Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX series running Junos Evolved software

Alert Description

Junos Evolved Software Service Release version 23.2R2-S2-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution


Junos Software service Release version 23.2R2-S2-EVO is now available.

23.2R2-S2-EVO - List of Fixed issues 

PR NumberSynopsisCategory: Issues with pluggable optics
1812634ZR optics doesn't work when wavelength 1548.91 is configured
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, ZR/ZR-M/ZR-M-HP modules configured with wavelength 1548.91nm can lead to link failures.
PR NumberSynopsisCategory: Border Gateway Protocol
1789863The rpd crash can be seen when large number of VRF instances are created and bgp peering terminated
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, the rpd (Routing Protocol Daemon) crash will be observed when BGP (Border Gateway Protocol) is terminated by the user and if large number of VRF instances are created. This happens as some BGP internal data structure is not cleaned up properly. This crash can lead to a temporary traffic drop, but the system will automatically recover.
PR NumberSynopsisCategory: PTX10003 Platform related issues
1748000Prolix-LTS22: log-out-on-disconnect not supported on PTX10003 platforms and console might become unresponsive.
Product-Group=evo
Severity=Major
 "log-out-on-disconnect" is not supported on PTX10003 platforms and console might become unresponsive.
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1818577Traffic drop seen after updating firewall filter
Product-Group=evo
Severity=Major
On QFX5130-32CD platform, committing a configuration change that leads to a firewall filter update (i.e. adding or modifying terms), if firewall filter is applied to a loopback interface, packets punted to CPU will be dropped while filter is updated.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1809423Interfaces take a long time to come up after reboot when configured in scaled IFL environment
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR/PTX-10002-36QDD/PTX10004/PTX10008/PTX10016 platforms with scaled L2 & L3 IFLs (Interface Logical Device) the boot time i.e., interfaces to come up will be around 25-30 mins.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1784438MX304 not reachable with the power-off failure on the PIC
Product-Group=evo
Severity=Major
When an MX304 LMIC is offline due to a power issue, it may take up to 20 minutes for the LMIC to come back online. You can configure event-options to reduce the time to restart the LMIC. See also: TSB83899 [juniper.net]
PR NumberSynopsisCategory: CoS support on DNX
1752960DSCP v4/v6 bits preservation issue on AE interfaces in ACX7K platforms
Product-Group=evo
Severity=Major
The issue causes DSCP v4 and v6 bits not to be preserved on AE (Aggregated Ethernet) interfaces, affecting the traffic flow between routers in L3VPN setups. This is applicable to all ACX7K products from release 22.4 onwards.
PR NumberSynopsisCategory: DNX L2 related features
1802525The MPLS tunnel traffic arriving at the ingress interface would drop on ACX7K platforms when storm control is enabled
Product-Group=evo
Severity=Major
On Junos Evolved ACX7K platforms configured with MPLS tunnel and Storm Control, the Layer 2 or MPLS tunnel-terminated known unicast traffic arriving at the ingress interface assigned with a high drop precedence by the interface-level classifier will get dropped on the interface where storm control profile is active. Due to this, MPLS tunnel traffic may get affected.
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1779524Traffic is dropped when packet-forwarding-options is configured along with global default VRF and management VRF configurations
Product-Group=evo
Severity=Major
On all Junos Evolved ACX platforms, traffic drop is observed along with error messages when the following configuration is done with global default VRF (Virtual Route Forwarding) and management VRF (management instance) configured."set system packet-forwarding-options hw-db-profile l3-xl"
PR NumberSynopsisCategory: DNX Multicast
1816540OSPFv3 neighborship does not form when configured over an IRB interface when MLD snooping is enabled on the Bridge Domain where IRB is hosted
Product-Group=evo
Severity=Major
On all Junos OS Evolved ACX Series platforms, OSPFv3 (Open Shortest Path First version 3) neighborship does not get established over an IRB (Integrated Routing and Bridging) interface when MLD (Multicast Listener Discovery) snooping is enabled for the BD (Bridge Domain) on which the IRB interface is hosted.
PR NumberSynopsisCategory: DNX VPLS
1805586Traffic loss will observed when renaming the VPLS routing-instance leading to MAC learning issues over LSI
Product-Group=evo
Severity=Major
On Junos OS Evolved ACX platforms having VPLS (Virtual Private LAN Service) with LSI (Label-Switched Interface) interface ( "no-tunnel-services") configured, during renaming of VPLS routing-instance multiple times some bridge-domain objects are not properly handled and are reaching PFE (Packet Forwarding Engine) during deletion, leading to LSI interface not getting created in the hardware waiting for the bridge-domain updates which already got deleted. This issue leads to MAC learning over LSI will stop working resulting in traffic loss.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1809956On Junos Evolved and Junos MX platforms with MPC10E/11E/LC9600 line cards traffic drop is seen due to changes in delay measurement profile
