diff --git a/content/cumulus-linux-37/Whats-New/rn.md b/content/cumulus-linux-37/Whats-New/rn.md
index 848f012a24..aa4925f7c4 100644
--- a/content/cumulus-linux-37/Whats-New/rn.md
+++ b/content/cumulus-linux-37/Whats-New/rn.md
@@ -268,7 +268,7 @@ pdfhidden: True
| 3216921 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)
| 3.7.0-3.7.16, 4.3.0-4.4.5 | |
| 3216759 | With the ip-acl-heavy TCAM profile, the following message might appear after you install an ACL with NCLU or cl-acltool and the ACL might not work correctly
hal_flx_acl_util.c:378 ERR hal_flx_acl_resource_release resource region 0 size 7387 create failed: No More ResourcesTo work around this issue, change the TCAM profile to
acl-heavy or ip-acl-heavy with ACL non-atomic mode. | 3.7.15-3.7.16, 4.3.0-4.4.5 | |
| 3209699 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)clagd service loses communication after 198 days of uptime. | 3.7.15-3.7.16 | |
| 3120423 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the /etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-4.3.0, 4.4.0-5.1.0 | 4.3.1, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3093966 | On Broadcom switches, INPUT chain iptable rules filter IPv6 packets matching the rules. | 3.7.15-3.7.16, 4.3.0-4.4.5 | |
@@ -530,7 +530,7 @@ pdfhidden: True
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3216921 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)sudo poectl -a \| grep disabled command to find ports with disabled POE. Run the sudo poectl -e swp1-swp48 command to enable POE on affected ports. | 3.7.10-3.7.16 | |
| 2959067 | ECMP produces errors indicating No More Resources and switchd crashes even when ECMP utilization is low. | 3.7.14.2-4.2.1 | 4.3.0-4.4.5|
@@ -752,7 +752,7 @@ pdfhidden: True
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3216921 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)sudo poectl -a \| grep disabled command to find ports with disabled POE. Run the sudo poectl -e swp1-swp48 command to enable POE on affected ports. | 3.7.10-3.7.16 | |
| 2940076 | In a VXLAN fabric with ToR switches configured in a MLAG pair, BUM traffic received on a VXLAN tunnel is decapsulated and forwarded on the peer link bond. The BUM traffic is then encapsulated by the peer switch and sent back to the fabric. The issue has been seen in environments where the following conditions exist at the same time:1) high VNI scale2) switchd is busy processing updates3) clagd is in a transition state, such as Up, then Down, then Up. For example, when clagd restarts, the switch reboots, and so onclagd state transition. | 3.7.12-3.7.15 | 3.7.16|
@@ -1006,7 +1006,7 @@ pdfhidden: True
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3216921 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)sudo poectl -a \| grep disabled command to find ports with disabled POE. Run the sudo poectl -e swp1-swp48 command to enable POE on affected ports. | 3.7.10-3.7.16 | |
| 2940076 | In a VXLAN fabric with ToR switches configured in a MLAG pair, BUM traffic received on a VXLAN tunnel is decapsulated and forwarded on the peer link bond. The BUM traffic is then encapsulated by the peer switch and sent back to the fabric. The issue has been seen in environments where the following conditions exist at the same time:1) high VNI scale2) switchd is busy processing updates3) clagd is in a transition state, such as Up, then Down, then Up. For example, when clagd restarts, the switch reboots, and so onclagd state transition. | 3.7.12-3.7.15 | 3.7.16|
@@ -1278,7 +1278,7 @@ pdfhidden: True
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3216921 | RADIUS authenticated users with read-only access to NCLU commands (users in the users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)users_with_show list) can run edit commands if a username for a non-local account is on the users_with_edit line of the /etc/netd.conf file. To work around this issue, make sure that all usernames on the users_with_edit line of the /etc/netd.conf file are configured local users for the system (real Linux users)sudo poectl -a \| grep disabled command to find ports with disabled POE. Run the sudo poectl -e swp1-swp48 command to enable POE on affected ports. | 3.7.10-3.7.16 | |
| 2940076 | In a VXLAN fabric with ToR switches configured in a MLAG pair, BUM traffic received on a VXLAN tunnel is decapsulated and forwarded on the peer link bond. The BUM traffic is then encapsulated by the peer switch and sent back to the fabric. The issue has been seen in environments where the following conditions exist at the same time:1) high VNI scale2) switchd is busy processing updates3) clagd is in a transition state, such as Up, then Down, then Up. For example, when clagd restarts, the switch reboots, and so onclagd state transition. | 3.7.12-3.7.15 | 3.7.16|
diff --git a/content/cumulus-linux-37/rn.xml b/content/cumulus-linux-37/rn.xml
index 2084c8c867..1d731ab2d6 100644
--- a/content/cumulus-linux-37/rn.xml
+++ b/content/cumulus-linux-37/rn.xml
@@ -1958,8 +1958,8 @@ To work around this issue, change the TCAM profile to {{acl-heavy}} or {{ip-acl-
peerlink.4095 interface stanza are duplicated. Subsequent ifreloads, or net commit commands fail until you manually remove the duplicated lines from this interface and run ifreload -a. | 4.2.1-4.4.5 | |
| 3376798 | On Broadcom switches, Cumulus Linux does not create the hardware bridging domain for a traditional bridge with a VXLAN interface during switchd restart. The /var/log/switchd.log file includes the following exception logs shortly after switchd restarts:switchd[30158]: hal_bcm_l3.c:1617 find_egr_path_if_vxlan_overlay:vxlan overlay : nh PORT: port <#>, vlanMAC learning looks correct, but traffic does not flow as expected. | 3.7.0-4.3.1 | 4.3.2-4.4.5| | 3364996 | Under certain conditions, BGP can allow a combination of EVPN and non-EVPN paths to be put into a multipath group together. This results in erroneous programming of EVPN symmetric next hops and RMACs, which can result in momentary traffic drops. | 4.3.0-4.3.1 | 4.3.2-4.4.5| +| 3364717 | On the Trident 2+ and Trident 3 switch when using VXLAN layer 2 VPNs and sending tunneled traffic where the inner IP header has a TTL of 1, the egress VTEP incorrectly forwards this traffic through the software path instead of the hardware data plane. This traffic is rate-limited to 100pps by default. To work around this issue, ensure that the traffic traversing the layer 2 tunnel has an inner IP header TTL value that is more than 1. If this workaround is not possible, contact Nvidia Support to determine other options. | 4.3.0-4.4.5 | | +| 3358865 | When you reboot a Broadcom switch with a static default route configured, the route might be installed in hardware without a next hop. This results in forwarded traffic to the CPU and drops. To recover from this issue, remove the default route configuration and reapply it. To prevent this issue, before rebooting the switch, split the default route configuration into two routes as below:. not yet ready
