeping the "monitor traffic interface" or tcpdump running, ensures that traffic will function properly.
Resolved In:
junos:23.2R2-S2 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: BSDX Software installation issues
1783119
Delays may occur during the upgrade process due to UFS status set to mode enable
Product-Group=junos
In USF mode enabled router, While upgrading router having scaled services AMS config with "load-balancing-options disable-hash", Router continuously dumps "'disable-hash' knob is only allowed in USF mode" error. This delays the bootup time with scaled config
Resolved In:
junos:21.2R3-S8 junos:22.1R3-S6 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: Flow Module
1762801
Packet routed to wrong destination on Junos SRX platforms when TCP proxy and reverse-route-packet-mode-vr is configured
Product-Group=junos
On Junos SRX platforms, when (Transmission Control Protocol TCP) proxy and reverse-route-packet-mode-vr option is enabled, flow daemon (flowd) uses incorrect routing table information for reverse packet route lookup causing the packet to route to wrong destination.
Resolved In:
junos:21.4R3-S6 junos:23.2R2 junos:23.4R1 junos:24.1R1
1791633
Packets over GRE or IPIP or GRE(PMI) will not reach destination
Product-Group=junos
On Junos platforms with GRE or GRE(PMI) or IPIP tunnels, when tunnel TTL(Time To Live) is set to 1 in the CLI, the traffic sent over GRE or IPIP or GREoIPSec tunnel does not reach its destination.
Resolved In:
junos:21.2R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: Security platform jweb support
1736942
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control important environment variables (CVE-2023-36845)
Product-Group=junos
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to control certain, important environments variables. Utilizing a crafted request an attacker is able to modify a certain PHP environment variable leading to partial loss of integrity, which may allow chaining to other vulnerabilities. For more information see https://kb.juniper.net/
JSA72300
[juniper.net]
Resolved In:
junos:19.1R3-S11 junos:19.2R3-S8 junos:19.3R3-S9 junos:19.4R3-S13 junos:20.4R3-S9 junos:21.2R3-S7 junos:21.2X32-D20 junos:21.3R3-S5 junos:21.4R3-S5 junos:21.4R3-S8 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.4R1 junos:23.4R2
PR Number
Synopsis
Category: Layer 2 Control Module
1686097
The l2ald crash seen after zeroize
Product-Group=junos
One time l2ald (Layer 2 Address Learning Daemon) crash will be seen once the box comes up after zeroize. There will be no service impact due to this.
Resolved In:
junos:22.2R3 junos:22.3R1-S1 junos:22.3R2 junos:22.4R1 junos:23.1R1
PR Number
Synopsis
Category: lldp sw on MX platform
1811545
The LLDP neighborship does not recover on ae interfaces
Product-Group=junos
When LLDP is configured on interface all and there are ae interfaces configured, to disable LLDP on one of the ae "set protocols lldp interface is done". To enable it back when rollback is done for reverting disable config, ae is not participating in LLDP neighborship and this happening because PFE stopped sending packets to control plane because on rollback L2CPD did not sent LLDP ENABLE for its child interface to PFE and LLDP on child interface was still set to disabled for PFE.
Resolved In:
evo:22.3X50-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S7-J17 junos:21.2R3-S8-J2 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: Odin Timing software
1745604
[TWM Clocking Solution] - chassis clock status should not move to "holdover" while switching between PTP path alone
Product-Group=junos
[TWM Clocking Solution] - chassis clock status should not move to "holdover" while switching between PTP path alone
Resolved In:
junos:20.4R3-S10 junos:21.2R3-S7 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR Number
Synopsis
Category: FreeBSD Kernel Infrastructure
1592495
Recovery snapshot creation fails due to a lack of storage on the OAM partition
Product-Group=junos
On EX2300/EX3400/EX2300-48MP platforms, the recovery snapshot creation fails due to a lack of storage on the Operations, Administration, and Management (OAM) partition.
Resolved In:
junos:23.4R2 junos:24.1R1 junos:24.2R1
PR Number
Synopsis
Category: Protocol Independant Multicast
1720240
RPD process crashes on all Junos and Junos OS Evolved platforms after adding static route to the VRF in some scenarios
Product-Group=junos
When static route is added to the VRF (Virtual Routing and Forwarding), and mc-ip (multicast-ip) and the PIM (Protocol Independent Multicast) instance get deleted in some scenarios, the RPD process crash is seen on all Junos and Junos OS Evolved platforms.
Resolved In:
evo:22.2R3-S2-EVO evo:22.3R3-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.2R3-S2 junos:22.3R3-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1-S2 junos:23.2R2 junos:23.3R1
1795964
The rpd process crash is seen when routing-instances name length is greater than 60 characters
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Protocol Independent Multicast (PIM) enabled under Routing-instance, the Routing Protocol Daemon (rpd) process crash is seen when the routing instance (RI) name length is greater than 60 characters. Due to the rpd process crash, protocols will be impacted and traffic loss will be seen.
Resolved In:
evo:22.3R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:22.3R3-S3 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: qfx-sw-mclag
1742613
Race condition where FLOOD ROUTE DEL event can cause l2ald crash.
