Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX10003 running Junos FIPS software

Alert Description

Junos Software Service Release version 19.3R3-S12 is now available for download from the Junos software download site.

This software release is specifically for MX10003 series running JUNOS FIPS software

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Review the SRN for an upgrade plan.

Solution

Junos Software service Release version 19.3R3-S12 is now available.

19.3R3-S12 - List of Fixed issues 

PR NumberSynopsisCategory: L2NG Access Security feature
1842682
Minor
Junos OS and Junos OS Evolved: Receipt of a specifically malformed DHCP packet causes jdhcpd process to crash (CVE-2025-30648)
Product-Group=junos
Severity=Minor
An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause the jdhcpd process to crash resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96458 [juniper.net] for more information.
PR NumberSynopsisCategory: Firewall Filter
1872347
Critical
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Critical
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: EVO L2 Control Protocols Support
1845098
Critical
Junos OS and Junos OS Evolved: Receipt of a malformed LLDP TLV results in l2cpd crash (CVE-2025-30646)
Product-Group=junos
Severity=Critical
A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malformed LLDP TLV to cause the l2cpd process to crash and restart, causing a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96456 [juniper.net] for more information.
PR NumberSynopsisCategory: SRX1500 platform software
1876867
Major
FPC goes offline and srxpfe core dump is generated during the system normal operation or boot-up
Product-Group=junosvae
Severity=Major
FPC (Flexible PIC Concentrators) on SRX1500 device goes offline and generates srxpfe core dump on system boot-up or normal operation in a rare timing scenario. This issue cause a traffic impact.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1840734
Major
RLT ifl remains down after RLT unit interface configuration is modified
Product-Group=junos
Severity=Major
On all Junos platforms which support PS over RLT, after modifying or deleting and re-adding a logical interface on RLT interface, the logical interface remains down and the following log messages is seen in the messages log:DCD_CONFIG_WRITE_FAILED: IFL rlt0.0 configuration write failed for an IFL ADD: File exists after configuration change.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1834204
Major
SRX becomes unresponsive when SNMP requests for VPN are received via the fxp0 interface immediately after a reboot
Product-Group=junos
Severity=Major
On Junos SRX platforms (except SRX1600, SRX2300, SRX4700 and SRX5000 series with SPC3 card) using the IPsec-key-management service (kmd) for VPNs (Virtual private networks), the SRX becomes unresponsive when SNMP (Simple Network Management Protocol) requests for VPN information are received via the fxp0 interface immediately after a reboot, before the IPC (Inter-Process Communication) connection to the PFE is fully established. This results in exhaustion of file descriptors (IO handlers) by kmd, preventing IPC connections from being established and impacting VPN operations and device manageability via SNMP.
PR NumberSynopsisCategory: lacp protocol
1616764
Major
BFD hold-down timer doesn't work properly when LAG is configured
Product-Group=junos
Severity=Major
On all devices, if the BFD hold timer is configured, the BFD hold-down timer doesn't work properly.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1695867
Major
VMHOST based platforms rebooted unexpectedly due to corruption in the system
Product-Group=junos
Severity=Major
On all Junos platforms with VMHOST, the device rebooted unexpectedly due to a minor corruption in the system.
1838460
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1825835
Major
IPsec traffic loss is observed when SA is stuck in the routing table even when the IPsec tunnel does not exist on the device
Product-Group=junos
Severity=Major
On MX platforms with MS-MPC/MS-MIC with IPsec (Internet Protocol Security) configured, IPsec traffic loss will be observed if an SA (Security Association) deletion request is sent by the peer just before the SA installation is completed. The issue happens in the scale scenario (4000 tunnels are configured, and when the SA count reaches up to 3900).
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1747009
Major
Traffic from subscribers will be dropped by Junos based MX platforms
Product-Group=junos
Severity=Major
On Junos based MX platforms in enhanced subscriber management scenario, with 'routing-services' and 'rpf-check' feature enabled all traffic from subscribers will be dropped.
1846055
Critical
PPE traps and traffic wedges are seen when subscribers are forwarded through Soft-GRE tunnel
Product-Group=junos
Severity=Critical
On all Junos MX platforms with MPC2-9 linecards, when subscribers are forwarded through the Soft-GRE (dynamic GRE tunnel), hardware memory corruption occurs resulting in PPE (Packet Processing Engines) traps being generated and traffic is impacted.
PR NumberSynopsisCategory: web filterig issues
1815930
Critical
Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop (CVE-2025-30658)
Product-Group=junos
Severity=Critical
A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://kb.juniper.net/JSA96469 [juniper.net] for more information.