ip route 0.0.0.0/1 10.1.1.1ip route 128.0.0.0/1 10.1.1.1| 4.3.1-4.4.5 | | | 3339249 | The
sensors.conf files in Cumulus Linux are out of date. | 4.2.1-4.4.5 | |
-| 3336590 | On the Trident 2+ and Trident 3 switch when using VXLAN layer 2 VPNs and sending tunneled traffic where the inner IP header has a TTL of 1, the egress VTEP incorrectly forwards this traffic through the software path instead of the hardware data plane. This traffic is rate-limited to 100pps by default. To work around this issue, ensure that the traffic traversing the layer 2 tunnel has an inner IP header TTL value that is more than 1. If this workaround is not possible, contact Nvidia Support to determine other options. | 4.3.0-4.3.1 | 4.3.2-4.4.5|
| 3334031 | When you configure or unconfigure a BGP peer and interface towards a host, memory corruption can cause BGP to crash. | 4.3.0-4.3.1 | 4.3.2-4.4.5|
| 3330705 | When using TACACS+, a TACACS+ server name that returns more than one IP address, such as an IPv6 and IPv4 address, is counted many times against the limit of seven TACACS+ servers, which might cause some of the later listed servers to be ignored as over the limit. To work around this issue, you can set the prefer_ip_version configuration option (the default value is 4) to choose between an IPv4 or IPv6 address if both are present. | 3.7.0-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3319919 | Currently, the default core dump size limit on Cumulus Linux is 256M but the SDK generates core dumps around 800M. To avoid incomplete core files, you can increase the core dump size limit. | 4.2.1-4.3.1, 4.4.0-5.3.1 | 4.3.2, 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3288385 | On the EdgeCore AS7326-56X and AS7726-32X switch, the fan speed reports a minimum threshold in the logs. | 4.3.1 | 4.3.2-4.4.5|
-| 3288343 | When you reboot a Broadcom switch with a static default route configured, the route might be installed in hardware without a next hop. This results in forwarded traffic to the CPU and drops. To recover from this issue, remove the default route configuration and reapply it. To prevent this issue, before rebooting the switch, split the default route configuration into two routes as below:ip route 0.0.0.0/1 10.1.1.1ip route 128.0.0.0/1 10.1.1.1| 4.3.1 | 4.3.2-4.4.5| | 3269538 | The
cl-ecmpcalc command prints the following error when the egress interface is a bond or SVI:ecmpcalc: will query hardwareTraceback (most recent call last):File “/usr/cumulus/bin/cl-ecmpcalc”, line 986, inisTrunkMbr, port = ecmp.getHdPort(hd_cmd)File “/usr/cumulus/bin/cl-ecmpcalc”, line 618, in getHdPortport = int(str4)ValueError: invalid literal for int() with base 10: ‘0t| 3.7.16-4.3.1 | 4.3.2-4.4.5| | 3267353 | In a QinQ configuration, if the VLAN priority is a non-zero value, double-tagged packets are translated to triple-tagged packets. | 4.3.1 | 4.3.2-4.4.5| | 3235956 | With certain triggers on Broadcom switches, such as adding or deleting a VNI or reloading the network, Cumulus Linux might consider the underlay routes as overlay routes. In this case,
switchd allocates the overlay next hop, which is incorrect and might affect traffic forwarding. | 4.3.0-4.3.1 | 4.3.2-4.4.5|
@@ -1383,8 +1383,8 @@ pdfhidden: True
| 3390022, 3323138 | When you restore the switch configuration after upgrading from Cumulus Linux 4.2.x to 4.4.5 and later with ONIE, the configuration lines under the peerlink.4095 interface stanza are duplicated. Subsequent ifreloads, or net commit commands fail until you manually remove the duplicated lines from this interface and run ifreload -a. | 4.2.1-4.4.5 | |
| 3376798 | On Broadcom switches, Cumulus Linux does not create the hardware bridging domain for a traditional bridge with a VXLAN interface during switchd restart. The /var/log/switchd.log file includes the following exception logs shortly after switchd restarts:switchd[30158]: hal_bcm_l3.c:1617 find_egr_path_if_vxlan_overlay:vxlan overlay : nh PORT: port <#>, vlanMAC learning looks correct, but traffic does not flow as expected. | 3.7.0-4.3.1 | 4.3.2-4.4.5| | 3364996 | Under certain conditions, BGP can allow a combination of EVPN and non-EVPN paths to be put into a multipath group together. This results in erroneous programming of EVPN symmetric next hops and RMACs, which can result in momentary traffic drops. | 4.3.0-4.3.1 | 4.3.2-4.4.5| +| 3364717 | On the Trident 2+ and Trident 3 switch when using VXLAN layer 2 VPNs and sending tunneled traffic where the inner IP header has a TTL of 1, the egress VTEP incorrectly forwards this traffic through the software path instead of the hardware data plane. This traffic is rate-limited to 100pps by default. To work around this issue, ensure that the traffic traversing the layer 2 tunnel has an inner IP header TTL value that is more than 1. If this workaround is not possible, contact Nvidia Support to determine other options. | 4.3.0-4.4.5 | | | 3339249 | The. not yet ready
sensors.conf files in Cumulus Linux are out of date. | 4.2.1-4.4.5 | |
-| 3336590 | On the Trident 2+ and Trident 3 switch when using VXLAN layer 2 VPNs and sending tunneled traffic where the inner IP header has a TTL of 1, the egress VTEP incorrectly forwards this traffic through the software path instead of the hardware data plane. This traffic is rate-limited to 100pps by default. To work around this issue, ensure that the traffic traversing the layer 2 tunnel has an inner IP header TTL value that is more than 1. If this workaround is not possible, contact Nvidia Support to determine other options. | 4.3.0-4.3.1 | 4.3.2-4.4.5|
