Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos Evolved Software

Alert Description

Junos Software Service Release version 22.2R3-S5-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Solution

Junos Software service Release version 22.2R3-S5-EVO is now available.

22.2R3-S5-EVO - List of Fixed issues

PR NumberSynopsisCategory: EVO interface software
1818352The picd process crash will be seen on PTX10001-36MR
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR platforms with Coherent Optics (400G-QDD-ZR, 400G-QDD-ZR-M , 400G-QDD-ZR-M-HP and 100G-ZR), the picd (port interface concentrator daemon) leaks memory during normal operation, which will lead to its crash resulting in traffic loss.
18197802x100G SFP port 0/1/9 channel 0 will go down on the Junos Evolved PTX10001-36MR platform
Product-Group=evo
Severity=Major
On Junos Evolved PTX10001-36MR platform, the 2x100G ZR-M/ZR-M-HP optics on port 0/1/9, channel 0 go down unexpectedly, leading to traffic loss for all traffic passing through channel 0.
PR NumberSynopsisCategory: BBE state synchronization issues
1811787The process bbe-smgd crash will be observed in the Subscriber login/logout scenario
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberSynopsisCategory: Border Gateway Protocol
1692320Deletion and addition of BGP transport-class caused the rpd crash
Product-Group=evo
Severity=Critical
On all Junos and Junos Evolved platforms deletion and addition of transport-class on top of BGP CT configuration and NSR configuration the rpd crash seen. commit synchronization process during config commit doesn't work for auto-created routing instances, created by BGP-CT transport classes.
1778879Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak (CVE-2024-39549)
Product-Group=evo
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1793714BGP routes may not get advertised when always-wait-for-krt-drain is configured with BGP sharding
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when 'delay-route-advertisements always-wait-for-krt-drain' is configured, the EoR (End of Record) from the source peer of the routes is not received in the BGP (Border Gateway Protocol) peer which is sent by a BGP speaker to indicate the end of a record or a sequence of updates. This is due to the BGP router advertiser being stuck in the wait-for-inbound-convergence state, which may cause the KRT (Kernel Routing Table) queue to get stuck, thereby halting the advertisement of BGP routes.
1814083Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39515)
Product-Group=evo
Severity=Critical
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.
1815222Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39516)
Product-Group=evo
Severity=Critical
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled. Please refer to https://supportportal.juniper.net/JSA88100 [juniper.net] for more information.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1819305BMP gets stuck and does not send data to BMP collector
Product-Group=evo
Severity=Critical
On all Junos OS and Junos OS Evolved platforms which supports BMP (BGP Monitoring Protocol), the BMP session stop sending data to an BMP Station. Please refer to TSB83918 [juniper.net] for more details.
PR NumberSynopsisCategory: EVO Layer-2 switching for BCM XGS Platforms
1705911Junos OS Evolved: QFX5000 Series: Configured MAC learning and move limits are not in effect (CVE-2024-47498)
Product-Group=evo
Severity=Critical
An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88128 [juniper.net] for more information.
PR NumberSynopsisCategory: PFE L2 forwarding features on BT based platforms
1809423Interfaces take a long time to come up after reboot when configured in scaled IFL environment
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX10001-36MR/PTX-10002-36QDD/PTX10004/PTX10008/PTX10016 platforms with scaled L2 & L3 IFLs (Interface Logical Device) the boot time i.e., interfaces to come up will be around 25-30 mins.
PR NumberSynopsisCategory: Express BT PFE L3 Features
1737395The FTI tunnel encapsulated traffic will be dropped
Product-Group=evo
Severity=Major
On Junos Evolved platforms, when "tunnel termination" configuration is added and then removed for FTI(Flexible Tunnel Interface) or when FTI is configured with network ports on PFE(Packet Forwarding Engine) other than '0' and device is restarted, the tunnel encapsulated traffic will get dropped.
1784498Higher AE traffic convergence observed in ALB configured AE interface
Product-Group=evo
Severity=Major
On PTX10001-36MR/PTX10004/PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on AE (Aggregated Ethernet) interface and link up/down, the AE interfaces will take higher traffic convergence during FRR (Fast Reroute) compared to regular AE.
1809955On PTX10001 EVO platform, traffic could get dropped unexpectedly due to uRPF failure
Product-Group=evo
Severity=Major
If uRPF is enabled and default route and source route both have same forwarding traits i.e. nexthop, iflistindex etc. then due to FIB compression, the source route might get compressed with default route which could lead to traffic drop due to urpf.
PR NumberSynopsisCategory: EVO ARP related PRs
1775981Duplicate IPv4 address detection error not logged on syslog for Junos Evolved platforms
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, duplicate IPv4 (Internet Protocol Version 4) address detection error is not logged on syslog.
PR NumberSynopsisCategory: software upgrade infra issues
1781632Software upgrade with force option tries to recover space for /var partition and the upgrade fails