 


 

19.3R3-S12 - List of Known issues 

PR NumberSynopsisCategory: EX2300/3400 PFE
1818760
Major
Junos OS: EX2300, EX3400, EX4000 Series, QFX5k Series: Receipt of a specific DHCP packet causes FPC crash when DHCP Option 82 is enabled (CVE-2025-30644)
Product-Group=junos
A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA96453 [juniper.net] for more information.

Resolved In: junos:20.3X75-D442 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to config-sync failure on Junos SRX platforms
Product-Group=junos
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the redundancy group (RG) priority is set to 0, preventing a successful failover during the ISSU process.

Resolved In: junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: "agentd" software daemon
1873990
Major
EX9208: Syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' every 5 sec
Product-Group=junos
On EX9200 series switch, syslog message 'JINSIGHTD_SENSOR_RESUBSCRIPTION' is seen every 5 sec

Resolved In: evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.2R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: BBE interface related issues
1850562
Major
Host unreachable from the router with PPPoE when "routing-service" and "RPF-check" are enabled, and the route is learned via EBGP
Product-Group=junos
On Junos platforms configured with BGP (Border Gateway Protocol) and rpf-check over PPPoE (PPP over Ethernet) subscribers, the platform is unable to reach the hosts present in the routing table when these are learnt by EBGP. This issue affects MX Platforms and QFX platforms.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S9 junos:22.4R3-S7 junos:23.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: the replication daemon (repd) for Shared Memory-base
1870183
Major
RPD might crash when upgrading using no-validate.
Product-Group=junos
RPD might crash when upgrading without using no-validate. Use no-validate to avoid the crash.

Resolved In: evo:22.2R3-S7-EVO evo:22.4R3-S7-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1709837
Critical
Junos OS and Junos OS Evolved: A crafted BGP UPDATE message allows a remote attacker to de-peer (reset) BGP sessions (CVE-2023-4481)
Product-Group=junos
An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA72510 [juniper.net] for more information.

Resolved In: evo:20.4R3-S10-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.1R3-S4-EVO evo:22.2R3-S3-EVO evo:22.2X100-D20-EVO evo:22.2X100-EVO evo:22.3R3-S1-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.3X80-D45-EVO evo:22.4R3-EVO evo:23.1R2-EVO evo:23.2R1-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.2R3-S10 junos:20.3X75-D36 junos:20.3X75-D44 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S10 junos:21.2R3-J2 junos:21.2R3-S4-J27 junos:21.2R3-S4-J29 junos:21.2R3-S4-J30 junos:21.2R3-S5-J21 junos:21.2R3-S5-J22 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S2-J24 junos:21.4R3-S3-J12 junos:21.4R3-S5 junos:21.4R3-S7 junos:22.1R3-S4 junos:22.2R3-S3 junos:22.3R2-S2 junos:22.3R3-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1-S1 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1
1750441
Major
Junos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crash (CVE-2024-30395)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA79095 [juniper.net] for more information.

Resolved In: evo:20.4R3-S9-EVO evo:21.2R3-S7-EVO evo:21.3R3-S5-EVO evo:21.4R3-S5-EVO evo:22.2R3-S3-EVO evo:22.2X100-EVO evo:22.3R3-S2-EVO evo:22.3X50-EVO evo:22.3X80-D39-EVO evo:22.4R3-EVO evo:23.2R1-S2-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO junos:18.4R3-S5-J11 junos:20.3X75-D36 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.4R3-S9 junos:21.2R3-S4-J27 junos:21.2R3-S4-J30 junos:21.2R3-S4-J37 junos:21.2R3-S7 junos:21.3R3-S5 junos:21.4R3-S5 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R1-S2 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.2R2
1754935
Major
BGP multipath route is not correctly applied after changing the IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, multipath route is not correctly applied due to this Equal-cost multi-path (ECMP) will not be formed, when Border Gateway Protocol (BGP) multipath is configured and the Interior Gateway Protocol (IGP) metric of a network is modified and subsequently reverted.