Product-Group=evo
Severity=Major
On Junos Evolved and Junos MX240/MX480/MX960/MX2008/MX10008/MX10016/MX2010/MX2020 platforms with MPC10E/11E/LC9600 line cards and MX304 platform, with enhanced-cfm mode enabled and IFL configured with dual tag, when measurement-interval and cycle-time is configured, packets do not get transmitted if there are further changes in the measurement-interval and cycle-time values.
PR NumberSynopsisCategory: Issues related to evo operations - libevo infra, typeinfo ..
1776828The evo-aftmand-bt process crash is observed during an RE switchover
Product-Group=evo
Severity=Major
On Junos Evolved PTX platforms with hundreds of firewall terms configured, an extremely rare timing scenario during Routing Engine (RE) switchover can cause evo-aftmand-bt process on the FPC to crash which can impact traffic services. This issue has only been observed once.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1803441Traffic drop will be observed when the IFLs have vlan-id-list above the vlan-bundling limit
Product-Group=evo
Severity=Major
On all Junos Evolved ACX platforms, there will be a drop in the traffic when the IFLs have vlan-id-list above the vlan-bundling limit. Hence a commit warning must be implemented when number of vlan-bundling is above the hardware limit.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1808779L2ald-agent core and IRB ifl stays Hardware-down after deletion of irb(with virtual-gateway-address config) , readding same virtual-gateway-address as IRB address and move back to irb with same virtual-gateway-address
Product-Group=evo
Severity=Major
l2ald-agent core and IRB ifl may stay in hardware-down state after following irb config changes which involves assigning VGA IP directly to IRB IFL, commit, delete the VGA from IRB IFL and add it as virtual-gateway-address again.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1750699Observing routes missing in few scale VRF configuration after doing "Interface Flap"
Product-Group=evo
Severity=Major
In scaled scenario (1 million BGP routes and 1000 VRF's), interface flap will impact relearning routes with few VRFs and the routes are missing. Clearing BGP neighbors should recover the issue. Issue is applicable to all EVO platforms.
PR NumberSynopsisCategory: EVO MBB infra related issues and enhancements
1820376Multicast routes can be out of sync due to the quick AE interface flap
Product-Group=evo
Severity=Critical
On Junos Evolved PTX platforms, due to quick Aggregated Ethernet (AE) interface flap, Multicast routes can be out of sync between the control plane and the forwarding plane (rpd and Packet Forwarding Engine (PFE)) resulting in traffic drops.
PR NumberSynopsisCategory: Express ptx-evo PFE L3 Features
1816310VRRP is not working for VRRP group 0 when specific Junos OS Evolved platforms are working as master
Product-Group=evo
Severity=Major
VRRP (Virtual Router Redundancy Protocol) will not work when VRRP group 0 is configured and specific Junos OS Evolved platforms (PTX10001/PTX10003/PTX10004/PTX10008/PTX10016) are working as master.
PR NumberSynopsisCategory: SNMP, mib2d issues
1814315There is no option for inband management through SNMPv3 on an interface configured with non-default routing instance
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, the routing instance needs to be specified in the snmpv3 query with -n option for the query to be successfully served.
1815524The mib2d crash is observed on Junos OS Evolved platforms with duplicate SNMP request
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms, the mib2d process crashes when SNMP get request is performed for duplicate OIDs.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=evo
Severity=Major
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: Express PFE FW Features
1812144Shared policer bandwidth doesnt work after removing an interface from AE (aggregated ethernet)
Product-Group=evo
Severity=Major
On the Junos Evolved PTX platforms, when shared bandwidth policers are configured on AE(aggregated ethernet) based interfaces, the bandwidth must be readjusted whenever an interface is added or removed from the bundle. This issue happens when FFT (fast-lookup-filters) is configured. The workaround is to reconfigure the policer or reattach the filter on an interface. The bandwidth adjustment happens automatically for releases where this problem was resolved.
PR NumberSynopsisCategory: ACX7332 & ACX7348 HWD process
1819254Negative values are seen for jnxOperatingUpTime SNMP mib on Junos OS Evolved platforms after ~248 days uptime
Product-Group=evo
Severity=Major
Negative values are observed for jnxOperatingUpTime while using this SNMP mib on Junos OS Evolved platforms after ~248 days uptime.
PR NumberSynopsisCategory: All Guardian (ACX7509) Platform related issues
1803114Interface connected to SFP-T optics fails to come up post switchover
Product-Group=evo
Severity=Major
On certain ACX Junos OS Evolved platforms, the ports equipped with SFP-T will not come up when picd restarts or when picd becomes active on back-up RE (Routing Engine) due to switchover.