| 3334031 | When you configure or unconfigure a BGP peer and interface towards a host, memory corruption can cause BGP to crash. | 4.3.0-4.3.1 | 4.3.2-4.4.5|
| 3330705 | When using TACACS+, a TACACS+ server name that returns more than one IP address, such as an IPv6 and IPv4 address, is counted many times against the limit of seven TACACS+ servers, which might cause some of the later listed servers to be ignored as over the limit. To work around this issue, you can set the prefer_ip_version configuration option (the default value is 4) to choose between an IPv4 or IPv6 address if both are present. | 3.7.0-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3327477 | If you use su to change to a user specified through TACACS+, the user becomes the local tacacs0 thru tacacs15 user instead of the named user to run sudo commands. As a result, the named user password might not match the local tacacs0 thru tacacs15 user password. | 3.7.0-3.7.16, 4.0.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
diff --git a/content/cumulus-linux-43/rn.xml b/content/cumulus-linux-43/rn.xml
index 0b10f237ec..d12706fded 100644
--- a/content/cumulus-linux-43/rn.xml
+++ b/content/cumulus-linux-43/rn.xml
@@ -7644,18 +7644,28 @@ MAC learning looks correct, but traffic does not flow as expected.
switchd might contribute to high CPU load while it continues to try to sync and resolve the neighbor entry. This results in many sync_l3_nexthop messages printed to /var/log/switchd.log. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3131423 | During EVPN multihoming bond failover, ARP and ND redirection fails if you configure layer 2 VNIs and ES bonds before you configure the loopback IP address of the switch. To work around this issue, configure the loopback IP address, then restart FRR with the systemctl restart frr command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3123965 | Under heavy system load, when many forwarding resources (routes, neighbors, ECMP groups, and so on) are removed from hardware, subsequent attempts to configure additional forwarding resources might fail and you see the following log message:sx_sdk: EMAD_RX_THREAD: EMAD transaction FW error| 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3123556 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the
/etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3120423 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the /etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-4.3.0, 4.4.0-5.1.0 | 4.3.1, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3119673, 2888040 | If the switch receives an EVPN route with multiple RTs that match the import policy for a local VNI, the bgpd service crashes. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3119615 | In an MLAG configuration, if you put a single connected interface into an admin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3117340 | When you edit the /usr/share/openvswitch/scripts/ovs-ctl-vtep file to change the ovs-vtepd configuration between vlan-aware and vlan-unaware mode, ovs-vtepd crashes when you restart the service. To recover, restart the networking service with the sudo systemctl restart networking command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3115415 | In the Cumulus-BGPVRF-MIB, the bgpPeerFsmEstablishedTime OID does not correctly report the time since a BGP session goes down. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3112971 | When you configure a VRF static route using the legacy command syntax in FRR (for example: ip route 10.0.0.0/8 172.16.1.1 vrf vrf-red), then make subsequent VRF or route configuration changes, FRR might crash. To avoid this problem, use the current method for configuring VRF routes within the VRF stanza:vrf vrf-red| 4.4.3-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3112938 | In the Cumulus-BGPVRF-MIB, the
ip route 10.0.0.0/8 172.16.1.1 vrf vrf-redend vrf
bgpPeerFsmEstablishedTransitions OID always reports a value of 0. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3102128 | When you configure a new VNI, the VLAN 1 VNI mapping is removed from the VXLAN device. To work around this issue, set the VNI interface mapped to VLAN 1 down and up again. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3085285 | The snmpd process will slowly leak memory when you poll TCP-MIB objects. To work around this issue, restart the snmpd service to free memory with the systemctl restart snmpd command. | 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3084476 | After you disable traffic shaping in the /etc/cumulus/datapath/qos/qos_features.conf file, the default QOS traffic shaping configuration does not restore. To work around this issue, restart switchd. | 4.4.3, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 4.4.4-4.4.5|
| 3084027 | Under a high load, you might see ingress drop counters increase. The drops are classified as HwIfInDiscards in ethtool and shown as ingress_general in hardware. | 4.3.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 3081232 | On the NVIDIA Spectrum 1 switch, when a port goes down, it might not come back up| 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3077547, 2812075 | When you configure multiple multicast RPs with groups matched by prefix lists, Cumulus Linux selects only one of the RPs and this selection is incorrect. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3077513 | When a MAC address is moved to a new VTEP in an EVPN MAC mobility scenario using traditional bridges, there might be up to 30 seconds of convergence delay. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3074390, 3055255, 2602877 | You can not apply NVUE configurations when TACACS is enabled for user authentication. To work around this issue, add the
cumulus@switch:~$ nv set vrf default router bgp neighbor 10.10.10.2 bfd min-rx-interval 400
cumulus@switch:~$ nv config apply
2022-05-04T21:36:10.800975+00:00 switch frrinit.sh16431: Stopped watchfrr.
