Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

JUNOS FIPS Software for MX204, NFX150, SRX family except for SRX380, SRX345, and SRX1500

Alert Description

Junos Software Service Release version 19.2R3-S12 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Please review.

Solution

Junos Software service Release version 19.2R3-S12 is now available.

19.2R3-S12 - List of Fixed issues 

PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Critical
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).

 


 

19.2R3-S12 - List of Known issues 

PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to config-sync failure on Junos SRX platforms
Product-Group=junos
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the redundancy group (RG) priority is set to 0, preventing a successful failover during the ISSU process.

Resolved In: junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
RPD might crash when upgrading without using no-validate. Use no-validate to avoid the crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.4R3-S7-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1709837
Critical
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-D20-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D45-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.2R3-S10 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:21.4R3-S7 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
1754935
Major
BGP multipath route is not correctly applied after changing the IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, multipath route is not correctly applied due to this Equal-cost multi-path (ECMP) will not be formed, when Border Gateway Protocol (BGP) multipath is configured and the Interior Gateway Protocol (IGP) metric of a network is modified and subsequently reverted.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:21.2R3-S7-J3 junos:21.2R3-S9 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.3R3-S2-J2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.

Resolved In: evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:25.2R1-EVO junos:20.3X75-D52 junos:25.2R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Firewall Filter
1491492
Major
The match condition of forwarding-class for IPv6 filter might not capture the correct forwarding-class for the host outbound traffic
Product-Group=junos
The IPv6 filter might not capture the host outbound traffic with the expected forwarding-class match condition. This can result in IPv6 host outbound traffic forwarding control issues.

Resolved In: junos:19.4R3-S3 junos:20.2R2-S2 junos:20.2R3 junos:20.3R3 junos:20.3X75-D34 junos:20.3X75-D40 junos:20.4R1
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008/PTX10016/QFX10008/PTX1000/PTX10002/QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EVPN control plane issues
1841965
Major
RPD core-dump on 22.2R3-S4
Product-Group=junos
RPD core occurs when we have an L3 instance (instance type: VRF) and an L2 instance for EVPN (instance type: MAC-VRF) with duplicate MAC detection enabled. For example: instance-type virtual-switch; protocols { evpn { duplicate-mac-detection { auto-recovery-time-seconds 30; Currently, there is no workaround, and no logs are available to help identify the root cause. Issue has been fixed on: 23.4R2-S4-EVO 25.2R1-EVO 24.4R2-EVO

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.

Resolved In: junos:21.4R3-S10 junos:22.2R3-J15 junos:22.2R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: ISIS routing protocol
1751371
Critical
ISIS export policy does not export all default routes (IPv6 and IPv4) from BGP (or any other protocol)
Product-Group=junos
On all Junos and Junos Evolved platforms, traffic flow will be impacted when only one of the default routes (either IPv4 or IPv6) will get exported into IS-IS (Intermediate System-Intermediate System) i.e. other AF (address-family) default routes (either IPv4 or IPv6) will not get exported when the default route for both IPv6 and IPv4 is getting exported into IS-IS via BGP (Border Gateway Protocol) (or any other protocol).

Resolved In: evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.2R2-S3 junos:23.3R1 junos:23.3R2 junos:23.4R1
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.

Resolved In: junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: jpppd daemon
1854387
Critical
The jpppd process will crash with frequent subscribers login/logout
Product-Group=junos
On Junos and Junos OS Evolved platforms, the jpppd (Juniper PPP daemon) process crash will be seen after a certain time of subscribers login/logout. The issue could also be seen with the applications that write their private data in /mfs/var/sdb/shmem/sdb_intf.ad.db, such as jl2tpd (Juniper L2TP daemon), repd (replication daemon) jdhcpd (Juniper DHCP daemon) and others.

Resolved In: evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1645022
Major
Junos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if the SIP ALG is enabled and specific SIP messages are processed (CVE-2023-22412)
Product-Group=junos
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC or MS-MIC card and SRX Series allows an unauthenticated, network-based attacker to cause a flow processing daemon (flowd) crash and thereby a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA70208 [juniper.net] for more information.

Resolved In: junos:20.4R3-S4 junos:21.1R3-S3 junos:21.2R3-S2 junos:21.3R3 junos:21.4R3 junos:22.1R2 junos:22.2R1 junos:22.2R2 junos:22.3R1
PR NumberSynopsisCategory: N/A:sw-jsr-flow-mcast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.

Resolved In: junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1688972
Critical
PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.3X75-D46 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S2-J8 junos:21.2R3-S3-J10 junos:21.2R3-S4 junos:21.4R3-S1-J3 junos:21.4R3-S3 junos:22.1R3-S6 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1 junos:23.2R1 junos:24.2R2
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.

