Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

EX4300 EX4600 SRX5400 SRX5600 SRX5800

Alert Description

Junos Software Service Release version 21.4R3-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Software Release Notification

Solution

Junos Software service Release version 21.4R3-S11 is now available.

21.4R3-S11 - List of Fixed issues 

PR NumberSynopsisCategory: EX4300 PFE
1848179
Minor
Counter for ipv6 egress filter does not work properly for EX4300
Product-Group=junos
Severity=Minor
On the EX4300, the egress Router Access Control List (eRACL) configured on the Layer 3 IPv6 interface with action count is not working.
1859134
Minor
PFE core-dumps can be seen on the EX4300 platform when Virtual Chassis is present
Product-Group=junos
Severity=Minor
On all EX4300 series platforms using the Virtual Chassis feature, PFE core-dumps can be seen randomly then hence traffic via all the ports on this FPC could be impacted.
PR NumberSynopsisCategory: EX2300/3400 PFE
1856201
Major
Error logs : "PFE_BRCM_COS_HALP_ERR: BRCM_COS_HALP" are observed and CoS not working on EX2300 switches
Product-Group=junos
Severity=Major
On Junos EX2300 platforms, WRED (Weighted Random Early Detection) will not work as expected with CoS (Class of Service) scheduler and drop-profile configuration and tail drop will happen as the queue is full.
PR NumberSynopsisCategory: N/A:jsr-nsd
1857379
Critical
The nsd process crashes on SRX platforms during cluster reboot, failover, or policy addition causes traffic outage
Product-Group=junos
Severity=Critical
On all Junos OS SRX series platforms configured with the logical systems (LSYS), the network security daemon (nsd) process crashes due to cluster failover or reboot of node in a standalone firewall setup or while adding security policies. This crash generates a core dump and prevents the system from configuring security policies. As a result, all policy configurations are removed, leading to a traffic outage.
PR NumberSynopsisCategory: PFE issue for flowd on australia SPU
1726888
Major
SNMP MIB walk for ipSystemStatsTable takes a long time to dump the output
Product-Group=junos
Severity=Major
When polling ip SystemStatsTable, the responses have noticable delay
PR NumberSynopsisCategory: QFX Control Plane VXLAN
1820712
Minor
Traffic loss is observed after configuration addition or baseline configuration override with static VXLAN or EVPN-VXLAN configuration
Product-Group=junos
Severity=Minor
On all QFX/EX/PTX /ACX platforms, when the configuration addition or baseline configuration override happens with static VXLAN (Virtual Extensible Local Area Network) or EVPN-VXLAN (Ethernet Virtual Private Network - Virtual Extensible LAN) configuration, forwarding traffic is impacted as the next-hop is not resolved in correct order of configuration events.
PR NumberSynopsisCategory: EX interfaces issues
1831409
Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created
Product-Group=junos
Severity=Major
On an EX4400 device with 4x25G Uplink module configured in 1GE or 25G speed, peer side of an interface with 10GBASE-T transceiver may remain up even when the IFD(xe-x/2/y) is not created. For this to happen, a speed mismatched configuration is needed, where a 1G speed or a 25G speed is configured on the PIC 2.
PR NumberSynopsisCategory: EX4400 PFE software
1854253
Major
Devices fail to obtain an IP address when DHCP Security Option 82 is enabled
Product-Group=junos
Severity=Major
On Junos EX and QFX platforms when DHCP (Dynamic Host Configuration Protocol) option 82 settings are enabled under dhcp-security, hosts fail to get an IP address from the DHCP server.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1834204
Major
SRX becomes unresponsive when SNMP requests for VPN are received via the fxp0 interface immediately after a reboot
Product-Group=junos
Severity=Major
On Junos SRX platforms (except SRX1600, SRX2300, SRX4700 and SRX5000 series with SPC3 card) using the IPsec-key-management service (kmd) for VPNs (Virtual private networks), the SRX becomes unresponsive when SNMP (Simple Network Management Protocol) requests for VPN information are received via the fxp0 interface immediately after a reboot, before the IPC (Inter-Process Communication) connection to the PFE is fully established. This results in exhaustion of file descriptors (IO handlers) by kmd, preventing IPC connections from being established and impacting VPN operations and device manageability via SNMP.
PR NumberSynopsisCategory: Layer 2 Control Module
1763053
Minor
LLDP neighborship will not be formed on all Junos devices