nvue account to the exclude_users line in /etc/tacplus_nss.conf:exclude_users=root,daemon,nobody,cron,radius_user,radius_priv_user,sshd,cumulus,quagga,frr,nvue,snmp,www-data,ntp,man,_lldpd,*| 5.0.1-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| +| 3072674 | In an MLAG configuration, if you put a single connected interface into an
admin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3066664 | In an EVPN-MH configuration, the switch fails to redirect tagged frames with the CoS bits set. | 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3061445 | When you run the NVUE command to change the minimum interval between received BFD control packets or the minimum interval for sending BFD control packets, the configuration apply failscumulus@switch:~$ nv set vrf default router bgp neighbor 10.10.10.2 bfd min-rx-interval 400cumulus@switch:~$ nv config apply2022-05-04T21:36:10.800975+00:00 switch frrinit.sh16431: Stopped watchfrr| 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3059566 | When you add an interface to a layer 3 bond, traffic does not forward and you see errors similar to the following:
2022-05-02T13:14:40.118597+00:00 cumulus sx_sdk: ROUTER: Failed to delete router interface(27) ref count isn’t 0, err= Resource is in use| 4.4.2-4.4.3, 5.0.1-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| @@ -109,7 +107,7 @@ pdfhidden: True | 3021897 | After you remove the port from the EVPN-MH bond, the port stays in the PRTDN state with the
protodown flag ON. | 4.4.3-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3021838 | PBR rules that you apply to interfaces in the default VRF install in the kernel with the action lookup local. As a result, packets that match this rule only perform a route lookup in the local table (which contains special routes for local IP addresses and broadcast addresses) but not in the main table (which contains unicast routes). As a result, policy routing might be applied to traffic incorrectly. | 4.4.2-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3021696 | On the NVIDIA SN4600C switch, when you run the /usr/share/snmp/resq_pp.py script used by SNMP, you see the following log message in syslog regardless of the forwarding table profile set in the /etc/cumulus/datapath/traffic.conf fileresq_pp: EXCEPTION=invalid literal for int() with base 10: 'v4-lpm-heavy'| 4.4.0-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3021693 | When ARP suppression is off, GARPs from
neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3020254 | When ARP suppression is off, GARPs from neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.3.0, 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.3.1, 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3017127 | After you convert a port from a layer 2 bond member to a layer 3 port, the switch drops transmitted untagged packets as egress VLAN membership discards. | 4.4.2-4.4.3, 5.0.0-5.0.1 | 4.4.4-4.4.5, 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3016882 | In certain cases, when you power cycle the switch, the NVUE configuration might become corrupted, which prevents NVUE from running. You see a critical error in the log file similar to:CRITICAL: cue_versions_v1.repo: The NVUE internal data store is corrupted or has been initialized incorrectly. The is an unrecoverable errorTo work around this issue, remove the
/var/lib/nvue/config and /var/lib/nvue/meta directories, then restart the nvued service with the sudo systemctl start nvued command. If possible, NVUE recovers user configuration and saves it in the /etc/nvue.d directory. The recovered configuration will be saved as YAML files, which are named as nvue-recovery-.yaml . You can reapply the recovered configuration with the nv config patch nvue-recovery-.yaml followed by nv config apply commands. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3014664 | On the NVIDIA SN3420, the smonctl command output shows the maximum PSU temperature higher than the critical temperature. | 4.4.2-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -225,18 +223,16 @@ pdfhidden: True
| 3138057 | When the next hop interface for EVPN type 5 routes flaps, FRR might uninstall the routes and Route install failed appears in /var/log/frr/frr.log. To work around this problem, restart FRR with the sudo systemctl restart frr command. | 4.4.0-5.2.1 | 5.3.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3131423 | During EVPN multihoming bond failover, ARP and ND redirection fails if you configure layer 2 VNIs and ES bonds before you configure the loopback IP address of the switch. To work around this issue, configure the loopback IP address, then restart FRR with the systemctl restart frr command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3123965 | Under heavy system load, when many forwarding resources (routes, neighbors, ECMP groups, and so on) are removed from hardware, subsequent attempts to configure additional forwarding resources might fail and you see the following log message:sx_sdk: EMAD_RX_THREAD: EMAD transaction FW error| 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3123556 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the
/etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3120423 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the /etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-4.3.0, 4.4.0-5.1.0 | 4.3.1, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3119673, 2888040 | If the switch receives an EVPN route with multiple RTs that match the import policy for a local VNI, the bgpd service crashes. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3119615 | In an MLAG configuration, if you put a single connected interface into an admin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3117340 | When you edit the /usr/share/openvswitch/scripts/ovs-ctl-vtep file to change the ovs-vtepd configuration between vlan-aware and vlan-unaware mode, ovs-vtepd crashes when you restart the service. To recover, restart the networking service with the sudo systemctl restart networking command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3115415 | In the Cumulus-BGPVRF-MIB, the bgpPeerFsmEstablishedTime OID does not correctly report the time since a BGP session goes down. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3112971 | When you configure a VRF static route using the legacy command syntax in FRR (for example: ip route 10.0.0.0/8 172.16.1.1 vrf vrf-red), then make subsequent VRF or route configuration changes, FRR might crash. To avoid this problem, use the current method for configuring VRF routes within the VRF stanza:vrf vrf-red| 4.4.3-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3112938 | In the Cumulus-BGPVRF-MIB, the
ip route 10.0.0.0/8 172.16.1.1 vrf vrf-redend vrf