Resolved In: evo:21.4R3-S6-EVO evo:22.1R3-S5-EVO evo:22.2R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.4R3-EVO evo:23.2R2-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:21.2R3-S7-J3 junos:21.2R3-S9 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.3R3-S2-J2 junos:22.4R3 junos:23.2R2 junos:23.3R2 junos:23.4R1 junos:24.1R1
1787290
Critical
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP update causes the session to reset (CVE-2024-39555)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA83015 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S3 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1
1797147
Major
Junos OS and Junos OS Evolved: Receipt of a specific malformed BGP path attribute leads to an RPD crash (CVE-2024-47491)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA88116 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D46 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S7-J26 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S3-J17 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R1-S2 junos:23.4R2 junos:24.2R1 junos:24.3R1 junos:24.3R2
1797777
Minor
Junos OS and Junos OS Evolved: A specific CLI command will cause a RPD crash when rib-sharding and update-threading is enabled (CVE-2025-30655)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA96465 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.4R3-S2-EVO evo:23.2R2-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S6 junos:22.4R3-S2 junos:23.2R2-S3 junos:24.2R1 junos:24.3R1
1807533
Critical
Junos OS and Junos OS Evolved: When BGP traceoptions is enabled, receipt of specially crafted BGP packet causes RPD crash (CVE-2024-39525)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88102 [juniper.net] for more information.

Resolved In: evo:21.2R3-S8-EVO evo:21.4R3-S8-EVO evo:22.2R3-S4-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S1-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S8 junos:21.4R3-S8 junos:22.2R3-S4 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S1 junos:23.4R2 junos:23.4R2-S1 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1814083
Critical
Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash (CVE-2024-39515)
Product-Group=junos
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA88099 [juniper.net] for more information.

Resolved In: evo:21.4R3-S8-EVO evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:22.4R3-S3-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D52 junos:21.2R3-S7-J20 junos:21.2R3-S9 junos:21.4R3-S8 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1848929
Major
Junos OS and Junos OS Evolved: Executing a specific CLI command when asregex-optimized is configured causes an rpd crash (CVE-2025-30652)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker executing a CLI command to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA96462 [juniper.net] for more information.

Resolved In: evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:22.4R3-S6-EVO evo:23.2R2-S3-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D36 junos:20.3X75-D442 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.2R2-S5 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:25.2R1-EVO junos:20.3X75-D52 junos:25.2R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP-LU (Border Gateway Protocol-Labeled Unicast) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:24.2R2-J4 junos:24.4R2 junos:25.2R1 junos:25.3R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos


Resolved In: evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: BGP Segment Routing
1648377
Major
The rpd process crashes when BGP-LU with the prefix-sid attribute is enabled in Segment Routing scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms supporting Border Gateway Protocol Labeled Unicast (BGP-LU), if the bgp-prefix-sid attribute is enabled in a Segment Routing (SR) scenario, when two prefixes use the same prefix-sid at the same time, the rpd process will crash.

Resolved In: evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: Firewall Filter
1491492
Major
The match condition of forwarding-class for IPv6 filter might not capture the correct forwarding-class for the host outbound traffic
Product-Group=junos
The IPv6 filter might not capture the host outbound traffic with the expected forwarding-class match condition. This can result in IPv6 host outbound traffic forwarding control issues.

Resolved In: junos:19.4R3-S3 junos:20.2R2-S2 junos:20.2R3 junos:20.3R3 junos:20.3X75-D34 junos:20.3X75-D40 junos:20.4R1
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008/PTX10016/QFX10008/PTX1000/PTX10002/QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: EVPN control plane issues
1841965
Major
RPD core-dump on 22.2R3-S4
Product-Group=junos
RPD core occurs when we have an L3 instance (instance type: VRF) and an L2 instance for EVPN (instance type: MAC-VRF) with duplicate MAC detection enabled.

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.

Resolved In: junos:21.4R3-S10 junos:22.2R3-J15 junos:22.2R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ISIS routing protocol
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.

