Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX PTX QFX platforms running Junos EVOLVED software

Alert Description

Junos Software Service Release version 21.4R3-S10-EVO is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Solution

Junos Software service Release version 21.4R3-S10-EVO is now available.

21.4R3-S10-EVO - List of Fixed issues

PR NumberSynopsisCategory: MPC10/11/LC9600 Chassis Category
1752654
Major
Voltage Threshold Crossed message observed on all Junos OS Evolved platforms
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms and device with MX10K-LC2301/ MX10K-LC9600, MX304, LC480, LC2101, LC1201 the voltage threshold cross is reported by MX20796 sensor.
PR NumberSynopsisCategory: EVO L3 routing for BCM XGS Platforms
1828017
Minor
The pfemand crash will be observed when "clear bgp neighbor all" command is executed
Product-Group=evo
Severity=Minor
On all Junos and Evolved platforms, in a scaled setup when the "clear bgp neighbor all" command is executed or "restart l2-learning immediately" is executed, the pfemand crash will be seen which leads to the restarting of the Flexible Packet Forwarding Card (FPC).
PR NumberSynopsisCategory: Express BT PFE L3 Features
1811245
Major
BGP session on PTX platforms may flap when inline BFD is configured with low BFD timer
Product-Group=evo
Severity=Major
On Junos OS Evolved PTX platform, the Border Gateway Protocol (BGP) session flap can be seen when inline Bidirectional Forwarding Detection (BFD) is configured under routing instance without loopback interface (lo0) leading to partial traffic drop. The issue is only seen when the interface is within the routing-instance.
1841145
Major
The evo-aftmand-bt/evo-aftmand-bx crash observed with SCU/DCU feature on IPv6 Prefixes
Product-Group=evo
Severity=Major
On Junos Evolved PTX10001-36MR, PTX10004, PTX10008, PTX10016, PTX10002-36QDD platforms, the evo-aftmand-bt/evo-aftmand-bx process may crash at high scale when source-class-usage (SCU) /destination-class-usage (DCU) features are configured on IPv6 prefixes (25 to 88 bits) due to hardware lookup entry updates from 20 to 40 bytes for additional action information.
PR NumberSynopsisCategory: EVO Netstack FIB Service Daemon
1612208
Major
Egress TCP RST may not have correctly populated DSCP field
Product-Group=evo
Severity=Major
Egress TCP RST may not have correctly populated DSCP field
1703955
Major
SYN-ACK and subsequent TCP session packets generated by RE will have incorrect DSCP value
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, TCP SYN-ACK packet generated by the Routing Engine(RE) in response to a TCP SYN and subsequent packets of the session will have an erroneous Differentiated Services code point (DSCP) value when "set class-of-service host-outbound-traffic dscp-code-point " is configured.
PR NumberSynopsisCategory: FIB telemetry, fibtd, libocaft repositories
1781544
Major
The fibtd process crash is seen on all Junos Evolved platforms
Product-Group=evo
Severity=Major
On all Junos Evolved platforms configured with fib-streaming, fibtd process crash can be seen due to interface flapping which caused traffic impact until the process self-recovers.
PR NumberSynopsisCategory: EVO L2 Control Plane PRs
1844623
Major
Stale MAC-IP entries are not cleared in an EVPN-VXLAN scenario when encapsulate-inner-vlan or decapsulate-accept-inner-vlan or both knobs are present
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, when decapsulate-accept-inner-vlan or encapsulate-inner-vlan or both knobs are configured for a VXLAN (Virtual Extensible Local Area Network) and when any action corresponding to MAC-IP entries cleanup takes place, the MAC-IP entries will not be cleaned up from kernel. This will result in anomalies in device and could also lead to a core crash.
PR NumberSynopsisCategory: EVO linux defects & enhancement requests
1607769
Major
Junos OS Evolved: Specific packets reaching the RE lead to a counter overflow and eventually a crash (CVE-2022-22195)
Product-Group=evo
Severity=Major
An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69508 [juniper.net] for more information.
1636063
Major
Junos OS Evolved: The kernel might restart in a BGP scenario where "bgp auto-discovery" is enabled and such a neighbor flaps (CVE-2023-22402)
Product-Group=evo
Severity=Major
