Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX EX MX PTX QFX SRX vSRX

Alert Description

Junos Software Service Release version 22.3R3-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as needed and follow the prompts

NOTE: Starting August 30th, 2024, we include PR severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 22.3R3-S4 is now available.

22.3R3-S4 - List of Fixed issues

PR NumberCategory: "agentd" software daemon
1808259
Major
On all Junos Evolved platforms configured with Openconfig telemetry, when streaming the GNMI leaves updates for data type value "ieeefloat32"will be seen streaming as type "float_val" instead of "bytes_val". There is no traffic impact due to this, and just a display issue.
1817267
Major
GNMI telemetry streaming of Decimal64 data types should stream double_val types instead of float_val types. GNMI has decremented the use of float_val and Decimal64 types in favor of double_val types for floating point data.
PR NumberCategory: MPC Fusion SW
1796770
Major
On Junos MX platforms traffic loss can be seen across FPC (Flexible PIC Concentrator) during ISSU if an FPC fails and recovers during iSSU (In-Service Software Upgrade). This issue is seen when ISSU is done from a release older than Junos 21.2 to release 21.2 or higher. The issue is due to number of Max PFE (Packet Forwarding Engine) mismatch between releases earlier than Junos 21.2 and releases 21.2 or higher.
PR NumberCategory: Interface related area
1809220
Major
On Junos SRX5400/5600/5800 platforms in cluster, with 40G interface in layer 2 (L2) transparent mode, when the chassis failovers, the interfaces on node0 will remain in a down state and will not come up. The same issue can also occur when node1 failovers to node0.
PR NumberCategory: BBE state synchronization issues
1811787
Critical
On all Junos and Junos OS Evolved platforms, in a scaled stack-based Subscriber Management scenario (e.g PPPOE, DHCP, PS over LT interface, etc.), the bbe-smgd process crash will be observed with continuous login/logout of a large number of subscribers over a period.
PR NumberCategory: Border Gateway Protocol
1708088
Major
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices. Please refer to https://supportportal.juniper.net/JSA88138 [juniper.net] for more information.
1778879
Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This memory is not properly freed in all circumstances, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83011 [juniper.net] for more information.
1807533
Critical
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88102 [juniper.net] for more information.
1814083
Critical
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.
1815222
Critical
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled. Please refer to https://supportportal.juniper.net/JSA88100 [juniper.net] for more information.
PR NumberCategory: OpenSSL and related subsystems
1815253
Major
The OpenSSL project has published security advisories for multiple vulnerabilities. Please refer to https://supportportal.juniper.net/JSA88107 [juniper.net] for more information.
PR NumberCategory: ACX platform interface issues
1775279
Major
On Junos based ACX5448 platforms with tri-rate SFP-T, when Junos upgrade is performed or interface speed is changed, interface speed sometimes becomes 'unspecified' and connected interface link will go down causing service impact.
PR NumberCategory: Ethernet OAM (LFM)
1811734
Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberCategory: EVO MACSEC Platform Independent Implementation
1811300
Major
On Junos MX2010/MX2020 platforms with MX2K-MPC11E line cards, and MACSec (IEEE 802.1AE standard) configured on line card ports. When the line card comes online for the first time, it is seen that ports are not being mapped correctly (port group value mismatch between picd and security) resulting in MACSec not working on some ports.
PR NumberCategory: Configd, ffp issues
1802837
Major
On all Junos OS Evolved platforms the DHCP (Dynamic Host Configuration Protocol) relay will not work as expected when two consecutive wildcards are used in prefix-list apply-path in the loopback filter and "set policy-options prefix-list pf-dhcp-servers apply-path "forwarding-options dhcp-relay server-group <*> <*>" is configured.
PR NumberCategory: mgd, ddl, odl infra issues
1749525
Major
Non-descriptive error messages are seen while committing config through gNMI
PR NumberCategory: Express PFE including evpn, vxlan
1808040
Major
On QFX10k platforms having Seamless EVPN-VXLAN (Ethernet VPN-Virtual Extensible LAN) DCI (Data Center Interconnect) Stitching configured with L2 (Layer 2) Bridged Overlay design, VRRP (Virtual Router Redundancy Protocol) multicast traffic may be flooded to all RNVEs (Regular Network Virtualization Equipment) and Wan-VTEPs (Wide Area Network - Virtual Tunnel Endpoints), irrespective of DF (Designated Forwarder)/NDF (Non-Designated Forwarder) role. This may result in duplicates of VRRP multicast packets.
PR NumberCategory: Express PFE L2 fwding Features
1798887
Major
On Junos QFX10002-36Q/QFX10002-72Q/QFX10002-60C and PTX10002-60C platforms, the decapsulate of the VXLAN (Virtual eXtensible Local-Area Network) packet will fail and result in traffic drops due to the tunnel termination table not being programmed in PFE (Packet Forwarding Engine).