bgpPeerFsmEstablishedTransitions OID always reports a value of 0. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3102128 | When you configure a new VNI, the VLAN 1 VNI mapping is removed from the VXLAN device. To work around this issue, set the VNI interface mapped to VLAN 1 down and up again. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3085285 | The snmpd process will slowly leak memory when you poll TCP-MIB objects. To work around this issue, restart the snmpd service to free memory with the systemctl restart snmpd command. | 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3084476 | After you disable traffic shaping in the /etc/cumulus/datapath/qos/qos_features.conf file, the default QOS traffic shaping configuration does not restore. To work around this issue, restart switchd. | 4.4.3, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 4.4.4-4.4.5|
| 3084027 | Under a high load, you might see ingress drop counters increase. The drops are classified as HwIfInDiscards in ethtool and shown as ingress_general in hardware. | 4.3.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 3081232 | On the NVIDIA Spectrum 1 switch, when a port goes down, it might not come back upadmin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3066664 | In an EVPN-MH configuration, the switch fails to redirect tagged frames with the CoS bits set. | 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3059135, 3060400 | In an OSPF configuration, after you change the IPv6 subnet mask, the old address remains in the RIB as a connected OSPF routesudo systemctl restart frr command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3054869, 3148920 | When you run NVUE commands as part of ZTP scripts, the commands fail with errors that indicate a missing $HOME environment variable. The issue has been fixed where the ZTP module initializes the $HOME environment variable before launching the ZTP scripts. However, if you are running older releases, before you use any NVUE commands in the ZTP script, add a section and define the HOME environment variable. Populate the variable with the default expected root user home directory value (/root), then export the HOME variable so it is available globally for NVUE to useHOME=/rootexport HOME| 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| @@ -249,7 +245,7 @@ pdfhidden: True | 3021897 | After you remove the port from the EVPN-MH bond, the port stays in the PRTDN state with the
protodown flag ON. | 4.4.3-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3021838 | PBR rules that you apply to interfaces in the default VRF install in the kernel with the action lookup local. As a result, packets that match this rule only perform a route lookup in the local table (which contains special routes for local IP addresses and broadcast addresses) but not in the main table (which contains unicast routes). As a result, policy routing might be applied to traffic incorrectly. | 4.4.2-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3021696 | On the NVIDIA SN4600C switch, when you run the /usr/share/snmp/resq_pp.py script used by SNMP, you see the following log message in syslog regardless of the forwarding table profile set in the /etc/cumulus/datapath/traffic.conf fileresq_pp: EXCEPTION=invalid literal for int() with base 10: 'v4-lpm-heavy'| 4.4.0-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3021693 | When ARP suppression is off, GARPs from
neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3020254 | When ARP suppression is off, GARPs from neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.3.0, 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.3.1, 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3017127 | After you convert a port from a layer 2 bond member to a layer 3 port, the switch drops transmitted untagged packets as egress VLAN membership discards. | 4.4.2-4.4.3, 5.0.0-5.0.1 | 4.4.4-4.4.5, 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3014664 | On the NVIDIA SN3420, the smonctl command output shows the maximum PSU temperature higher than the critical temperature. | 4.4.2-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3008388 | When you set vlan-bridge-binding on for a VLAN interface, the VLAN interface status does not change to down even when all bridge member ports are down. | 4.4.3-5.0.1 | 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-50/rn.xml b/content/cumulus-linux-50/rn.xml
index 46ad0dd880..fda726109f 100644
--- a/content/cumulus-linux-50/rn.xml
+++ b/content/cumulus-linux-50/rn.xml
@@ -414,10 +414,10 @@ sx_sdk: EMAD_RX_THREAD: EMAD transaction FW error
sudo systemctl restart hw-management.service command to restart the hardware management service. | 5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3131423 | During EVPN multihoming bond failover, ARP and ND redirection fails if you configure layer 2 VNIs and ES bonds before you configure the loopback IP address of the switch. To work around this issue, configure the loopback IP address, then restart FRR with the systemctl restart frr command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3123965 | Under heavy system load, when many forwarding resources (routes, neighbors, ECMP groups, and so on) are removed from hardware, subsequent attempts to configure additional forwarding resources might fail and you see the following log message:sx_sdk: EMAD_RX_THREAD: EMAD transaction FW error| 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3123556 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the
/etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3120423 | When you configure an interface in FRR to send IPv6 RAs before you configure the interface in the /etc/network/interfaces file, the switch does not process IPv6 RAs. To work around this issue, remove the interface configuration in FRR and reapply it. | 3.7.15-4.3.0, 4.4.0-5.1.0 | 4.3.1, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3119673, 2888040 | If the switch receives an EVPN route with multiple RTs that match the import policy for a local VNI, the bgpd service crashes. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3119615 | In an MLAG configuration, if you put a single connected interface into an admin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3117340 | When you edit the /usr/share/openvswitch/scripts/ovs-ctl-vtep file to change the ovs-vtepd configuration between vlan-aware and vlan-unaware mode, ovs-vtepd crashes when you restart the service. To recover, restart the networking service with the sudo systemctl restart networking command. | 4.3.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3115419 | When you configure conditional advertisement, BGP might crash when you run show commands or during a steady state. | 5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3115415 | In the Cumulus-BGPVRF-MIB, the bgpPeerFsmEstablishedTime OID does not correctly report the time since a BGP session goes down. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -104,17 +103,16 @@ pdfhidden: True
| 3112971 | When you configure a VRF static route using the legacy command syntax in FRR (for example: ip route 10.0.0.0/8 172.16.1.1 vrf vrf-red), then make subsequent VRF or route configuration changes, FRR might crash. To avoid this problem, use the current method for configuring VRF routes within the VRF stanza:vrf vrf-red| 4.4.3-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3112938 | In the Cumulus-BGPVRF-MIB, the
ip route 10.0.0.0/8 172.16.1.1 vrf vrf-redend vrf