Resolved In: junos:22.4R3-S5 junos:23.2R2-S3
PR NumberSynopsisCategory: Express Chip L3 software
1583480
Critical
The egress traffic might be dropped after flapping the inet6 family from the AEx bundle
Product-Group=junos
In the same AE IFL of the PTX platforms with both IPv4 and IPv6 egress traffic scenario, both IPv4 and IPv6 next-hop share the same next-hop descriptor address. If flapping the inet6 family from the AEx bundle, the IPv6 next-hop might be created as IPv4 next-hop, then the egress next-hop might not be handled properly by PFE, it might cause the egress traffic to be forwarded through the IPv4 next-hop of that AE IFL, the egress packets might be dropped.

Resolved In: junos:18.2X75-D55 junos:20.3X75-D10 junos:20.3X75-D20 junos:20.4R3-S1-J10 junos:21.2R3-S10 junos:21.4R3-S11 junos:24.2R2-S2
1713279
Major
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.

Resolved In: junos:20.3X75-D42 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D51 junos:20.4R3-S1-J10 junos:20.4R3-S8 junos:21.2R3-S5-J4 junos:21.2R3-S5-J5 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S4 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.2R3-S6 junos:22.3R3 junos:22.3R3-S1 junos:22.4R2 junos:22.4R2-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
1761887
Major
ECMP traffic drop after the AE interface flap
Product-Group=junos
On Junos OS PTX and QFX platforms, in a race condition after the AE (Aggregated Ethernet) interface flap, PFE (Packet Forwarding Engine) will not update unilist next-hops with flapped AE next-hop correctly, causing ECMP (Equal-Cost Multi-Path) traffic drop.

Resolved In: junos:20.3X75-D36 junos:20.4R3-S1-J10 junos:21.4R3-S5-J1 junos:21.4R3-S5-J11 junos:21.4R3-S5-J8 junos:21.4R3-S5-J9 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.

Resolved In:
PR NumberSynopsisCategory: QFX5100 Interface related issues
1555741
Major
The Virtual Chassis Port (VCP) might not come up after upgrading to 18.4R2-S4 or later releases on EX4600 or QFX5100 platform
Product-Group=junos
In EX4600 or QFX5100 with the Virtual Chassis (VC) scenario, if the QSFP+-40G-LR4/LX4/BXSR is used as the Virtual Chassis Port (VCP), it might come up against the optical signal strength issue accidentally after upgrading to 18.4R2-S4 or later releases. Then the VCP might be brought down by the physical port driver randomly and not come up again. The functionality of VC or the Virtual Chassis Fabric (VCF) might be impacted.

Resolved In: junos:18.4R2-S9 junos:19.1R3-S7 junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.4R3-S1 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667
Major
The rpd process and chassisd process crash is seen
Product-Group=junos
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S2-J2 junos:22.3R3-S3 junos:22.4R3-J6 junos:22.4R3-S1 junos:22.4R3-S7 junos:23.2R1-S1-J7 junos:23.2R2 junos:23.2R2-J14 junos:23.2R2-S4 junos:23.4R1 junos:23.4R2 junos:23.4R2-S4 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S6-J25 junos:21.2R3-S9 junos:22.2R3-S7 junos:23.2R2-J18 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376
Minor
The 1G interface might be down after upgradation on SRX4600 platform
Product-Group=junos
On SRX4600 platform, upgrading from any earlier release to Junos 23.2R2 or later whether via ISSU (in-service software upgrade) or a standard upgrade process can cause the 1G interfaces to go down when the speed is changed from 10G to 1G. As a result, the port fails to activate properly at 1G, remaining down and unable to transmit any traffic.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S2-J14 junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S5-J52 junos:23.2R2-S4 junos:23.4R2-S3-J16 junos:23.4R2-S4-J17 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S3-J23 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1734703
Major
Speed configuration mismatch causes the ukern core on Junos PTX10008 and PTX10016 platforms
Product-Group=junos
On Junos PTX10008 and PTX10016 platforms, when the speed configuration on the interface is not matching with the speed of the optics present in the port, it causes memory corruption because of this FPC will crash and restart. Traffic loss till the FPC restarts after the ukern core.

Resolved In: junos:20.3X75-D36 junos:20.4R3-S10 junos:20.4R3-S8 junos:21.2R3-S7 junos:21.4R3-S9 junos:22.2R3-S7 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
On MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S4 junos:23.4R2-S4-J3 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1

 

Modification History

First publication 2025-06-12