Product-Group=junos
Severity=Minor
On Junos and Junos OS Evolved platforms, LLDP (Link Layer Discovery protocol) neighborship will not come up on local device if the local device is using Junos version lower than 22.3 and remote device is using Junos version 21.4R3-S2 and its subsequent service releases or version higher than 22.3.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: Protocol Independant Multicast
1767314
Major
RPD may restart unexpectedly when MSDP peers were reset or closed
Product-Group=junos
Severity=Major
When an MSDP peer is terminated, the peer's information may not be cleaned up properly. Causing the RPD process to restart unexpectedly.
PR NumberSynopsisCategory: Issues related to PKI daemon
1845573
Major
Auto-re-enrollment for local certificate once fail, not trigger again on SRX platforms
Product-Group=junos
Severity=Major
Added missing syslog messages for SCEP and CMPv2 certificate enrolment failure.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1876359
Minor
ON QFX5K and EX4K platforms a log is required for route leaking when destination table hits a platform limitation
Product-Group=junos
Severity=Minor
On Junos QFX5K and Junos EX4K switches, route leaking for IPv4 requires a minimum route mask of /16, and the leak destination table must have a prefix length longer than or equal to that of the leak prefix for proper routing. When this doesn't occur, traffic forwarding is affected, and there is no log associated with this event
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1820286
Major
The remote end of port JNP-SFPP-10GE-T doesn't shut down when the hardware is rebooted using request system reboot
Product-Group=junos
Severity=Major
On all Junos QFX devices or any platform which is using qfx-5e image, the interface JNP-SFPP-10GE-T does not get disabled using the CLI command "request system reboot" causing the remote end interface to show active.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platform optics related issues
1823771
Major
The SFP 10GBASE-T part No. 740-083295 on platforms running Junos/Junos EVO is unable to detect a linkdown
Product-Group=junos
Severity=Major
On Junos/Junos EVO platforms with the SFP 10GBASE-T part No. 740-083295 Link up/Link down is randomly not detected.
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1734549
Minor
Syslog messages modification for SNMPv3 authentication failure
Product-Group=junos
Severity=Minor
On all Junos and Junos Evolved platforms, the syslog message for a wrong auth/privacy and password has been changed to include more information.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1872025
Minor
Jade process crash is seen with RPC when radius is configured
Product-Group=junos
Severity=Minor
On EX4300 platforms, when radius is configured and a remote procedure call is made to the device, the jade process may crash generating a core-dump, causing the RPC to fail. This issue is consistently reproducible when radius is present in the authentication order and a radius server is configured.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1799215
Major
The commit fails error can be seen when configuration is modified after commit prepare
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, when the user attempts to issue the commit command after modifying the configuration post 'commit prepare', the commit discards the prepared commit cache as it is no longer valid and throws " commit fails" error and proceeds with the regular commit process from scratch.
1847834
Major
Multiple daemons crash upon ephemeral or static db commits
Product-Group=junos
Severity=Major
On all Junos platforms with ephemeral configuration, multiple daemons like chassisd, dcd, l2ald, l2cpd, mib2d and transportd crash upon ephemeral or static db commits causing service traffic impact. The services will self recover after the issue is hit in the network.
PR NumberSynopsisCategory: Issues related to NETCONF
1792362
Major
RPC request for file copy with routing instances is failing
Product-Group=junos
Severity=Major
On Junos OS and Junos OS Evolved platforms configured with routing instances, RPC (Remote Procedure Call) request for file copy using routing instance fails. There is no service/traffic impact due to this issue.
1796297
Major
Error message not prompted on commit confirmed RPC sent in private mode on all Junos and Junos Evolved platforms
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms, commit confirmed command executed with remote procedure call (RPC) in private configuration mode is being allowed where ideally it should not be.