PR NumberSynopsisCategory: Platform infra to support jvision
1817967Product annotation is missing for sensors on the MX, PTX, and EX92XX platforms
Product-Group=evo
Severity=Major
Product annotation files with correct product support/exclude information for specific sensors with respect to platform MX, PTX and EX92XX products. Request customer to enable CLI "set services analytics product-path-check no-path-check" configure to override product annotation issue.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where persistent learning is enabled in the EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) scenario, and MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
1822265Host path communication delay seen due to high dcpfe CPU utilization
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, with ARP entries learned on Layer 2 VLANs (VLANs without IRB (Integrated Routing and Bridging) ), the dcpfe CPU goes high when continuous mac-moves are happening during re-arp. This will lead to delays in host path communication and also affect control traffic (ssh, ping etc).
PR NumberSynopsisCategory: For multicast snooping on MX
1710565In a scaled setup mcsnoopd is taking high CPU causing traffic drop
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.
PR NumberSynopsisCategory: OSPF routing protocol
1793148LDP label advertisement is stopped for approximately 25 seconds when micro loop avoidance is enabled in SR over OSPF
Product-Group=evo
Severity=Major
On all Junos platforms that support MLA (Microloop Avoidance), the LDP (Label Distribution Protocol) label advertisement gets stopped for approximately 25 seconds when MLA is enabled in SR (Segment Routing) over OSPF (Open Shortest Path First) and the interface between LDP (Label Distribution Protocol) domain and SR domain is down and coming up.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1797996BGP learning or convergence performance degradation.
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms configured with BGP (Border Gateway Protocol), when there are scaled routes (greater than 1M routes) the BGP learning or convergence performance degradation is observed.
PR NumberSynopsisCategory: Resource Reservation Protocol
1800034Label Switched Path (LSP) traffic drop observed on a transit router with graceful-restart configured after a brief outgoing link flap
Product-Group=evo
Severity=Major
If a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in longer than expected traffic blackholing on the router that is at the downstream end of the flapping link.
PR NumberSynopsisCategory: Issues related to control plane security
1741624Junos OS Evolved: A high rate of SSH connections causes a Denial of Service (CVE-2024-39562)
Product-Group=evo
Severity=Critical
A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS) by blocking SSH access for legitimate users. Continued receipt of these connections will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA75724 [juniper.net] for more information.
1780283Junos OS and Junos OS Evolved: Loading a malicious certificate from the CLI may result in a stack-based overflow (CVE-2024-39556)
Product-Group=evo
Severity=Critical
A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to the CLI the ability to load a malicious certificate file, leading to a limited Denial of Service (DoS) or privileged code execution. Please refer to https://supportportal.juniper.net/JSA83016 [juniper.net] for more information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1821845The system scripts refresh will fail when using load CLI option
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.
1825728When using an FQDN (Fully qualified domain Name) in conjunction with the ephemeral configuration database, the MGD process may crash.
Product-Group=evo
Severity=Critical
The MGD process (Junos CLI) will crash if the switch has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP, radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1795952The eventd crashes if eventd traceoptions is enabled
Product-Group=evo
Severity=Major
When traceoptions is enabled for event-options, eventd crash may be observed.
PR NumberSynopsisCategory: Issues related to NETCONF
1792362RPC request for file copy with routing instances is failing
Product-Group=evo
Severity=Major
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
PR NumberSynopsisCategory: VCCP related PRs for virtual-chassis in MX
1801522AE child links in back member is in detached state
Product-Group=evo
Severity=Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberSynopsisCategory: ACX7000 hwd/chassisd software related issues.
1700839ACX reports "/psm/0/ hwdre/0/cm/0/ psm_mcu /psm0/psm_cml_cmd_fault" even though the PSM is in working order
Product-Group=evo
Severity=Minor
ACX reports "/psm/0 /hwdre/0 /cm/0 /psm_mcu/ psm0/psm_cml_cmd_fault" even though the PSM is in working order
1801225Junos OS Evolved ACX platforms is powered down randomly due to incorrect read of temperature sensor
Product-Group=evo
Severity=Major
On ACX platforms running Junos OS Evolved, the device gets powered down due to incorrect reading of a temperature sensor, impacting all the services running on the box.
 