A Use After Free vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Refer to https://kb.juniper.net/JSA70198 [juniper.net] for more information.
PR NumberSynopsisCategory: Junos Evolved socket replication
1627625
Major
Transient JSR replication errors 113 / 115 seen on disable/enable OSPF
Product-Group=evo
Severity=Major
No functionality impact as NSR gets enabled again quickly on all protocols after the error messages. Also errors are mostly seen when rpd-agent crashes
1643328
Minor
Junos OS Evolved: Kernel processing of unvalidated TCP segments could lead to a Denial of Service (DoS) (CVE-2022-22247)
Product-Group=evo
Severity=Minor
An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker to send a crafted TCP segment to the device, triggering a kernel panic, leading to a Denial of Service (DoS) condition. Please refer to https://kb.juniper.net/JSA69904 [juniper.net] for more information.
1660685
Major
An error log from rpd/kernel might be seen on EVO platforms
Product-Group=evo
Severity=Major
On all Junos OS Evolved platforms, an error log from rpd/kernel corresponding to "JSR backup registration failed" might be observed during extreme scenarios of rpd restart. There is no service impact due to this benign issue.
PR NumberSynopsisCategory: EVO Socket replication
1594082
Major
[PTX EVO] The IPv4/IPv6 BGP session convergence slow when Non Stop Routing (NSR) is enabled
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, the BGP session convergence will be slow however there is not any traffic impact due to this issue. As the convergence is significantly slower when NSR enabled, the FIB programing rate is taking longer than expected time to finish
1626040
Major
The master kernel may get crash if NSR is enabled
Product-Group=evo
Severity=Major
When Nonstop active routing (NSR) is enabled and if replication on a socket gets enabled and disabled continuously (for reasons like a configuration change, unable to replicate connection to backup) then kernel on the master may crash.
1663201
Major
Junos OS Evolved: PTX Series: An attacker can cause a kernel panic by sending a malformed TCP packet to the device (CVE-2022-22192)
Product-Group=evo
Severity=Major
An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69915 [juniper.net] for more information.
1671458
Major
The unreplicated message might not be sent from the master to back if there is an rpd restart
Product-Group=evo
Severity=Major
On all Junos Evolved platforms, during switchover, if an unreplicate message reaches backup before backup recovery is completed, it can lead to leaking of the connection on the backup also recovery might not happen on it.
1723268
Critical
Junos OS Evolved: Receipt of a specific TCP packet may result in a system crash (vmcore) on dual RE systems with NSR enabled (CVE-2024-39559)
Product-Group=evo
Severity=Critical
An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to crash the device (vmcore) by sending a specific TCP packet over an established TCP session with MD5 authentication enabled, destined to an accessible port on the device, resulting in a Denial of Service (DoS). The receipt of this packet must occur within a specific timing window outside the attacker's control (i.e., race condition). Please refer to https://supportportal.juniper.net/JSA83019 [juniper.net] for more information.
1736428
Major
BGP session flaps due to hold time expiration
Product-Group=evo
Severity=Major
On all Junos Evolved platforms which supports dual RE (Routing Engine), BGP (Border Gateway Protocol) session flaps due to hold time expiration when BGP and NSR (Nonstop Active Routing) are enabled and the peers exchange routes at same time.
PR NumberSynopsisCategory: EVPN control plane issues
1839959
Critical
The MAC+IP table and mac-table are not in sync in the EVPN-MPLS active-active multihomed scenario leading to traffic loss
Product-Group=evo
Severity=Critical
On all Junos and Junos OS Evolved platforms that supports ESI lag interface and in an EVPN-MPLS (Ethernet Virtual Private Network - Multi Protocol Label Switching) active-active multihomed scenario, when the multihomed access interfaces are flapped in quick succession, it results in an unresolved destination route for the specific IP host. This is occurred due to race condition within l2ald (Layer 2 Address learning daemon) followed by an interface flap which causes the locally learned MAC to go missing from the mac-table on the other PE router.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1715343
