Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved software

Alert Description

 

Alert Description

Junos Software Service Release version 22.4R3-S4-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

 

Junos Software service Release version 22.4R3-S4-EVO is now available.

22.4R3-S4-EVO - List of Fixed issues 

PR NumberSynopsisCategory: EVO interface software
18197802x100G SFP port 0/1/9 channel 0 will go down on the Junos Evolved PTX10001-36MR platform
Product-Group=evo
Severity=Major
On Junos Evolved PTX10001-36MR platform, the 2x100G ZR-M/ZR-M-HP optics on port 0/1/9, channel 0 go down unexpectedly, leading to traffic loss for all traffic passing through channel 0.
PR NumberSynopsisCategory: BBE state synchronization issues
1811787The process bbe-smgd crash will be observed in the Subscriber login/logout scenario
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberSynopsisCategory: Border Gateway Protocol
1761627Increase in task memory observed on 'clear validation database'
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when routing-options session validation is configured, and BGP is configured, task memory usage increases in every iteration on executing 'clear validation database' command.
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=evo
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1767785The EOR message is missed for one peer in a scaled BMP scenario
Product-Group=evo
Severity=Minor
On all Junos and Junos OS Evolved platforms with BGP Monitoring Protocol (BMP) enabled in scaled scenario (4K BGP peers, 6 BMP stations), after disabling/enabling BMP, due to timing issues, one out of six BMP stations will not receive End-of-RIB (EOR) message for one peer. This will not impact routing or data forwarding, however will have impact on data collection.
1770976Routes getting stuck in hidden state forever in BMP scenario
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms where BMP (BGP Monitoring Protocol) is configured, the routes are not removed from the RIB (Routing Information Base) even when the damping timer expires and they are stuck in the hidden 
PR NumberSynopsisCategory: EVO MBB infra related issues and enhancements
1820376Multicast routes can be out of sync due to the quick AE interface flap
Product-Group=evo
Severity=Critical
On Junos Evolved PTX platforms, due to quick Aggregated Ethernet (AE) interface flap, Multicast routes can be out of sync between the control plane and the forwarding plane (rpd and Packet Forwarding Engine (PFE)) resulting in traffic drops.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1815166The evo-cda-bt process crash and error logs are observed with AE member interfaces on non-zero PFEs
Product-Group=evo
Severity=Major
On Junos Evolved PTX platforms, if the AE (Aggregated Ethernet) member interfaces are present only on non-zero (PFEs) Packet Forwarding Engine, the evo-cda-bt process crash is observed for releases below 21.4R1-EVO and beyond 21.4R1-EVO releases error logs are observed which have no impact.
PR NumberSynopsisCategory: Layer 2 Circuit issues
1768323JUNOS and JUNOS EVO-RPD process crash under High Availability Route Engine (RE) scenarios when L2circuits are enabled
Product-Group=evo
Severity=Major
Routing Protocol Daemon (RPD) process crash when l2circuits are enabled in scenarios with backup Route Engine (RE).
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1792672License is lost on NG-RE platforms after device/routing-engine reboot
Product-Group=evo
Severity=Major
On NG-RE (Next Generation Routing Engine) platforms, license is lost after restarting device/routing-engine. If any service depends on that license, that service will be impacted.
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1727528The rpd process can crash during a race condition when BGP rib-sharding is configured
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when BGP RIB sharding is configured, the rpd process crashes during a rare race condition where multiple threads try to initialise a single global variable. During the rpd crash and restart, all routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=evo
Severity=Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
 
 

22.4R3-S4-EVO - List of Known issues 

PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1777003PTX10001-36MR: epp_epc_intr_shmem_err seen in logs
Product-Group=evo
On a BT-base PTX platform, you may see the "epp_epc_intr_shmem_err" in its Syslog when a vlan id is missing from an interface.

Resolved In: evo:21.4R3-S6-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:21.4X9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-S3-J3-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.

Resolved In: evo:21.4R3-S9-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.1R1-EVO junos:22.4R3-S5 junos:23.4R2-S3 junos:24.1R1 junos:24.2R1-S1 junos:24.2R2
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1784818The non-root user will not be able to copy files
Product-Group=evo
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.

Resolved In: evo:21.4X9-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO junos:20.3X75-D36 junos:21.4R3-S9 junos:22.3R3-S4 junos:22.4R3-S4 junos:23.2R2 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.3R2
1821845The system scripts refresh will fail when using load CLI option
Product-Group=evo
On all Junos and Junos OS Evolved platforms when the 'edit system scripts' hierarchy configuration is changed using loading a configuration from a file or the terminal using 'load' option, the scripts refresh will fail.

Resolved In: evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:23.4R2-S2-EVO evo:23.4X31-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:22.4R3-S4 junos:23.2R2-S2 junos:23.4R2-S1 junos:24.2R1-S1 junos:24.3R1 junos:24.4R1

 

Modification History

First publication 2024-09-18