Product-Group=junos
When system comes up with BULK L2 config, a subsequent CONFIG delete in a way that L2ALD is still not finished processing the config create, could lead to a race condition where FLOOD ROUTE DEL event can cause l2ald crash.
Resolved In:
evo:22.2R3-S3-EVO evo:22.3R3-S2-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR Number
Synopsis
Category: QFX EVPN / VxLAN
1783397
The fxpc process crash and the device reboots after deleting Aggregated Ethernet (AE) Interface along with its associated physical interface and then applying new interface configuration on the associated physical interface in an EVPN-VXLAN scenario
Product-Group=junos
On an Ethernet Virtual Private Network (EVPN) / Virtual eXtensible Local-Area Network (VXLAN) scenario, after removing an Aggregated Ethernet (AE) Interface along with its associated physical interface on a QFX5k series device and then applying any configuration to the physical interface, the fxpc process crashes and the device undergoes an automatic reboot.
Resolved In:
junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S3 junos:22.3R3-S3 junos:22.4R3-S2 junos:23.2R2 junos:23.4R1-S1 junos:24.1R1 junos:24.2R1 junos:24.2R2
1798684
On Junos QFX5K, EX4100, EX4300, EX4400 and EX4650, type 5 tunnel traffic loss observed when the last IRB configuration is deleted
Product-Group=junos
On all Junos QFX5K, EX4100, EX4300, EX4400 and EX4650 platforms with EVPN-VxLAN (Ethernet Virtual Private Network-Virtual Extensible LAN), deleting the last IRB (Integrated Routing and Bridging) configuration while still having type 5 tunnels installed results in type 5 tunnel traffic loss when type 5 tunnel MAC (Media Access Control ) is same as global/chassis IRB MAC.
Resolved In:
junos:23.4R2 junos:24.2R2 junos:24.3R1
1806114
Multicast nexthop delete causes nexthop stale entries which fail when the same nexthop is reused in VXLAN VLAN creation
Product-Group=junos
On all Junos QFX5K and EX4K platforms, when L3 multicast nexthop entries are deleted when configured with IRB or switched from non-default to default VRF, stale entries from the multicast NH (NextHop) delete cause reusing of stale nexthop in VXLAN (Virtual Extensible LAN) and subsequent creation of VXLAN VLAN fails.
Resolved In:
junos:22.2R3-S4 junos:22.4R3-S2 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: QFX5100 Platfom related issues. CPLD, FPGA, FRU, Host, RE
1694522
High memory utilization on switch after the code upgrade to 20.4 or later
Product-Group=junos
There is increase in memory footprint across different demons after an image upgrade resulting increase in the system memory.
Resolved In:
PR Number
Synopsis
Category: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1757704
JUNOS_REG: QFX5110-48S : "mge" interface is going down after performing soft OIR
Product-Group=junos
this is an issue with SOFT OIR, which is used for internal debugging purposes.
Resolved In:
PR Number
Synopsis
Category: ZT/YT pfe infra issues
1796344
PacketIO PFE process will drop small fragments of TCP and UDP packets destined to the routing engine
Product-Group=junos
On platforms running PacketIO PFE process (MPC10E, MPC11E, MX10K-LC9600, MX304 and all Junos OS Evolved platforms), small fragments of TCP and UDP packets destined to the routing engine will be dropped.
Resolved In:
evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S5-J4 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: ZT/YT pfe firewall software
1802341
Filter will be configured with incorrect vlan-IDs and commit error will not be displayed
Product-Group=junos
On mx10008 platform, filter will be configured with incorrect vlan-IDs and commit error will not be displayed if vlan-ID is not configured in the range of 0-4095 which is syntactically incorrect.
Resolved In:
evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR Number
Synopsis
Category: UI Infrastructure - mgd, DAX API, DDL/ODL
1645119
Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=junos
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/
JSA82992
[juniper.net]
for more information.
Resolved In:
evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R1-S1-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:22.1R2-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S1 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1 junos:23.2R2-S1
PR Number
Synopsis
Category: web filterig issues
1772232
[SRX] Flowd core is generated by UTM web-filtering
Product-Group=junos
On SRX platform, flowd core might be generated when when TCP flow session for HTTP traffic is in error state due to some reason and UTM WF trying to apply fallback action.
Resolved In:
junos:20.4R3-S10 junos:21.2R3-S8 junos:22.2R3-S4 junos:22.4R3-S2 junos:23.2R2 junos:23.4R2 junos:24.1R1
1806786
UTM Web filtering does not work for HTTPS traffic sent from Google Chrome browser or MS Edge v124
Product-Group=junos
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
Resolved In:
junos:21.2X32-D20 junos:21.2X32-D30 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR Number
Synopsis
Category: usf nat related issues
1802242
Interim logs for deterministic NAT are not generated as per the modified time interval
Product-Group=junos
On all MX platforms, the configuration change done to interim logging interval for deterministic Network Address Translation (NAT) does not come into effect. Even after modifying the interval value from T1 to T2, logs still get generated at the interval T1.
Resolved In:
junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
Modification History
First publication 2024-07-19
21.4R3-S8: Software Release Notification for JUNOS Software