Resolved In: junos:23.4R2-S5 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1604123
Major
Junos OS: MX Series and SRX Series: The flowd daemon will crash if the SIP ALG is enabled and specific SIP messages are processed (CVE-2022-22175)
Product-Group=junos
An Improper Locking vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated networked attacker to cause a flowprocessing daemon (flowd) crash and thereby a Denial of Service (DoS). Continued receipt of these specific packets will cause a sustained Denial of Service condition. Refer to https://kb.juniper.net/JSA11281 [juniper.net] for more information.

Resolved In: junos:20.4R3-S1 junos:21.1R2-S2 junos:21.1R3 junos:21.2R1-S2 junos:21.2R2 junos:21.2R3 junos:21.3R1-S1 junos:21.3R2 junos:21.4R1 junos:22.1R1
PR NumberSynopsisCategory: Flow Module
1779792
Critical
Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash (CVE-2025-30645)
Product-Group=junos
A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd process, resulting in a Denial of Service (DoS). Continuous triggering of specific control traffic will create a sustained Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA96455 [juniper.net] for more information.

Resolved In: junos:20.2R3-S10 junos:21.2R3-S9 junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2 junos:24.2R1
PR NumberSynopsisCategory: N/A:sw-jsr-flow-mcast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.

Resolved In: junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1688972
Critical
PFE wedge will be seen due to fast link flaps
Product-Group=junos
When the 10/40/100G links of the same PFE (Packet Forwarding Engine) on MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards flap continuously, the whole PFE can wedge and all the links in that PFE will be affected.

Resolved In: evo:22.3R3-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:20.3X75-D46 junos:20.4R3-S7 junos:21.1R3-S5 junos:21.2R3-S2-J8 junos:21.2R3-S3-J10 junos:21.2R3-S4 junos:21.4R3-S1-J3 junos:21.4R3-S3 junos:22.1R3-S6 junos:22.2R3 junos:22.3R2 junos:22.3R3 junos:22.4R2 junos:22.4R3 junos:23.1R1 junos:23.2R1 junos:24.2R2
1719682
Major
LACP interface will be down after aggressive link flaps with 100ms interval
Product-Group=junos
When link flaps repeatedly within a very short time frame on 100G interface on MPC10E line card supported platforms(MX240, MX480, MX960, MX2010, MX2020), traffic stops egressing the affected interface and report syslog messages during link down event. When there are continous flaps and if those flaps are very fast under 1 second and continuous then this issue will be seen.

Resolved In: evo:23.2R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D46 junos:21.2R3-S2-J27 junos:21.2R3-S4-J33 junos:21.2R3-S4-J34 junos:21.2R3-S5-J31 junos:21.2R3-S5-J33 junos:21.2R3-S6-J6 junos:21.2R3-S6-J7 junos:21.2R3-S6-J8 junos:21.2R3-S7 junos:21.4R3-J4 junos:21.4R3-S1-J3 junos:21.4R3-S3-J13 junos:21.4R3-S4-J14 junos:21.4R3-S5-J4 junos:21.4R3-S6-J3 junos:21.4R3-S7 junos:22.1R3-S6 junos:22.2R3-S1-J10 junos:22.2R3-S3 junos:22.3R2-S1-J1 junos:22.3R3-S2 junos:22.4R2-S1-J4 junos:22.4R2-S1-J8 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: MX104 Software - Timing
1782868
Major
MX104 AFEB might crash following a change of PTP clock source.
Product-Group=junos
On MX104, the AFEB could crash and reboot following a change of PTP GM clock source, which affects traffic forwarding.

Resolved In: junos:21.2R3-S9
PR NumberSynopsisCategory: OS IPv4/ARP/ICMPv4
1881956
Major
IPv6 default route gets deleted from FIB by slaac daemon after an upgrade with an unsupported configuration
Product-Group=junos
On all Junos OS platforms , deletion of IPv6 default route from FIB (Forward Information Base) by slaacd (Stateless Address AutoConfiguration Daemon ) is observed while recovering the device from amnesiac state after the OS upgrade with any unsupported or incompatible configuration.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.

Resolved In: junos:21.2R3-S9 junos:21.4R3-S11 junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:25.3R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.