Major
Ping overlay vxlan replies Overlay-segment present even the bridge-domain has been deactivated
Product-Group=evo
Severity=Major
The vxlan ping overlay request is recevied for a certain VNI on MX and the bridge-domain associcated with the VNI has been deactivated. However the MX still responses with "Overlay-segment present" sub-code in the reply message.
PR NumberSynopsisCategory: MX Inline Jflow
1813925
Major
FPC reboots after sensor configuration is removed and readded over a long period on MX and EX9200-15C platforms
Product-Group=evo
Severity=Major
On all MX platforms with MPC10/MPC11/LC9600, MX304 and EX9200-15C platforms, when any sensor configuration on protocols, for example, MPLS LSP, is configured and removed over a long period, the aftd-trio process starts a memory leak and eventually causes FPC to reboot.
PR NumberSynopsisCategory: ISIS routing protocol
1841108
Major
Traffic drop is seen after GRES on ISIS peer
Product-Group=evo
Severity=Major
On all Junos and Junos OS Evolved platforms, in an ISIS(Intermediate System-Intermediate System) graceful restart scenario, helper node sends and programs its locally configured hold-time (180 secs) instead of the "Restart-duration" received as hold-time from DUT (210 secs), due to this incorrect update, the hold timer expires at the helper node before the GR (Graceful Restart) is complete on DUT and it causes a flap of ISIS adjacency on peer/helper Node.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1820882
Major
Traffic drop is seen in an EVPN multihoming scenario when mac-pinning is enabled
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms, in Ethernet VPN (EVPN) multihoming scenario with mac-pinning enabled, traffic drop will be seen when the Designated Forwarder role (DF) is changed.
PR NumberSynopsisCategory: Label Distribution Protocol
1817712
Major
MPLS LDP sessions are not established when container-lsp is configured with an already existing lsp-template
Product-Group=evo
Severity=Major
On all Junos and Junos Evolved platforms Label Distribution Protocol (LDP) sessions are not formed due to the configuration of "container-lsp" with an already existing configured lsp-template which has "ldp-tunneling" knob enabled.
PR NumberSynopsisCategory: TCP/UDP transport layer
1663550
Major
Junos OS Evolved: Specific TCP packets will bypass a control plane firewall filter (CVE-2023-44202)
Product-Group=evo
Severity=Major
An Incorrect Authorization vulnerability in TCP packet processing of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass intended access restrictions. Please refer to https://supportportal.juniper.net/JSA73168 [juniper.net] for more information.
PR NumberSynopsisCategory: Routing Information Protocol
1726028
Major
Neighbor state is down while checking RIPng neighbor information
Product-Group=evo
Severity=Major
When a virtual IP is configured over an IRB interface, IFA having the virtual IP is considered by RIPng and hence an IFA having a non-virtual ip is discarded with the error (errno : Address already in use), which is causing RIPng neighbor state to be down.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1801382
Minor
Memory Leak in the rpd Process During Protocol Deactivation/Activation
Product-Group=evo
Severity=Minor
On all Junos and Junos Evolved platforms, A memory leak occurs during protocol, routing instance, or interface deactivation/activation, linked to improper IPv6 Interface Address (IFA) reference handling in the " ifx_dist_msg " process. This can lead to rpd crashes and service disruptions.
1817807
Major
Routes for secure tunnel interface interface not installed on forwarding-table on SRX platforms
Product-Group=evo
Severity=Major
On all SRX platforms, after the In-Band Cluster (ICU) upgrade if the system has routes pointing to the secure tunnel interface (st0) interface, or on clearing security IPsec sa on peer router a few routes might have trouble getting installed in forwarding, impacting traffic on the routes that are not installed after the upgrade.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1802329
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=evo
Severity=Major
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