bgpPeerFsmEstablishedTransitions OID always reports a value of 0. | 4.4.4-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3102128 | When you configure a new VNI, the VLAN 1 VNI mapping is removed from the VXLAN device. To work around this issue, set the VNI interface mapped to VLAN 1 down and up again. | 5.0.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3085285 | The snmpd process will slowly leak memory when you poll TCP-MIB objects. To work around this issue, restart the snmpd service to free memory with the systemctl restart snmpd command. | 4.4.0-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3084476 | After you disable traffic shaping in the /etc/cumulus/datapath/qos/qos_features.conf file, the default QOS traffic shaping configuration does not restore. To work around this issue, restart switchd. | 4.4.3, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 4.4.4-4.4.5|
| 3084027 | Under a high load, you might see ingress drop counters increase. The drops are classified as HwIfInDiscards in ethtool and shown as ingress_general in hardware. | 4.3.0-4.4.5, 5.0.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3084007, 3334028 | The clagd process uses 100 percent CPU and eventually crashes with an Unable to allocate memory errorsyslog writes phcsync phc_ctl set clock time messages continuously every minute even when supervisord is not running, which prevents critical information from being logged. | 5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3082463 | On the NVIDIA SN4800 switch, the LED on the line cards does not match the CLI command output. | 5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 3081232 | On the NVIDIA Spectrum 1 switch, when a port goes down, it might not come back up| 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3077547, 2812075 | When you configure multiple multicast RPs with groups matched by prefix lists, Cumulus Linux selects only one of the RPs and this selection is incorrect. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3077513 | When a MAC address is moved to a new VTEP in an EVPN MAC mobility scenario using traditional bridges, there might be up to 30 seconds of convergence delay. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 3074390, 3055255, 2602877 | You can not apply NVUE configurations when TACACS is enabled for user authentication. To work around this issue, add the
cumulus@switch:~$ nv set vrf default router bgp neighbor 10.10.10.2 bfd min-rx-interval 400
cumulus@switch:~$ nv config apply
2022-05-04T21:36:10.800975+00:00 switch frrinit.sh16431: Stopped watchfrr.
nvue account to the exclude_users line in /etc/tacplus_nss.conf:exclude_users=root,daemon,nobody,cron,radius_user,radius_priv_user,sshd,cumulus,quagga,frr,nvue,snmp,www-data,ntp,man,_lldpd,*| 5.0.1-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| +| 3072674 | In an MLAG configuration, if you put a single connected interface into an
admin down state, any dynamic MAC addresses on the peer link are flushed, then added back, which causes momentary traffic disruption. | 3.7.15-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3071652 | On rare occasions, after you reboot or restart switchd on a Spectrum 1 switch, any 25G connections with Direct Attach Copper (DAC) cables that connect from the switch to a non-NVIDIA device might flap continuously. To work around this issue, bring the affected link administratively down for a few seconds on the non-NVIDIA device, then bring the link back up. | 4.4.4-4.4.5, 5.1.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 3069069, 3271536 | When you run the systemctl reload switchd command, there is momentary traffic loss after a port configured with lossless buffers goes down. This is only temporary and the traffic stabilizes after the initial drops. | 5.1.0-5.5.1 | 5.6.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3066664 | In an EVPN-MH configuration, the switch fails to redirect tagged frames with the CoS bits set. | 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -135,7 +133,7 @@ pdfhidden: True
| 3037824 | The NVUE nv show interface link state command shows an empty table instead of showing the port link state. | 5.0.0-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3034435, 3101184 | In an MLAG EVPN deployment when either of the MLAG peers reboots, FRR incorrectly programs the local host entries in the ARP table as remote. To work around this issue, either restart FRR or use BGP policies to mark and drop routes within an MLAG pair. Both MLAG peers must have an outbound policy that add a community representing the unique MLAG pair to Type-2 EVPN routes and an inbound policy to match and drop that community. | 4.4.4-5.4.0 | 5.5.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3023345 | When you run NVUE commands to unset one or more options associated with a field, the command fails with an error. For example:cumulus@switch:~$ nv unset system forwarding ecmp-hash source-portusage: nv unset system forwarding ecmp-hash [options]nv unset system forwarding ecmp-hash: error: unrecognized arguments: source-port| 5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 3021693 | When ARP suppression is off, GARPs from
neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 3020254 | When ARP suppression is off, GARPs from neighmgrd for remote neighbors are sent over VXLAN. | 3.7.15-4.3.0, 4.4.0-4.4.3, 5.0.0-5.1.0 | 4.3.1, 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3016882 | In certain cases, when you power cycle the switch, the NVUE configuration might become corrupted, which prevents NVUE from running. You see a critical error in the log file similar to:CRITICAL: cue_versions_v1.repo: The NVUE internal data store is corrupted or has been initialized incorrectly. The is an unrecoverable errorTo work around this issue, remove the
/var/lib/nvue/config and /var/lib/nvue/meta directories, then restart the nvued service with the sudo systemctl start nvued command. If possible, NVUE recovers user configuration and saves it in the /etc/nvue.d directory. The recovered configuration will be saved as YAML files, which are named as nvue-recovery-.yaml . You can reapply the recovered configuration with the nv config patch nvue-recovery-.yaml followed by nv config apply commands. | 5.0.1-5.1.0 | 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3015393 | The NVUE nv show interface command shows the operational state of the tunnel as down even though the tunnel is up, and encapsulation and decapsulation occurs correctly. | 5.1.0-5.3.1 | 5.4.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 3014664 | On the NVIDIA SN3420, the smonctl command output shows the maximum PSU temperature higher than the critical temperature. | 4.4.2-4.4.3, 5.0.0-5.1.0 | 4.4.4-4.4.5, 5.2.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-51/rn.xml b/content/cumulus-linux-51/rn.xml
index 1d6340f2fe..8261881195 100644
--- a/content/cumulus-linux-51/rn.xml
+++ b/content/cumulus-linux-51/rn.xml
@@ -558,10 +558,10 @@ sx_sdk: EMAD_RX_THREAD: EMAD transaction FW error
nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -192,6 +193,7 @@ pdfhidden: True
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -235,7 +237,6 @@ pdfhidden: True