Resolved In: junos:22.4R3-S5 junos:23.2R2-S3 junos:24.2R2-S2
PR NumberSynopsisCategory: Express Chip L3 software
1583480
Critical
The egress traffic might be dropped after flapping the inet6 family from the AEx bundle
Product-Group=junos
In the same AE IFL of the PTX platforms with both IPv4 and IPv6 egress traffic scenario, both IPv4 and IPv6 next-hop share the same next-hop descriptor address. If flapping the inet6 family from the AEx bundle, the IPv6 next-hop might be created as IPv4 next-hop, then the egress next-hop might not be handled properly by PFE, it might cause the egress traffic to be forwarded through the IPv4 next-hop of that AE IFL, the egress packets might be dropped.

Resolved In: junos:18.2X75-D55 junos:20.3X75-D10 junos:20.3X75-D20 junos:20.4R3-S1-J10 junos:21.2R3-S10 junos:21.4R3-S11 junos:24.2R2-S2
1713279
Major
Next-hop programming issue at PFE on Junos PTX and QFX10k platforms when the member of unilist is in hold state
Product-Group=junos
On PTX Series routers and the QFX10000 line of switches, traffic going over unilist is dropped when unilist member goes from next-hop hold state to unicast/aggregate state.

Resolved In: junos:20.3X75-D42 junos:20.3X75-D43 junos:20.3X75-D46 junos:20.3X75-D51 junos:20.4R3-S1-J10 junos:20.4R3-S8 junos:21.2R3-S5-J4 junos:21.2R3-S5-J5 junos:21.2R3-S6 junos:21.3R3-S5 junos:21.4R3-S4 junos:21.4R3-S5 junos:22.1R3-S3 junos:22.1R3-S4 junos:22.2R3-S2 junos:22.2R3-S6 junos:22.3R3 junos:22.3R3-S1 junos:22.4R2 junos:22.4R2-S1 junos:22.4R3 junos:22.4R3-S1 junos:23.1R2 junos:23.2R1 junos:23.3R1
1761887
Major
ECMP traffic drop after the AE interface flap
Product-Group=junos
On Junos OS PTX and QFX platforms, in a race condition after the AE (Aggregated Ethernet) interface flap, PFE (Packet Forwarding Engine) will not update unilist next-hops with flapped AE next-hop correctly, causing ECMP (Equal-Cost Multi-Path) traffic drop.

Resolved In: junos:20.3X75-D36 junos:20.4R3-S1-J10 junos:21.4R3-S5-J1 junos:21.4R3-S5-J11 junos:21.4R3-S5-J8 junos:21.4R3-S5-J9 junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:25.3R1-EVO junos:23.2R2-S5 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.

Resolved In:
PR NumberSynopsisCategory: QFX5100 Interface related issues
1555741
Major
The Virtual Chassis Port (VCP) might not come up after upgrading to 18.4R2-S4 or later releases on EX4600 or QFX5100 platform
Product-Group=junos
In EX4600 or QFX5100 with the Virtual Chassis (VC) scenario, if the QSFP+-40G-LR4/LX4/BXSR is used as the Virtual Chassis Port (VCP), it might come up against the optical signal strength issue accidentally after upgrading to 18.4R2-S4 or later releases. Then the VCP might be brought down by the physical port driver randomly and not come up again. The functionality of VC or the Virtual Chassis Fabric (VCF) might be impacted.

Resolved In: junos:18.4R2-S9 junos:19.1R3-S7 junos:19.4R3-S6 junos:20.1R3-S2 junos:20.2R3-S3 junos:20.3R3-S1 junos:20.4R3-S1 junos:21.1R3 junos:21.2R2 junos:21.3R1 junos:21.4R1
PR NumberSynopsisCategory: KRT Queue issues within RPD
1761667
Major
The rpd process and chassisd process crash is seen
Product-Group=junos
On Junos and Junos Evolved platforms configuring BGP causes the rpd to crash abnormally and later chassisd crashes too.