 


 

21.4R3-S10-EVO - List of Known issues

PR NumberSynopsisCategory: Border Gateway Protocol
1755287
Major
Junos OS and Junos OS Evolved: Malformed BGP UPDATE causes rpd crash (CVE-2024-39552)
Product-Group=evo
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the rpd process to crash leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75726 [juniper.net] for more information.

Resolved In: evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X80-D47-EVO evo:22.4R2-S1-J10-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:18.4R3-S5-J11 junos:19.1R3-S12 junos:19.2R3-S8 junos:19.3R3-S9 junos:19.4R3-S13 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S3-J32 junos:21.2R3-S4-J27 junos:21.2R3-S4-J30 junos:21.2R3-S4-J37 junos:21.2R3-S6-J15 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:21.4R3-S6 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
1817834
Major
The rpd crashes when stale label entry keeps increasing when knob stale-labels-holddown-period is configured
Product-Group=evo
On all Junos and Junos Evolved platforms configured with the "stale-labels-holddown-period" setting and extensive label configurations (such as Multiprotocol Label Switching labels), the Routing Protocol Daemon (RPD) may crash if stale labels are not cleared periodically and keep accumulating. Due this, temporary traffic impact will be seen until the rpd process restarts.

Resolved In: evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
1826686
Major
Traffic impact due to BGP route stuck in hidden state
Product-Group=evo
On all Junos and Junos Evolved platforms, with BMP (BGP Monitoring Protocol) configured, the BGP route gets stuck in a hidden state with the next hop state as 'Next hop type unusable' leading to traffic drop.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Bowmore specific platform defects tracking
1782498
Major
[Junos OS Evolved] PTX10004/8/16 - !Minor alarm LED on FPM(Front Panel Module) is glowing Yellow, although there is no active alarms/errors on the system
Product-Group=evo
On PTX10004/8/16 EVO platforms, !Minor alarm LED on FPM(Front Panel Module) is glowing Yellow, although there is no active alarms/errors shown by "show system alarms" CLI.

Resolved In: evo:22.4R3-S2-J1-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Distributor related issues
1836997
Major
The rpdagent process is getting restarted after switchover
Product-Group=evo
On Junos OS Evolved platforms, a rare race condition can cause a previously added state on master before switchover to arrive late on the new master and after switchover rpdagent restarts which results into traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: SNMP, mib2d issues
1814315
Major
There is no option for inband management through SNMPv3 on an interface configured with non-default routing instance
Product-Group=evo
On all Junos Evolved platforms, the routing instance needs to be specified in the snmpv3 query with -n option for the query to be successfully served.

Resolved In: evo:23.2R2-S2-EVO evo:23.2R2-S3-EVO evo:23.4R2-S1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: EVPN control plane issues
1796532
Major
EVPN mac-ip entry flag "Duplicate-Not-Best" not updated after deleting duplicated IRB IP in EVPN_VXLAN MAC-VRF
Product-Group=evo
On all Junos and Junos Evolved platforms, duplicate mac-ip detection for IRB IP is not working since the IP move is not triggered after adding an IP address to the IRB interface.

Resolved In: evo:23.4R2-S4-EVO evo:23.4X100-D30-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.4R2-S4 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1826194
Major
The rpd crash is observed during upgrade or restart
Product-Group=evo
On all Junos and Junos Evolved platforms, rpd crash is observed during upgrade or restart since kernel takes more time to update ifstate information.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: MPC11 ULC fabric software related issues.
1827058
Major
The PFE gets disabled due to large number of fabric self ping errors
Product-Group=evo
On MX platforms with MPC11E and LC9600 and MX304, when multiple fabric self ping errors and timeouts are seen, device attempts to recover by performing port bounces at fabric end. But when there are large number of self ping errors and timeouts are seen which require more than 256 port bounces, the affected PFE(Packet Forwarding Engine) will get disabled resulting in traffic loss.

Resolved In: evo:24.2R2-EVO evo:24.4R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: PTX10K Routing Engine
1770585
Major
Junos vmhost upgrade will continue to reboot the box even if the upgrade has failed due to tar errors when the reboot option is used
Product-Group=evo
Issue identified when upgrading vmhost, but applies to all Junos platforms that support vmhost. When there are tar errors during the upgrade, and the reboot option is used in the upgrade command, the machine will still reboot the RE despite that the upgrade was not completed correctly. This will break the routing engine. It is necessary to stop the reboot, if error or tar problems occurred during the upgrade.

Resolved In: junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1805427
Minor
The rpd process crashes during rpd restart on Junos and Junos Evolved platforms
Product-Group=evo
On all Junos platforms, due to timing issue during the restart of the rpd process may cause it to crash. This can temporarily impacts traffic until the process recovers.

Resolved In: evo:22.4R3-S5-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S9 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1771344
Major
Leaked routes via BGP rib-group remains in hidden state even though "loops" is configured with any value greater than one
Product-Group=evo
On all Junos and Junos Evolved platforms having BGP (Border Gateway protocol) configured, when route is leaked via rib-group from one routing instance to another having the same AS (Autonomous System) number and one of the routing-instances has BGP configured with local-as, it is observed that even after configuring "loops" with any value greater than one as the number of loops option, the route still remains hidden instead of being active which results in traffic drop.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1819948
Major
LSP re-optimization issue has been observed
Product-Group=evo
On all Junos and Junos Evolved platforms, the LSP (Label Switched Path) re-optimization issue has been observed. LSP bandwidth change is unsuccessful due to bandwidth unavailable RSVP (Resource Reservation Protocol) PathErr.