 

23.2R2-S2-EVO - List of Known issues 

PR NumberSynopsisCategory: EVO interface software
1736206The interface comes up with a mismatch FEC after setting FEC91 on one end and will be stuck in down state after deleting FEC91
Product-Group=evo
Severity=Major
The interface comes up with a mismatch FEC after setting FEC91 on one end and will be stuck in down state after deleting FEC91.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D41-EVO evo:22.3X80-D42-EVO evo:23.4R1-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
Severity=Major
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:21.4X9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
Severity=Major
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-S3-J3-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: DNX L2 related features
1756648The evo-pfemand process is observed to crash on Junos Evolved platforms with LACP configuration
Product-Group=evo
Severity=Major
JDI_REG:EVO:ultron: evo-pfemand.re cored at futex_abstimed_wait_cancelable (private=0, abstime=0x7fd17582c870, clockid=0, expected=0, futex_word=0x7fd1479fb570) at ../sysdeps/unix/sysv/linux/futex-internal.h:208

Resolved In: evo:23.4R1-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: EVO Services Jflow PRs for defect & enhancement requests
1816542A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period
Product-Group=evo
Severity=Major
A router running sampling may see the msvcs-db daemon run at 99.9% for an extended period

Resolved In: evo:21.4X9-EVO evo:23.2R2-J11-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: Express PFE CFM
1785008CFM Inline : AE anchor child interface change , CFM sessions go down
Product-Group=evo
Severity=Major
When AE bundle has multiple child links, and thea anchor child link is chaged die to any underlying activity like pfe restart of pfe hosting current anchor child, CFM inline sessions fail to come up on the newly selected anchor child link.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: QFX L2 PFE
1711860The dcpfe process will crash due to memory fragmentation
Product-Group=evo
Severity=Major
On Junos and Junos OS Evolved platforms, the dcpfe (Dense Concentrator Packet Forwarding Engine) process crash will be observed due to memory fragmentation issue. This is a very rare case and would impact traffic as due to dcpfe failure the PFE restarts, so the interfaces will flap.

Resolved In: evo:23.4R1-EVO junos:23.4R1
PR NumberSynopsisCategory: RPD policy options
1807830OSPF neighbourship with IPsec authentication goes down after RE switchover
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, the Open Shortest Path First (OSPF) neighbourship configured with Internet Protocol Security (IPsec) authentication will go down during the Routing Engine (RE) switchover.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1820893Detour path is not coming up when detour hop-limit is set to 255 or high value
Product-Group=evo
Severity=Major
detour might not form when hop-limit is set to be high value

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.4R3-S4 junos:23.2R2-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: RPD API infrastructure
1715599Inconsistent RPD crash found in rt_walk, task_job_run_job_bg, task_scheduler
Product-Group=evo
Severity=Critical
PRPD installed flowspec routes were not deleted on routing-instance delete, leading to RPD crash.

Resolved In: evo:22.3X80-D40-EVO evo:22.3X80-D41-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.4R1 junos:23.4R2 junos:24.1R1
PR NumberSynopsisCategory: PTX10K specific platform PRs
1738854The FPC MEZZ board state becomes unknown with 'Too many open files' error messages due to file descriptor leak in picd process
Product-Group=evo
Severity=Major
On PTX10K Junos OS Evolved platforms, the FPC MEZZ board state becomes unknown with 'Too many open files' error messages due to an FD (File Descriptor) leak in picd (Physical Interface Card Daemon) process.

Resolved In: evo:21.4R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.4R1
PR NumberSynopsisCategory: Trio LU and LUSS SW driver
1735490Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash (CVE-2024-39539)
Product-Group=evo
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA82999 [juniper.net] for more information.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S10 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1801136Configuration in master and backup RE might be out of sync when graceful-switchover is configured
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when graceful-switchover is configured, the configuration on master RE and backup RE might be in out of sync. To recover from this and to avoid problem due to problem delta synchronize, "set system commit no-delta-synchronize" can be configured as work-around (no-delta-synchronize is hidden knob but safe to use). It will enforce entire 'juniper.conf' to synchronize rather than delta changes and will help in this case.

Resolved In:
PR NumberSynopsisCategory: Issues related to NETCONF
1792554JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241
Product-Group=evo
Severity=Minor
JUNOS: Netconf: Edit-config with operation attribute create for existing hierarchy is not working as per RFC 6241

Resolved In:
PR NumberSynopsisCategory: ACX724 timing issues
18081341 second time offset can be seen on ACX7024 in the T-GM setup
Product-Group=evo
Severity=Major
On Junos Evolved platform with PTP (Precision Time Protocol) G.8275.1 profile using T-GM (Telecom Grandmaster) Functionality fixed 1 second time error offset can be seen when tool with built-in GNSS (Global Navigation Satellite System) is used for performance monitoring. This will cause timing functionality failure, there is no impact on regular traffic due to this.

Resolved In: evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO

Modification History

First publication 2024-09-09