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, while doing the upgrade with force option, it is observed that the upgrade checks for /var partition and when /var partition is 80% full, older versions are deleted to recover the space. However, still the upgrade fails and not completed.
PR NumberSynopsisCategory: Interface PRs defect & enhancement requests
1803068ISSU from 23.2R2 to newer releases cause cores
Product-Group=evo
Severity=Major
1. Object data structure was extended for a fix.2. During the extension, the extensions between the releases should match3. There was a mismatch wrt such extensions between the releases which caused the issue.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1808779L2ald-agent core and IRB ifl stays Hardware-down after deletion of irb(with virtual-gateway-address config) , readding same virtual-gateway-address as IRB address and move back to irb with same virtual-gateway-address
Product-Group=evo
Severity=Major
l2ald-agent core and IRB ifl may stay in hardware-down state after following irb config changes which involves assigning VGA IP directly to IRB IFL, commit, delete the VGA from IRB IFL and add it as virtual-gateway-address again.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1750699Observing routes missing in few scale VRF configuration after doing "Interface Flap"
Product-Group=evo
Severity=Major
In scaled scenario (1 million BGP routes and 1000 VRF's), interface flap will impact relearning routes with few VRFs and the routes are missing. Clearing BGP neighbors should recover the issue. Issue is applicable to all EVO platforms.
1765503Junos OS Evolved: Multiple vulnerabilities resolved in c-ares 1.18.1(CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32067)
Product-Group=evo
Severity=Major
Multiple vulnerabilities in the c-ares component of Juniper Networks Junos OS Evolved have been resolved in c-ares version 1.18.1. Please refer to https://supportportal.juniper.net/JSA88112 [juniper.net] for more information.
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1811300MACSec does not work on some ports on MX platforms with MPC11E line card
Product-Group=evo
Severity=Major
On Junos MX2010/MX2020 platforms with MX2K-MPC11E line cards, and MACSec (IEEE 802.1AE standard) configured on line card ports. When the line card comes online for the first time, it is seen that ports are not being mapped correctly (port group value mismatch between picd and security) resulting in MACSec not working on some ports.
PR NumberSynopsisCategory: EVO MBB infra related issues and enhancements
1820376Multicast routes can be out of sync due to the quick AE interface flap
Product-Group=evo
Severity=Critical
On Junos Evolved PTX platforms, due to quick Aggregated Ethernet (AE) interface flap, Multicast routes can be out of sync between the control plane and the forwarding plane (rpd and Packet Forwarding Engine (PFE)) resulting in traffic drops.
PR NumberSynopsisCategory: EVO Socket replication
1594082[PTX EVO] The IPv4/IPv6 BGP session convergence slow when Non Stop Routing (NSR) is enabled
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, the BGP session convergence will be slow however there is not any traffic impact due to this issue. As the convergence is significantly slower when NSR enabled, the FIB programing rate is taking longer than expected time to finish
PR NumberSynopsisCategory: event/op/commit scripts, SLAX, netconf issues
1753283Custom scripts may fail in Evo Single RE platforms
Product-Group=evo
Severity=Major
Custom scripts may fail in Evo Single RE platforms
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1807084The VXLAN traffic drop could be seen after modifying control-word in an EVPN instance
Product-Group=evo
Severity=Major
On MX, QFX and PTX10K line of routers running Junos and Junos OS Evolved with static Virtual Extensible LAN (VXLAN), the Virtual Tunnel Endpoint (VTEP) connections may not work properly after enabling or disabling control-word in the EVPN instance. This could disrupt the connectivity provided by the static VXLAN setup and affect data traffic.
PR NumberSynopsisCategory: Express PFE L2 fwding Features
1815166The evo-cda-bt process crash and error logs are observed with AE member interfaces on non-zero PFEs
Product-Group=evo
Severity=Major
On Junos Evolved PTX platforms, if the AE (Aggregated Ethernet) member interfaces are present only on non-zero (PFEs) Packet Forwarding Engine, the evo-cda-bt process crash is observed for releases below 21.4R1-EVO and beyond 21.4R1-EVO releases error logs are observed which have no impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1800944In EVPN-VXLAN scenario missing destination mac address causes flooding resulting in traffic loss
Product-Group=evo
Severity=Minor
On all Junos and Junos OS Evolved platforms in the EVPN-VXLAN scenario, ipv4 and ipv6 traffic flooding will be seen due to the missing destination MAC address.
1812482Persistent MAC getting stuck in the SRP state results in traffic loss in the EVPN-VxLAN scenario
Product-Group=evo
Severity=Major
On Junos and Junos Evolved platforms, traffic loss is observed when the Persistent MAC gets stuck in the SRP (Static, Remote, Pinned) state and not removed during the "clear persistence mac' operation for some MACs that are getting added with an incorrect flag: SRP. The issue happens when MAC learning happens on Multihoming peers where 'persistent-learning' is enabled in an EVPN-VxLAN (Ethernet VPN-Virtual Extensible LAN) environment. MAC is just marked as Persistent but not installed in the Persistent database.