| 4066219 | Some STP interfaces might remain in a blocking state when there are large numbers of discontiguous VLANs enabled on a port. | 5.8.0-5.9.3, 5.10.0-5.10.1 | 5.9.4, 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4065849 | A firmware upgrade on certain Innolight cables might get stuck or fail. | 5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4065847 | Due to internal definition changes in Module firmware, ISSU on Spectrum-4 switches from earlier releases to Cumulus Linux 5.10.1 is not supported. | 5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4062271, 4048679 | ASIC monitoring histogram collection might not work because of a crash in the asic-monitor service. To work around this issue, see the Release Considerations section of the What’s New. | 5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4062001 | With VM migration from one VTEP to another, traffic loss might occur during a MAC move as locally learned MAC addresses are frequently refreshed in the kernel. | 5.8.0-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4061534 | When you remove a secondary OTLP collector, there is a telemetry spike and existing connections with OTLP exporters reset. When new connections with the OTLP collector re-establish, the server experiences a high CPU and memory leak, which can bring down the telemetry collection service. | 5.10.0-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4052578 | When you perform a binary upgrade from Cumulus Linux 5.8 or earlier to 5.9.0 or later with a pre-staged startup.yaml file, the cumulus user password is reset to the default password because there is no default startup.yaml file present in 5.8.0 or earlier. To work around this issue, generate the startup.yaml file from the existing NVUE configuration. | 5.9.2-5.11.5 | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -245,18 +246,19 @@ pdfhidden: True
| 4048583 | If there are failures in MSTPD or a port is not updated in the database, the NVUE nv show bridge domain stp command might not work and might produce errors even when STP has data for other working ports or VLANs. This is a display issue only and does not impact functionality. | 5.10.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4047829, 4040901, 4040916 | Ports can be operationally down if the switchd service fails to come UP due to certain firmware failures and you the following switchd.log messages:PDDR long process T.O
MCIA no response
FW assert [0x8C91] detected
shutdown -r +1 to schedule a reboot after one minute so that the ZTP process can successfully complete disabling the ztp.service systemd service. | 5.10.0 | 5.9.2, 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4042657 | The SDK times out with a FW FATAL health event, which requires a reboot of the system to recover. | 5.9.1-5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4042262 | The switchd service goes down and there is a FW Long Command Timeout. | 5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4040024 | After network churn, the watchfrr process might restart FRR because zebra is unresponsive. | 5.9.1-5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4039850 | When the MAC address of the neighbor changes, a possible crash might occur because the pointer to which the MAC address points is freed, resulting in a dangling pointer. | 5.3.1-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4037462 | The Open telemetry interface statistic description for nvswitch_histogram_interface_egress_buffer has a typographical error; engress should be egress. | 5.10.0 | 5.10.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4037315 | NVUE fails to enforce the password length limitation of 512 characters or fewer. | 5.10.0-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4037224, 4048679 | ASIC monitoring histogram collection might not work because of a crash in the asic-monitor service. To work around this issue, see the Release Considerations section of the What’s New. | 5.10.0 | 5.10.1-5.15.1, 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4030380 | When you roll back interface configuration to the default setting with the nv unset interface command, NVUE removes the complete entry for the interface from the /etc/network/interface file, and puts the interface in admin down. As a result, you cannot configure FEC on the interface at the lower layers. | 5.10.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4023318 | If you run nv set commands after you perform an upgrade but before a reboot, NVUE creates a revision based off the pre-upgrade version. After reboot, the revision contains pre-upgrade data that might cause it to fail during config apply. To work around this issue, detach the stale revision after upgrade with the nv config detach command. | 5.10.0-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4022906 | If you use NVUE to configure a bond, apply a port mirror on the bond, then run the nv config apply command, the validation fails.nv config apply command before you configure the port mirror on the bond. | 5.10.0-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4019257 | Some switches start booting but stop at the boot menu because console‑port noise is misinterpreted as input. | 5.9.1-5.10.1 | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4019256 | If you change the switch hostname, the histogram data producer service restarts. | 5.10.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4016216 | If a ZTP script includes a directive to reboot, the reboot might stop the running ZTP process before it is able to disable itself from running again. As a result, the ZTP process starts again when the system comes back up. To work around this issue, run shutdown -r +1 to schedule a reboot after one minute so that the ZTP process can successfully complete disabling the ztp.service systemd service. | 5.10.0 | 5.9.2, 5.10.1-5.15.1, 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4005422, 4015452 | When you upgrade Cumulus Linux 5.9.1 to Cumulus Linux 5.10 or later with package upgrade, the NTP service stops. To restart the NTP service, enable, then restart the service in the VRF in which it was running with the systemctl enable ntpsec@ and systemctl restart ntpsec@ commands. | 5.10.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4004898 | When you configure the SNMP server listening address to a VRF that has no interfaces, snmp.service fails.default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640898 | When a new LLDP neighbor is discovered with an empty or missing Port Description TLV; for example, when introducing a new third-party switch into the fabric, a ptmd defect might cause a segmentation fault (crash). | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640126 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -212,15 +214,16 @@ pdfhidden: True