PR NumberCategory: SRX1500 platform software
1813536
Major
Reachability issue observed when trying to ping oversize packet via IRB
PR NumberCategory: idp flow creation, deletion, notification, session mgr intfce
1826377
Critical
On SRX platforms with IDP (Intrusion Detection and Prevention) enabled, while processing IDP traffic a memory leak can occur which would lead to regular flow processing being affected as memory depletes eventually. This issue affects the following Junos releases: 21.2R3-S8, 21.4R3-S7/8, 22.2R3-S3/4, 22.3R3-S3, 22.4R3-S2/3, 23.2R2, 23.2R2-S1 and 24.2R1. All other releases are not affected by this issue.
PR NumberCategory: jdhcpd daemon
1818919
Major
DHCP ALQ (Active Leasequery) Sessions go down due to core dumps in jdhcpd (Juniper DHCP Daemon). These jdhcpd core dumps may be seen on ALQ setups when subscriber synchronization happens after the TCP (Transmission Control Protocol) connection comes up.
PR NumberCategory: Flow Module
1820291
Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88133 [juniper.net] for more information.
PR NumberCategory: High Availability/NSRP/VRRP
1821452
Critical
An Improper Validation of Specific Type of Input vulnerability in the packet forwarding engine (PFE) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, network based attacker to cause a Denial of Service (Dos). Please refer to https://supportportal.juniper.net/JSA88134 [juniper.net] for more information.
PR NumberCategory: IPSEC/IKE VPN
1794895
Major
On Junos SRX platforms with a cluster, when a high volume of traffic is observed, high CPU (Central Processing Unit) usage might be seen from the SPUs (Security Processing Units). The FPC (Flexible PIC Concentrator) may reboot, and the IKE SAs (Internet Key Exchange Security Associations) may be cleared and timed out, preventing the VPNs (Virtual Private Networks) from failing over and causing a traffic impact.
PR NumberCategory: Platform infra to support jvision
1769294
Critical
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during telemetry polling, to move the AgentD process into a state where AgentD attempts to reap an already destroyed sensor. This reaping attempt then leads to memory corruption causing the FPC to crash which is a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88121 [juniper.net] for more information.
PR NumberCategory: MPC11 ULC fabric software related issues.
1802259
Critical
On MX2020/MX2010 platforms having SFB3, traffic drops will be observed due to multiple PFEs (Packet Forwarding Engine) getting disabled or blackholing traffic. This issue happens when an SFB3 comes up online after an ungraceful offline followed by a master SPMB reboot leading to fabric Link errors.
PR NumberCategory: For multicast snooping on MX
1710565
Major
On all Junos and Junos Evolved platforms, whenever a commit is done, that involves mcsnoopd daemon config parsing such as (VLAN creation/deletion, interface add/delete to VLAN, interface enable/disable, IGMP (Internet Group Management Protocol) snooping/MLD (Multicast Listener Discovery) snooping related config commands) mcsnoopd will consume CPU. In less scaled setup (few IGMP snooping enabled VLANs and few hundred IGMP snooping memberships), the CPU time taken is less. In a more scaled setup (many IGMP snooping-enabled VLANs and a few thousand IGMP snooping memberships), the CPU may reach >90%. Since mcsnoopd is taking high CPU, it may affect other daemons like rpd. It may affect all the protocols if the CPU is not available to the protocols/daemons. This can impact route entries expiring and cause traffic drop.
PR NumberCategory: QFX L2 PFE
1811701
Major
On QFX5110-48S platforms in VC (Virtual Chassis), when 100G port is used as VC interconnect, multiple protocols and services do not work on the backup member when the VC port related configurations are deleted and added back on the backup member. The issue is also seen when the PFE process on the backup member is restarted. LACP (Link Aggregation Control Protocol) interfaces from backup switch goes into detached/defaulted mode which causes major connectivity and traffic disruptions.
PR NumberCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1808463
Major
On all Junos and Junos OS Evolved platforms in a corner case, the Routing Protocol Daemon (rpd) CPU utilization will be seen high in scenarios where recursive route resolution is involved. The rpd process will be continuously spinning in the re-resolution job which could impact scheduling of other jobs and re-resolution of other routes impacting traffic.
PR NumberCategory: Scuba fabric software
1807812
Critical
During ungraceful Peer-SFB/Peer-FPC offline or due to a bad fabric link XM ASIC based FPCs can hit CPQ Underrun Major error on an unused queue resulting in PFE Disable action. This PR fixes the underlying reason for the CPQ Underrun error and prevents PFE from being disabled.
PR NumberCategory: SRX Argon module
1815751
Critical
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of protected files on the file system. Please refer to https://supportportal.juniper.net/JSA88104 [juniper.net] for more information.
PR NumberCategory: Track usability related J-Web PR, like UI layout, workflow
1823264
Major