1816049MAC addresses learnt on interfaces part of VLAN with MAC limiting by interface and "drop-and-log" action configured are cleared after VLAN description is changed
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, when "set vlans switch-options interface-mac-limit packet-action drop-and-log" is configured, changing the Virtual Local Area Network (VLAN) description will cause flush of Media Access Control (MAC) addresses learnt on the interfaces part of the VLAN and traffic impact
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1808956The syslog "LICENSE_EXPIRED" are not seen when license gets expired"
Product-Group=evo
Severity=Major
On Junos Evolved platforms, when license gets expired, LICENSE_EXPIRED syslog is supposed to get generated which is missing.
PR NumberSynopsisCategory: Port-based link layer security services and protocols that a
1757100Memory leak observed in AFTd-Trio daemon in PFE with IFL based MACSEC enabled on MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16
Product-Group=evo
Severity=Major
On all Junos MX platforms with MPC11/LC2301/LC9600 line cards and MX304-LMIC16, the statistics for MACSEC (MAC Security) are not displayed properly and lead to memory not getting freed. In a scaled environment of IFLs with MACSEC configured, eventually leads to AFTd-Trio daemon crash due to memory exhaustion.
PR NumberSynopsisCategory: For multicast snooping on MX
1710565In a scaled setup mcsnoopd is taking high CPU causing traffic drop
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.
PR NumberSynopsisCategory: QFX analyzer, sflow
1710919The sflow reports incorrect extended switch data and in some scenarios extended switch data is missing in all pakcets
Product-Group=evo
Severity=Major
Sflow reports incorrect extended switch data for different untagged/vlan-tagged and vlan-tagged/untagged ingress/egress interface combinations. In Ingress ECMP scenarios, where the egress IFL is tagged and ingress IFL is untagged, the extended switch data is missing in the sflow records.
PR NumberSynopsisCategory: show route table commands, tracing, and syslog facilities
1812009The rpd process crash is observed when there are catastrophic changes under the particular routing instance configuration
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when there is any catastrophic changes made in the configuration without deactivating a particular routing instance will lead to the rpd process crash.
PR NumberSynopsisCategory: Resource Reservation Protocol
1785214RSVP incorrectly determines the outgoing interface resulting in the rpd crash
Product-Group=evo
Severity=Major
On Junos platforms, the rpd (Routing Protocol Process Daemon) crash is observed when LSP (Label-Switched-Path) terminates on the incorrect outgoing interface. The issue happens because RSVP (Resource Reservation Protocol) incorrectly determines the outgoing interface that the ResvTear applies to.
PR NumberSynopsisCategory: PTX10K Line Card specific interface PRs
1776596Interface stay in link DOWN state when using third party optics
Product-Group=evo
Severity=Major
On Junos OS Evolved platforms and MX ULC based line cards, interfaces will stay DOWN when using third party vendor optics, due to an incorrect programming of EEPROM when plugged into the device.
1794352Channelized interface 4x10G remains DOWN with good signal levels
Product-Group=evo
Severity=Major
On Junos EVO a channelized interface can get stuck in DOWN state.
PR NumberSynopsisCategory: PTX10K specific platform PRs
1720259System calls for shutdown after RE switchover
Product-Group=evo
Severity=Major
When Routing Engine (RE) mastership switchover is performed, CoolingApp from the new backup Routing Engine might incorrectly interpret the temperature sensor reading and initiates a system shutdown request.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1772092Junos OS and Junos OS Evolved: MX Series with MPC10/MPC11/LC9600, MX304, EX9200, PTX Series: Receipt of malformed DHCP packets causes interfaces to stop processing packets (CVE-2024-39526)
Product-Group=evo
Severity=Major
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series with MPC10/MPC11/LC9600 line cards, EX9200 with EX9200-15C lines cards, MX304 devices, and Juniper Networks Junos OS Evolved on PTX Series, allows an attacker sending malformed DHCP packets to cause ingress packet processing to stop, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88103 [juniper.net] for more information.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberSynopsisCategory: VCCP related PRs for virtual-chassis in MX
1801522AE child links in back member is in detached state
Product-Group=evo
Severity=Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1822867After RE switchover the VRRP master and backup router will start functioning as master routers
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms configured with VRRP (Virtual Router Redundancy Protocol) and NSR (Non-Stop Routing), after RE switchover or GRES (Graceful Routing Engine Switchover) the master router would starts sending VRRP advertisements with a different priority value. As a result, both the master and backup VRRP routers will begin operating as the master which results in inconsistent traffic routing or packet loss as the system fails to establish a single master node.
PR NumberSynopsisCategory: ACX7000 hwd/chassisd software related issues.
1801225Junos OS Evolved ACX platforms is powered down randomly due to incorrect read of temperature sensor
Product-Group=evo
Severity=Major
On ACX platforms running Junos OS Evolved, the device gets powered down due to incorrect reading of a temperature sensor, impacting all the services running on the box.