Resolved In: evo:22.4R3-S5-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D441 junos:20.3X75-D46 junos:21.4R3-S10 junos:22.4R3-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: PTX10K specific platform PRs
1780256
Minor
PSM removed and displayed incorrectly on "show chassis craft-interface" O/P
Product-Group=evo
on PTX10K EVO platforms, we might see on the O/P of the "show chassis craft-interface" command the PSM LED status as RED, while it should be displayed as (.) not (*). Only in case of HW failure, it should be displayed as RED/(*). In case the PSM is turned off or the feeds are disconnected for a healthy PSM, its status should be displayed as (.)

Resolved In: evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO
PR NumberSynopsisCategory: ZT/YT LUSS SW driver
1765394
Major
Fatal(MQSS and XQSS errors) error on FPC leads to PIC card offline and traffic impact
Product-Group=evo
On Junos MX304 and MX platforms with LC9600 linecards, With the current error handling mechanism upon receiving fatal error on Flexible pic concentrators(FPC), leads to disable both the Packet Forwarding Engine(PFE) on a Physical Interface Cards(PIC) card and seen traffic impact.

Resolved In: evo:24.1R1-EVO junos:23.4R2-S4 junos:24.1R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1816378
Major
XQSS_CMERROR errors will be seen which might disable PFE
Product-Group=evo
On MX204, MX10003 and MX platforms with MPC7, MPC8, MPC9, LC480, LC2101, LC2103, MPC10 and MPC11 line cards or EX92xx platforms with EX9200-40XS, EX9200-12QS, EX9253-6Q12C, EX9253-6Q12C-M line cards, SRX5400, SRX5600, SRX5800 platforms with SRX5K-IOC4-10G, SRX5K-IOC4-MRAT line cards, in a scenario where there could be fabric drops because of over-subscription or CRC errors, there could be case when the same tail entry get re-used across packets leading to packet corruption and CM error. This is a corner case and might lead to PFE(Packet Forwarding Engine) disable resulting in traffic loss.

Resolved In: evo:24.3R1-EVO junos:21.4R3-S10 junos:22.4R2-S1-J8 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1-S1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1636085
Major
MTU configuration on an interface is not set as expected
Product-Group=evo
On all Junos with persist-groups disabled ( on Junos persist-groups feature is enabled by default 19.4 onwards) and on EVO platforms where persist groups can be disabled (21.4R1 onwards persist-groups cannot be disabled on EVO) this issue can be seen. This issue occurs when grafting happens during configuration expansion (when persist-groups is disabled) and a configuration such as a customer configuration is applied( for example, a configuration in which MTU is inherited from a groups configuration).

Resolved In: evo:22.2R1-EVO evo:22.3R1-EVO junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S10 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: Issues related to NETCONF
1585855
Critical
< ok/> response is getting generated along with < rpc-error>
Product-Group=evo
When maximum-password-length is configured and the user tries to configure password whose length exceeds configured maximum-password-length, there is an error and the '' tag is emitted. (Ideally '' tag should not be emitted in an error scenario.) The configuration does not get committed.

Resolved In: evo:22.2R3-S1-EVO evo:22.3R2-S2-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.3X75-D36 junos:22.1R3-S6 junos:22.2R3-S1 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R2-S2 junos:22.4R3 junos:23.1R1 junos:23.2R1 junos:23.4R2
1796297
Major
Error message not prompted on commit confirmed RPC sent in private mode on all Junos and Junos Evolved platforms
Product-Group=evo
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.

Resolved In: evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S3-EVO evo:23.4X100-D30-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:25.1R1
PR NumberSynopsisCategory: MX10K linecard
1809511
Major
Ethernet interfaces configured with loopback option remains down after multiple iteration of line card boot is performed
Product-Group=evo
On MX platforms with LC2101 line cards and 10-gigabit ethernet interfaces configured in loopback mode, when Line card is booted multiple times, the ethernet interfaces on line card remains down and traffic on those interfaces will be impacted.

Resolved In: evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:21.4R3-S10 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1

Modification History

First publication 2025-01-30