On all SRX series platforms enabled with J-Web, NAT (Network Address Translation) policies cannot be edited/added using J-Web if the destination address name contains '.' dot or '/' slash.
PR NumberCategory: SRX branch platforms
1819054
Major
On Branch SRX platforms the contents of ~root/.ssh directory is deleted on every reboot. This can cause issues with SSH issues as locally stored public and private keys are deleted (stored on ~root/.ssh by default)
PR NumberCategory: SSL Proxy functionality on JUNOS
1753540
Major
On Junos based SRX platforms in a low memory condition, the flowd process will crash because of memory corruption and crash files will be observed. Traffic flow will be impacted till the time flowd restarts.
PR NumberCategory: Stout card (MPC7) fabric issues
1812276
Critical
On MX2010/MX2020 platforms with non-native LCs installed with an ADC, if a non-native LC PFE erroneously starts sending the traffic to a remote PFE using some fabric plane with link error towards that remote PFE, then this traffic will build up at the sending LC ADC, which cause the traffic blackholing to the remote PFE over all fabric planes.
PR NumberCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1722945
Major
On all MX platforms with line cards before MPC10, when Broadband Network Gateway (BNG) switchover occurs, the new master does not send PPPoE Active Discovery Termination (PADT) packet for an unknown session if the incoming packet is PPPoE/PPP data packet and thus the existing subscribers does not come up on this router.
1788669
Major
On Junos MX platforms, when subscriber management is enabled and mac-validate is configured on interfaces, traffic drop is seen while attempting to add a new link to an existing AE (Aggregate Ethernet) bundle from a different FPC.
PR NumberCategory: Trio pfe l3 forwarding issues
1784593
Major
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA88123 [juniper.net] for more information.
PR NumberCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.
PR NumberCategory: Configuration mgmt, ffp, load-action, commit processing
1818692
Major
Core dumps in mustd seen commiting a change to a large prefix-list used by BGP
PR NumberCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1784818
Major
On all Junos and Junos Evolved platforms, when logged in as a non-root user and trying to copy a file from a remote location, it shows as cannot become non-root username although logged in as a non-root user and an error message is thrown.
1794536
Minor
The device is went into config locked state due to stale mgd. For netconf sessions with , if ungraceful exit happens, the lock is not released. There is auto cleanup supported for such cases, But it is not triggered under problem conditions as faced in this PR. This leads to device remain in locked state due to stale entry. "request system logout pid " can be used for cleanup and to recover from this state.
1825728
Critical
On all Junos and Junos Evolved platforms, the mgd process crashes when device has an ephemeral configuration database instance and an FQDN (Fully Qualified Domain Name) is used for NTP (Network Time Protocol), radius-server, tacplus-server, etc. in either the main static configuration or the ephemeral configuration database.
PR NumberCategory: Issues related to NETCONF
1792362
Major
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
1819656
Major
In all Junos and Junos OS Evolved platforms with MNHA (Multinode High Availability) supported and "set system commit peers-synchronize" is configured in a local primary node of the HA, when the "commit" command is issued, a synchronization warning message is displayed informing that session to peer (backup) has failed and configuration is committed only in the local primary device. Under the same configuration, if the command "commit peers-synchronize" is used instead of "commit", then the synchronization error will cause the configuration to not be committed on any of the high availability nodes. This issue does not affect network services. The synchronization error is caused by a TACACS authentication failure when primary node attempts to access the secondary backup node.
PR NumberCategory: Issues related to XML, JSON handling
1736286
Major
When OpenConfig data is queried using using gnmi GetRequest in json format, appropriate module prefixes will get displayed for the first container object from the respective module.
PR NumberCategory: web filterig issues
1806786
Major
On SRX platforms, Unified Threat Management (UTM) web filtering does not work for Hypertext transfer protocol secure (HTTPS) traffic sent from Google Chrome browser or MS Edge v124.
PR NumberCategory: VCCP related PRs for virtual-chassis in MX
1801522
Major
On Junos MX platforms with MPC10E-10C card platforms, the issue is observed during a VC(Virtual Chassis) sequential upgrade , where AE child links in backup member is in detached state after auto reboot. Hence redundancy is lost
PR NumberCategory: usf flow and datapath issue on SPC3
1799512
Major
On Junos MX platforms equipped with SPC3 (Services Processing Card 3), when running on Talus 0x215 version and each SPC3-PIC (Physical Interface Card) handling significantly high throughput along with bursty traffic, will lead to tx_NoDp_drop' to be hit leading to packet drop.

 


Modification History

First publication 2024-11-25