 


 

22.2R3-S5-EVO - List of Known issues

PR NumberSynopsisCategory: ACX Interface and line card
1690655Port LED going unlit/off instead of amber/on when port is disabled
Product-Group=evo
On all EVO platforms, port LED goes unlit/off instead of amber/on when port is disabled

Resolved In: evo:22.4R1-EVO evo:23.1R1-EVO
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1713444The rpd process may crash when BMP socket write fails or blocks.
Product-Group=evo
On all Junos and Junos Evolved platforms, the rpd process may crash when BGP Monitoring Protocol (BMP) socket write fails or blocks. This is a special case in BMP operation but can be common for a large scale network. This may cause rpd to restart and affect routing protocols.

Resolved In: evo:21.4X1-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO junos:21.2R3-S6 junos:21.2R3-S9 junos:21.4R3-S4 junos:22.1R3-S3 junos:22.2R3-S2 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Express BT PFE L3 Features
1777759LAG interfaces will take longer than usual to come up in a scaled scenario with ALB
Product-Group=evo
On PTX10001, PTX10004, PTX10008 and PTX10016 platforms, if Adaptive load balancing (ALB) is configured on LAG interface, the LAG interfaces will take longer than usual to be up if they are all enabled in the same commit. LAG interfaces get stuck in 'attached' state. This issue happens in a scaled Link Aggregation Group (LAG) (~65 ae*) scenario.

Resolved In: evo:21.4X9-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D44-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
1790095The pfestatsd process may fail to restart when running out of file descriptors
Product-Group=evo
The pfestatsd process runs out of file descriptors when there are 16 FPCs in the system as the number of concurrent connections exceeded 1024 for Junos EVO Platforms seen on releases 23.2R2-S1-EVO, 23.4R1-S2-EVO, 21.4R3-S7-EVO, and 22.4R3-S2-EVO

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-S3-J3-EVO evo:22.4R3-S5-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: DNX Multicast
1691134Junos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenario (CVE-2024-39519)
Product-Group=evo
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA82983 [juniper.net] for more information.

