Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX and QFX platforms running Junos Evolved software

Alert Description

Alert Description

Junos Software Service Release version 21.4R3-S9-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 21.4R3-S9-EVO is now available.

21.4R3-S9-EVO - List of Fixed issues

PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1820001Multiple processes on both the REs are crashing
Product-Group=evo
Severity=Critical
On Junos MX platforms, when a Stats DB corrupt entry in encountered, several processes related to subscriber management were high like CPU/Memory and statsd and authd both continuously crashing in both REs. As a result subscribers stuck in terminating.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1798164BMP reaches a state where no data is sent out to BMP Station
Product-Group=evo
Severity=Critical
On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), reaches a state where no data is sent out to BMP Station. This is an unexpected behaviour.
1819305BMP gets stuck and does not send data to BMP collector
Product-Group=evo
Severity=Critical
On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), the BMP session stop sending data to an BMP Station. Please refer to TSB83918 [juniper.net] for more details.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1809423Interfaces take a long time to come up after reboot when configured in scaled IFL environment
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR/PTX-10002-36QDD/PTX10004/PTX10008/PTX10016 platforms with scaled L2 & L3 IFLs (Interface Logical Device) the boot time i.e., interfaces to come up will be around 25-30 mins.
PR NumberSynopsisCategory: Host path software for ACX platform
1786574Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhausted (CVE-2024-47490)
Product-Group=evo
Severity=Major
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX Series allows an unauthenticated, network based attacker to cause increased consumption of resources, ultimately resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88115 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO Netstack FIB Service Daemon
1785913Junos OS Evolved: TCP session state is not always cleared on the Routing Engine leading to DoS (CVE-2024-47502)
Product-Group=evo
Severity=Critical
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88132 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1765503Junos OS Evolved: Multiple vulnerabilities resolved in c-ares 1.18.1(CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32067)
Product-Group=evo
Severity=Major
Multiple vulnerabilities in the c-ares component of Juniper Networks Junos OS Evolved have been resolved in c-ares version 1.18.1. Please refer to https://supportportal.juniper.net/JSA88112 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1811300MACSec does not work on some ports on MX platforms with MPC11E line card
Product-Group=evo
Severity=Major
On Junos MX2010/MX2020 platforms with MX2K-MPC11E line cards, and MACSec (IEEE 802.1AE standard) configured on line card ports. When the line card comes online for the first time, it is seen that ports are not being mapped correctly (port group value mismatch between picd and security) resulting in MACSec not working on some ports.
PR NumberSynopsisCategory: EVO MBB infra related issues and enhancements
1820376Multicast routes can be out of sync due to the quick AE interface flap
Product-Group=evo
Severity=Critical
On Junos Evolved PTX platforms, due to quick Aggregated Ethernet (AE) interface flap, Multicast routes can be out of sync between the control plane and the forwarding plane (rpd and Packet Forwarding Engine (PFE)) resulting in traffic drops.
PR NumberSynopsisCategory: Express PFE CoS Features
1768992Drops field in Output Errors are not reporting the Queue drops on Evolved PTX platforms
Product-Group=evo
Severity=Major
Drops field in Output Errors are not reporting the Queue drops on Evolved PTX platforms.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1792128Configuring multiple IFL of different families on Junos QFX10K SP style interfaces leads to traffic loss
Product-Group=evo
Severity=Major
On Junos QFX 10K platforms, traffic drop is seen when multiple interface logical (IFLs) of different families are configured on the same interface physical (IFD) with Service Provide (SP) style configuration and layer 2 (L2) ILF is the first IFL to be created.
1815166The evo-cda-bt process crash and error logs are observed with AE member interfaces on non-zero PFEs
Product-Group=evo
Severity=Major
On Junos Evolved PTX platforms, if the AE (Aggregated Ethernet) member interfaces are present only on non-zero (PFEs) Packet Forwarding Engine, the evo-cda-bt process crash is observed for releases below 21.4R1-EVO and beyond 21.4R1-EVO releases error logs are observed which have no impact.
PR NumberSynopsisCategory: jdhcpd daemon
1822178JUNOS_REG:EX4650-48Y:ZTPv6:Failed to reconnect to device as unable to load configuration to device via shelscript from ztp server
Product-Group=evo
Severity=Major
During ZTP, if shell script is used (for config download), it will not work on EX46* platforms However, if the baseline config is downloaded via regular way (as config file and not shell script), it will work.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
Severity=Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberSynopsisCategory: Protocol Independant Multicast
1709038Junos OS and Junos OS Evolved: Receipt of specific PIM packet causes rpd crash when PIM is configured along with MoFRR (CVE-2024-39558)
Product-Group=evo
Severity=Major
An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically adjacent, unauthenticated attacker sending specific PIM packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS), when PIM is configured with Multicast-only Fast Reroute (MoFRR). Continued receipt and processing of this packet may create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA83018 [juniper.net] for more information.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1709741The rpd process crash on backup RE will be observed during configuration removal or restoration
Product-Group=evo
Severity=Major
The rpd process crash on backup RE will be observed during configuration removal or restoration.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to NETCONF
1819656In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=evo
Severity=Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1822867After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.