 


 

21.4R3-S11 - List of Known issues 

PR NumberSynopsisCategory: EX4300 PFE
1848179
Minor
Counter for ipv6 egress filter does not work properly for EX4300
Product-Group=junos
On the EX4300, the egress Router Access Control List (eRACL) configured on the Layer 3 IPv6 interface with action count is not working.

Resolved In: junos:21.4R3-S11 junos:21.4X12-X1
PR NumberSynopsisCategory: BBE interface related issues
1703270
Major
RPF firewall filter errors during DHCP dual stack subscriber logout
Product-Group=junos
Firewall Filter errors are seen in PFE (Packet forwarding engine) when DHCP (Dynamic host control protocol) dual stack subscriber with RPF filter is logged-out.

Resolved In: evo:22.4R2-EVO evo:23.1R1-EVO junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Border Gateway Protocol
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D442 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-J4 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System crash is observed due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
On Junos OS platforms, the system runs out of memory due to mbuf (Memory Buffer) leak, leading to the system crash (VMcore is generated) resulting in service impact and error logs is observed. This issue happens when a firewall filter is applied to around 1k ifls (logical interface), each filter having > 250 terms and the filter is updated every 2-3 minutes which triggers an update for all filter attachments.

Resolved In: evo:22.4R3-S7-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
PR NumberSynopsisCategory: MX10K LC2101 Timing
1664569
Major
Switch Fabric Board information for supporting PTP on MX10k8 with MX10K-LC2101 LC(s)
Product-Group=junos
MX10k8 with MX10K-LC2101 Linecard(s) supports *PTP* only with JNP10008-SF Switch Fabric Board(s), *PTP* currently doesn't work with JNP10008-SF2 Switch Fabric Board(s).

Resolved In: evo:22.2R3-EVO evo:22.3R2-EVO evo:22.4R2-EVO evo:23.1R1-EVO junos:20.4R3-S8 junos:21.2R3-S6 junos:22.1R3-S5 junos:22.2R3 junos:22.3R2 junos:22.4R1 junos:22.4R2 junos:23.1R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1827648
Minor
ARP not learned on Switch Leading to Traffic Drop in EVPN-VXLAN Setup
Product-Group=junos
On all Junos QFX series platforms in an EVPN (Ethernet Virtual Private Network) VXLAN (Virtual Extensible Local Area Network) setup with CRB (Centralized Routing Bridge) architecture, ARP packets are not being learned, leading to traffic forwarding issues. This problem arises when ARP packets are sent from the firewall to the spine switches. The issue is linked to IRB (Integrated Routing and Bridging) handling and bridge domain re-incarnation, which triggers ARP request failures and impacts L3 forwarding.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S5 junos:23.2R2-S4 junos:23.4R2-S4 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: Flow Module
1859163
Minor
Security forwarding process crash may occur when multicast traffic triggers a route resolution request that needs to be processed for a pending session
Product-Group=junos
When multicast traffic triggers a route resolution request for a pending session, and the route is subsequently resolved, a race condition may occur if that pending session is terminated by a different thread before processing can continue. This can result in a crash of the flowd (security forwarding process). However, the control plane remains online and unaffected.

Resolved In: junos:21.4R3-S10-J1 junos:22.2R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:25.2R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on all Junos QFX and EX platforms due to memory corruption
Product-Group=junos
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on all Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.

Resolved In: junos:22.2R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: N/A:sw-rio-timing
1830382
Major
The PTP global info parameters announce-interval, synchronization-interval, and delay-response-interval unicast packets are not captured as expected
Product-Group=junos
On the Junos ACX5448 platform, the PTP min and max announce, sync and delay-request/response do not match with the configured values in the CLI output "show ptp global-information".

Resolved In: junos:21.2R3-S9 junos:22.4R3-S7 junos:24.2R2 junos:24.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1868085
Major
rpd crashes seen on multiple ACX7024x, system unable to core due to disk issue
Product-Group=junos
RPD asserts seen when BGP sharding is enabled.

Resolved In: evo:23.4R2-S5-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:25.2R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: usf nat related issues
1829633
Critical
The flowd process crashes in scaled scenario when subscribers exceed maximum session limit for NAPT44 on MX platforms with MX-SPC3
Product-Group=junos
On MX240, MX480 and MX960 with MX-SPC3 and in highly scaled subscriber scenario with high memory utilisation, MX-SPC3 reboots and flowd process crashes when subscriber received through Endpoint Independent Filtering (EIF) reaches the configured "max-sessions-per-subscriber" limit for Network Address and Port Translation(NAPT44).

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S3-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.4R1 junos:25.1R1

 

Modification History

First publication 2025-05-15