Resolved In: evo:22.4R2-EVO evo:22.4R3-S2-EVO evo:23.1R1-EVO evo:23.2R2-S1-EVO evo:23.4R1-S1-EVO evo:24.1R1-EVO
PR NumberSynopsisCategory: EVO Netstack icmpd
1733616DNS resolution over a routing-instance fails
Product-Group=evo
Many issues were observed in EVO library regarding the DNS resolution & these were fixed in this PR

Resolved In: evo:21.4R3-S6-EVO evo:23.2R2-EVO evo:23.4R1-S1-EVO evo:23.4R2-EVO evo:24.1R1-EVO junos:23.4R2
PR NumberSynopsisCategory: Issues related to evo operations - libevo infra, typeinfo ..
1711265The rpd and rpd-agent crash are observed after the reboot of Master RE or Switchover
Product-Group=evo
On all Junos Evolved platforms with Dual Routing Engine(RE), if Master RE is rebooted or Switchover happens, the Multicast Composite Next Hop (MCNH) is deleted by the Routing Protocol daemon(rpd) of the new Master RE, which leads to a crash of rpd and rpd-agent and routing protocols are impacted, which could cause service impact.

Resolved In: evo:22.2R3-S2-J8-EVO evo:22.2R3-S3-J1-EVO evo:22.2R3-S4-J3-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.1R1-S1-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO evo:24.2R2-EVO junos:22.3R3 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: EVO MACSEC Platform Independent Implementation
1713163Junos OS Evolved: Specific low privileged CLI commands and SNMP GET requests can trigger a resource leak (CVE-2024-47505)
Product-Group=evo
An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88136 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S8-EVO evo:21.4R3-S7-EVO evo:22.1R3-S6-EVO evo:22.2R3-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:22.3R3 junos:22.4R2 junos:23.2R1
PR NumberSynopsisCategory: EVO RPD agent PRs
1802000The rpd process crashes when Routing Instance type is changed from L2 to L3 or vice versa
Product-Group=evo
On all Junos OS Evolved platforms, when a layer 2 RI (Routing Instance) is changed to layer 3 RI or vice versa without changing the name of the RI in a single commit, due to a rare timing issue, the rpd process can crash. During the rpd crash and restart, the routing protocols will be impacted and traffic disruption will be seen due to the loss of routing information.

Resolved In: evo:22.3X80-D43-EVO evo:22.3X80-D45-EVO evo:23.4R2-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:24.2R2
PR NumberSynopsisCategory: mgd, ddl, odl infra issues
1665008The system will ask for password while saving configuration files on single RE platforms
Product-Group=evo
The system may ask for your password when you are thing to save configuration file.

Resolved In: evo:22.2R3-S4-EVO evo:22.2X100-D20-EVO evo:22.2X100-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.1R1-EVO junos:23.1R1
PR NumberSynopsisCategory: SNMP, mib2d issues
1737682The snmpd crash is observed after FPC restart
Product-Group=evo
On all Junos Evolved platforms, snmpd crash can be seen when snmpd query is running and simultaneously FPCs are restarted or system rebooted. There is no traffic impact due to this issue.

Resolved In: evo:21.4R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.3X80-D36-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO evo:24.1R1-EVO evo:24.2R2-EVO
PR NumberSynopsisCategory: ACX7332 & ACX7348 HWD process
1819254Negative values are seen for jnxOperatingUpTime SNMP mib on Junos OS Evolved platforms after ~248 days uptime
Product-Group=evo
Negative values are observed for jnxOperatingUpTime while using this SNMP mib on Junos OS Evolved platforms after ~248 days uptime.

Resolved In: evo:23.2R2-S2-EVO evo:23.4R2-S1-EVO evo:24.2R1-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1751384License is missing on device on performing upgrade
Product-Group=evo
On all Junos Evolved platforms, under rare scenario, it is seen that license file gets removed on performing upgrade.

Resolved In: evo:21.4R3-S5-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1698889The rpd process will crash when rpd is restarted
Product-Group=evo
On all Junos and Junos OS Evolved platforms, when MPLS (Multiprotocol Label Switching) statistics is configured without LSP (Label-Switched Path) configuration, the rpd process will crash and impact the routing protocols. This leads to traffic disruption due to the loss of routing information.