 


 

21.4R3-S9-EVO - List of Known issues

PR NumberSynopsisCategory: Border Gateway Protocol
1788543BGP OutQ counter of one of the BGP peers gets stuck after system reboot/restart routing/clear bgp neighbor
Product-Group=evo
On all Junos and Junos Evolved platforms, when there is a high route churn and the system reboot/restart routing/clear bgp neighbor is done, there are some values stuck in the OutQ counter of one of the peers in a group. Due to this, the route updates are not sent which might result in traffic/service impact.

Resolved In: evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
1810617BGP routes with next hops as link-local address are not installed
Product-Group=evo
On all Junos and Junos OS Evolved platforms, BGP (Border Gateway Protocol) routes are not installed on routing table when their next hops are link-local addresses, and unnumbered session and confederation are configured. Missing information in the routing table might cause no route to destination is found or suboptimal path being chosen.

Resolved In: evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
1817834The rpd crashes when stale label entry keeps increasing when knob stale-labels-holddown-period is configured
Product-Group=evo
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:21.4X9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-S3-J3-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1661578Junos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak (CVE-2024-47508)
Product-Group=evo
An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88136 [juniper.net] for more information.

Resolved In: evo:20.4R3-S7-EVO evo:21.2R3-S8-EVO evo:21.3R3-EVO evo:21.4R2-EVO evo:21.4R3-EVO evo:22.1R1-S1-EVO evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1661618Junos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak (CVE-2024-47509)
Product-Group=evo
An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88136 [juniper.net] for more information.

Resolved In: evo:21.4R2-EVO evo:21.4R3-EVO evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1819281JSD coredump during longevity ( collector, BGP peer, prefix, interface ) flaps
Product-Group=evo
On all Junos/EVO platforms JSD core dump might be seen after any of the following events (collector, BGP peer, prefix, interface ) flaps.

Resolved In:
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1818692Configuration commit fails due to mustd process crash
Product-Group=evo
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP

Resolved In: evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R3-S5-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S5 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1645119Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user (CVE-2024-39532)
Product-Group=evo
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. Please refer to https://supportportal.juniper.net/JSA82992 [juniper.net] for more information.

Resolved In: evo:21.4X9-EVO evo:22.2R2-S1-EVO evo:22.2R3-EVO evo:22.3R1-S1-EVO evo:22.3R2-EVO evo:22.4R1-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.1R2-S2 junos:22.2R2-S1 junos:22.2R3 junos:22.3R1-S1 junos:22.3R1-S2 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1 junos:23.2R2-S1
1784818The non-root user will not be able to copy files
Product-Group=evo
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.

Resolved In: evo:21.4X9-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:22.4R0-J0-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:21.4R3-S9 junos:22.3R3-S4 junos:22.4R3-S4 junos:23.2R2 junos:23.4R1-S1 junos:23.4R2 junos:24.1R1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.3R2
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=evo
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1800859Configuration push to device using RPC resulted in incorrect policy order
Product-Group=evo
On all Junos and Junos OS Evolved platforms, RPC command with default-operation replace uses load update instead of load override from Junos 21.1 onwards. Policies could get incorrectly reordered impacting traffic, because load update does not honor the replace: tag present in configuration file loaded.

Resolved In: evo:22.4R3-S5-EVO evo:24.2R1-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S9 junos:22.4R3-S5 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1

Modification History

First publication 2024-10-17