Resolved In: evo:22.2R3-S3-EVO evo:22.3R3-S3-EVO evo:22.3X50-EVO evo:22.3X80-D43-EVO evo:22.3X80-D44-EVO evo:22.3X80-D45-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.4R1-EVO evo:23.4R2-EVO evo:24.1R1-EVO evo:24.2R2-EVO evo:24.4R1-EVO junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-J10 junos:22.2R3-S3 junos:22.2R3-S4 junos:22.3R3-S2-J2 junos:22.3R3-S3 junos:22.4R3-J6 junos:22.4R3-S1 junos:22.4R3-S7 junos:23.2R1-S1-J7 junos:23.2R2 junos:23.2R2-J14 junos:23.2R2-S4 junos:23.4R1 junos:23.4R2 junos:23.4R2-S4 junos:24.1R1 junos:24.2R2
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1806694
Major
Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash (CVE-2025-21593)
Product-Group=junos
An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA92861 [juniper.net] for more information.

Resolved In: evo:22.2R3-S5-EVO evo:22.3R3-S4-EVO evo:22.3X50-EVO evo:22.3X80-D45-EVO evo:22.3X80-D46-EVO evo:23.2R2-S2-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:19.1R3-S14 junos:20.3X75-D52 junos:21.2R3-S9 junos:21.4R3-S10 junos:22.2R3-S5 junos:22.3R3-S4 junos:22.4R3-S3 junos:23.2R2-S2 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: HA functionality on ASP
1853304
Major
Traffic was lost on MX platforms following a Routing Engine failover
Product-Group=junos
On Junos MX240/MX480/MX960/MX2010/MX2020 platforms which support TLB (Traffic-Load Balancer) the PFE (Packet Forwarding Engine) is not properly synchronized with the new master RE (Routing Engine) after a RE failover causing traffic loss

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S6-J25 junos:21.2R3-S9 junos:22.2R3-S7 junos:23.2R2-J18 junos:23.2R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1819376
Minor
The 1G interface might be down after upgradation on SRX4600 platform
Product-Group=junos
On SRX4600 platform, upgrading from any earlier release to Junos 23.2R2 or later whether via ISSU (in-service software upgrade) or a standard upgrade process can cause the 1G interfaces to go down when the speed is changed from 10G to 1G. As a result, the port fails to activate properly at 1G, remaining down and unable to transmit any traffic.

Resolved In: junos:21.4R3-S9 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S2 junos:23.4R2-S2-J14 junos:23.4R2-S3 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO junos:21.2R3-S5-J52 junos:23.2R2-S4 junos:23.4R2-S3-J16 junos:23.4R2-S4-J17 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Major
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:21.4R3-S10 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1807742
Major
Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information (CVE-2025-30654)
Product-Group=junos
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged, authenticated attacker with access to the CLI to access sensitive information. Please refer to https://supportportal.juniper.net/JSA96464 [juniper.net] for more information.

Resolved In: evo:21.4R3-S10-EVO evo:22.2R3-S6-EVO evo:22.3X50-EVO evo:22.3X80-D47-EVO evo:22.4R0-J0-EVO evo:22.4R3-S5-EVO evo:23.4R2-S3-EVO evo:23.4X100-D20-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO junos:20.3X75-D36 junos:20.3X75-D441 junos:20.3X75-D46 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:21.2R3-S9 junos:21.2X32-D30 junos:21.4R3-S10 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S3 junos:23.4R2-S3 junos:24.2R1 junos:24.2R2 junos:24.3R1 junos:24.4R1
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S3-J23 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: PTX/QFX10002/8/16 specific software components
1734703
Major
Speed configuration mismatch causes the ukern core on Junos PTX10008 and PTX10016 platforms
Product-Group=junos
On Junos PTX10008 and PTX10016 platforms, when the speed configuration on the interface is not matching with the speed of the optics present in the port, it causes memory corruption because of this FPC will crash and restart. Traffic loss till the FPC restarts after the ukern core.

Resolved In: junos:20.3X75-D36 junos:20.4R3-S10 junos:20.4R3-S8 junos:21.2R3-S7 junos:21.4R3-S9 junos:22.2R3-S7 junos:22.4R3 junos:23.1R2 junos:23.2R2 junos:23.3R1 junos:23.4R1
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
On MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S6-J8 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S4 junos:23.4R2-S4-J3 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1



Modification History

First publication 2025-06-18