Resolved In: evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.1R2-EVO evo:23.2R1-EVO junos:20.3X75-D43 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.2R3-S1 junos:22.3R3 junos:22.4R2-S2 junos:22.4R3 junos:23.1R1 junos:23.1R2 junos:23.2R1
PR NumberSynopsisCategory: OSPF routing protocol
1704521On all Junos and Junos OS Evolved platforms, the TI-LFA and Legacy LFA are mutually exclusive, and the commit check will fail and blocks LFA on one instance
Product-Group=evo
On all Junos and Junos OS Evolved platforms, if configuring LFA (Loop-Free Alternate)/RLFA (Remote LFA)/PPLFA (Per-prefix LFA) in the routing-instance and TI-LFA (topology independent LFA) in the master instance, along with Segment Routing and node-link-protection with post-convergence, the commit check fails and blocks LFA on one instance.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:21.4R2-S1-J4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3 junos:22.4R2-S2 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: PTX10K specific platform PRs
1701983The snmp mib walk jnxOperatingState on fan tray X returns running(2), although fan tray X speed is set to full-speed
Product-Group=evo
On all Junos Evolved platforms, snmp mib walk jnxOperatingState on Fan Tray X returns running(2), although fan tray X speed is set to full-speed. It is expected runningAtFullSpeed(5) when fan tray speed is set to full-speed.

Resolved In: evo:21.4R3-S3-EVO evo:22.3R3-EVO evo:22.3X50-EVO evo:22.3X80-D38-EVO evo:22.3X80-D39-EVO evo:22.4R2-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.3R1-EVO junos:22.3R3 junos:23.1R2 junos:23.2R1 junos:23.3R1
PR NumberSynopsisCategory: Trio LU and LUSS SW driver
1735490Junos OS: MX Series: Continuous subscriber logins will lead to a memory leak and eventually an FPC crash (CVE-2024-39539)
Product-Group=evo
A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). Please refer to the https://supportportal.juniper.net/JSA82999 [juniper.net] for more information.

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.4R1-EVO junos:19.1R3-S12 junos:19.2R3-S9 junos:19.3R3-S10 junos:19.4R3-S13 junos:20.2R3-S9 junos:20.3X75-D36 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S6 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1799215The commit fails error can be seen when configuration is modified after commit prepare
Product-Group=evo
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.

Resolved In: evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1825728The mgd process crashes while using an FQDN in conjunction with the ephemeral configuration database
Product-Group=evo
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.

Resolved In: evo:21.4X9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:22.4R3-S4-EVO evo:23.2R2-S2-EVO evo:23.4R2-S2-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.4R2-S2 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.3R2 junos:24.4R1
PR NumberSynopsisCategory: Issues related to NETCONF
1819656In all Junos and Junos OS Evolved platforms, with Multinode High Availability configured, node configuration on primary might differ from backup due to configuration synchronization failure at the time of commit
Product-Group=evo
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.

Resolved In: evo:21.4R3-S9-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.4R0-J0-EVO evo:23.2R2-S2-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S4 junos:22.4R3-S5 junos:23.4R2-S3 junos:24.2R1-S1 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: ACX724 timing issues
1833150Object anomalies seen post deactivate/delete of PTP configurations.
Product-Group=evo
Object anomalies seen post deactivate/delete of PTP configurations.

Resolved In: evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO
PR NumberSynopsisCategory: Express ZX PFE L3 Features
1732283Junos OS Evolved: PTX10003 Series: MAC address validation bypass vulnerability (CVE-2023-44189)
Product-Group=evo
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjacent LAN to be forwarded to the downstream network. Due to this issue, the router will start forwarding traffic if a valid route is present in forwarding-table, causing a loop and congestion in the downstream layer-2 domain connected to the device.Please refer to https://supportportal.juniper.net/JSA73153 [juniper.net] for more information.

Resolved In: evo:21.4R3-S4-EVO evo:21.4X1-EVO evo:22.1R3-S3-EVO evo:22.3R2-S2-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D35-EVO evo:22.4R2-S1-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-EVO evo:23.2R2-EVO evo:23.3R1-EVO junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S1 junos:22.4R3 junos:23.1R2 junos:23.2R1 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1

Modification History

First publication 2024-10-25