Alert Type

SRN - Software Release Notification
Low/NotificationFIPS Software Release Notification
Low/NotificationFIPS Software Release Notification

Product Affected

JUNOS FIPS Software for MX204, NFX150, SRX family except for SRX380, SRX345, and SRX1500

Alert Description

Junos Software Service Release version 19.2R3-S11 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review and plan for upgrade as necessary

Solution

Junos Software service Release version 19.2R3-S11 is now available.

19.2R3-S11 - List of Fixed issues

PR NumberSynopsisCategory: L2NG Access Security feature
1842682
Minor
Junos OS and Junos OS Evolved: Receipt of a specifically malformed DHCP packet causes jdhcpd process to crash (CVE-2025-30648)
Product-Group=junos
Severity=Minor
An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96458 [juniper.net] for more information.
PR NumberSynopsisCategory: Ethernet OAM (LFM)
1811734
Major
The LFM session flaps will be observed at random
Product-Group=junos
Severity=Major
On Junos ACX5448 & ACX710 platforms with LFM (Link-fault-management) configured in distributed mode, the LFM session flaps will be seen at random when the peer device has LFM configured in inline mode. This will result in traffic loss.
PR NumberSynopsisCategory: EVO L2 Control Protocols Support
1845098
Critical
Junos OS and Junos OS Evolved: Receipt of a malformed LLDP TLV results in l2cpd crash (CVE-2025-30646)
Product-Group=junos
Severity=Critical
A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96456 [juniper.net] for more information.
PR NumberSynopsisCategory: Express PFE Services including JTI, TOE, HostPath, Jflow
1830575
Major
The dcpfe crashes when ukern_trace handle buffer size is set to 10000
Product-Group=junos
Severity=Major
On all Junos platforms, the dcpfe crash is seen with a core-dcpfe dump when the ukern_trace handle buffer size is set to 10000. It is a rare issue.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1840734
Major
RLT ifl remains down after RLT unit interface configuration is modified
Product-Group=junos
Severity=Major
On all Junos platforms which support PS over RLT, after modifying or deleting and re-adding a logical interface on RLT interface, the logical interface remains down and the following log messages is seen in the messages log:DCD_CONFIG_WRITE_FAILED: IFL rlt0.0 configuration write failed for an IFL ADD: File exists after configuration change.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1834204
Major
SRX becomes unresponsive when SNMP requests for VPN are received via the fxp0 interface immediately after a reboot
Product-Group=junos
Severity=Major
On Junos SRX platforms (except SRX1600, SRX2300, SRX4700 and SRX5000 series with SPC3 card) using the IPsec-key-management service (kmd) for VPNs (Virtual private networks), the SRX becomes unresponsive when SNMP (Simple Network Management Protocol) requests for VPN information are received via the fxp0 interface immediately after a reboot, before the IPC (Inter-Process Communication) connection to the PFE is fully established. This results in exhaustion of file descriptors (IO handlers) by kmd, preventing IPC connections from being established and impacting VPN operations and device manageability via SNMP.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1695867
Major
VMHOST based platforms rebooted unexpectedly due to corruption in the system
Product-Group=junos
Severity=Major
On all Junos platforms with VMHOST, the device rebooted unexpectedly due to a minor corruption in the system.
1838460
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: TCP/UDP transport layer
1670303
Critical
Junos OS: Receipt of crafted TCP packets destined to the device results in MBUF leak, leading to a Denial of Service (DoS) (CVE-2023-22396)
Product-Group=junos
Severity=Critical
An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a Denial of Service (DoS). Please refer https://kb.juniper.net/JSA70192 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
Severity=Major
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1747009
Major
Traffic from subscribers will be dropped by Junos based MX platforms
Product-Group=junos
Severity=Major
On Junos based MX platforms in enhanced subscriber management scenario, with 'routing-services' and 'rpf-check' feature enabled all traffic from subscribers will be dropped.
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
PR NumberSynopsisCategory: web filterig issues
1815930
Critical
Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop (CVE-2025-30658)
Product-Group=junos
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://kb.juniper.net/JSA96469 [juniper.net] for more information.

 


 

19.2R3-S11 - List of Known issues

PR NumberSynopsisCategory: EX2300/3400 PFE
1818760
Major
Junos OS: EX2300, EX3400, EX4000 Series, QFX5k Series: Receipt of a specific DHCP packet causes FPC crash when DHCP Option 82 is enabled (CVE-2025-30644)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA96453 [juniper.net] for more information.

Resolved In: junos:20.3X75-D442 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Border Gateway Protocol
1709837
Critical
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-D20-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D45-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.2R3-S10 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:21.4R3-S7 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
1750441
Major
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-30395)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79095 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S4-J27 junos:21.2R3-S4-J30 junos:21.2R3-S4-J37 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.2R2
1797777
Minor
Junos OS and Junos OS Evolved: A specific CLI command will cause a RPD crash when rib-sharding and update-threading is enabled (CVE-2025-30655)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA96465 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.4R3-S2-EVO evo:23.2R2-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S6 junos:22.4R3-S2 junos:23.2R2-S3 junos:24.2R1 junos:24.3R1
1848929
Major
Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configured causes an rpd crash (CVE-2025-30652)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96462 [juniper.net] for more information.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D36 junos:20.3X75-D442 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Flow Module
1779792
Critical
Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash (CVE-2025-30645)
Product-Group=junos
A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a Denial of Service (DoS). Continuous triggering of specific control traffic will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA96455 [juniper.net] for more information.

Resolved In: junos:20.2R3-S10 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1678431
Major
Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash (CVE-2024-21613)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA75754 [juniper.net] for more information.

Resolved In: evo:21.3R3-S5-EVO evo:21.4R3-EVO evo:22.1R3-EVO evo:22.2R2-EVO evo:22.2R3-EVO evo:22.3R1-EVO evo:22.3R2-EVO evo:22.4R1-EVO junos:19.4R3-S13 junos:20.3X75-D35 junos:20.3X75-D42 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-S3 junos:21.3R3-S5 junos:21.4R3-S3 junos:22.1R3 junos:22.2R2 junos:22.2R3 junos:22.3R1 junos:22.3R2 junos:22.4R1
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S11 junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1806694
Major
Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash (CVE-2025-21593)
Product-Group=junos
An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA92861 [juniper.net] for more information.

Resolved In: evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:19.1R3-S14 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1807742
Major
Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information (CVE-2025-30654)
Product-Group=junos
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Please refer to https://supportportal.juniper.net/JSA96464 [juniper.net] for more information.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.3X80-D47-EVO evo:22.4R3-S5-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52-J3 junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S10 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1

Modification History

First publication 2025-05-22