| 4930152 | When you configure layer 3 SVI interfaces with an anycast gateway (VRR) IP address only and no unique IP address, the connected route for the subnet is not programmed in the ASIC, causing packets destined for locally connected hosts to drop after decapsulation. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 4805286 | During port‑mapping configuration, an edge case might lead to an invalid configuration state, causing the system to eventually become stuck. | 5.11.3-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4829843 | During port‑mapping configuration, an edge case might lead to an invalid configuration state, causing the system to eventually become stuck. | 5.11.3-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4771874 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4731091, 4857885 | During optimized image upgrade, the switch logs an error because a new file is added. There is no functional impact. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4729839 | In an MLAG configuration, when you reboot the primary MLAG switch with PVRST spanning tree mode configured on both MLAG switches, PVRST mode briefly changes to RSTP, then back to PVRST when the primary switch comes back up. | 5.11.3-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4683602 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640898 | When a new LLDP neighbor is discovered with an empty or missing Port Description TLV; for example, when introducing a new third-party switch into the fabric, a ptmd defect might cause a segmentation fault (crash). | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640126 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -384,12 +387,13 @@ pdfhidden: True
| 4930152 | When you configure layer 3 SVI interfaces with an anycast gateway (VRR) IP address only and no unique IP address, the connected route for the subnet is not programmed in the ASIC, causing packets destined for locally connected hosts to drop after decapsulation. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 4805286 | During port‑mapping configuration, an edge case might lead to an invalid configuration state, causing the system to eventually become stuck. | 5.11.3-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4829843 | During port‑mapping configuration, an edge case might lead to an invalid configuration state, causing the system to eventually become stuck. | 5.11.3-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4771874 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4729839 | In an MLAG configuration, when you reboot the primary MLAG switch with PVRST spanning tree mode configured on both MLAG switches, PVRST mode briefly changes to RSTP, then back to PVRST when the primary switch comes back up. | 5.11.3-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4683602 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640898 | When a new LLDP neighbor is discovered with an empty or missing Port Description TLV; for example, when introducing a new third-party switch into the fabric, a ptmd defect might cause a segmentation fault (crash). | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640126 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -550,9 +554,10 @@ pdfhidden: True
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4771874 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4683602 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640898 | When a new LLDP neighbor is discovered with an empty or missing Port Description TLV; for example, when introducing a new third-party switch into the fabric, a ptmd defect might cause a segmentation fault (crash). | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640126 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -749,9 +754,10 @@ pdfhidden: True
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4771874 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4683602 | When you poll optical module data with ethtool -m, switchd might crash due to a firmware timeout that triggers a fatal health-check failure. | 5.11.1-5.11.4 | 5.9.5, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -961,6 +967,7 @@ pdfhidden: True
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-511/rn.xml b/content/cumulus-linux-511/rn.xml
index dbcb97c538..e78cfa22b6 100644
--- a/content/cumulus-linux-511/rn.xml
+++ b/content/cumulus-linux-511/rn.xml
@@ -45,6 +45,12 @@
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4686865 | An invalid hashed-password string for a local NVUE user causes all nv config apply operations (including unrelated changes) to fail health checks and raise tracebacks when NVUE attempts to recreate the user. | 5.12.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4667010 | When streaming telemetry is enabled, additional logs containing ERROR BULK_COUNTER might be generated by the switch, unexpectedly bypassing log suppression rules. | 5.12.1-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -239,6 +241,7 @@ pdfhidden: True
| 5093873 | When you configure BGP dynamic neighbors and default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4686865 | An invalid hashed-password string for a local NVUE user causes all nv config apply operations (including unrelated changes) to fail health checks and raise tracebacks when NVUE attempts to recreate the user. | 5.12.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4640898 | When a new LLDP neighbor is discovered with an empty or missing Port Description TLV; for example, when introducing a new third-party switch into the fabric, a ptmd defect might cause a segmentation fault (crash). | 5.11.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -337,8 +341,8 @@ pdfhidden: True
| 4291970 | When you enable NVUE pagination with the nv set system cli pagination state enabled command, even short outputs become paginated inside less even though they fit the terminal. If you want to see pagination only for CLI outputs larger than the terminal size, set nv set system cli pagination state to auto. | 5.12.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4290634 | When you run the nv show interface counters command, there is a delay in showing the output. | 5.12.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4290629 | The NVUE nv show interface qos command takes approximately two minutes to display output. To work around this issue, fetch only the sub commands that are part of the nv show interface qos, command such as buffer, congestion-control, pfc, and so on. | 5.12.0-5.12.1 | 5.11.2, 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4288264 | Optimized (two partition) upgrade and rollback fails when you apply configuration by editing the /etc/nvue.d/startup.yaml file, then run nv config apply startup. To work around this issue, after activating optimized upgrade, but before rebooting, save a copy of the contents of /var/lib/nvue/ to some other location. Then, after activating rollback, but before rebooting, move /var/lib/nvue/ to some other location and copy the previously saved contents to /var/lib/nvue/. | 5.12.0 | 5.11.1, 5.12.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4286833 | When you change the port breakout configuration, the switch deletes, then recreates the port and the sflow configuration on the port resets. However, switchd continues to retain sflow configuration for the same logical ID, which leads to divergence in sflow configuration in the SDK and switchd; switchd sees sflow enabled for the port but in the SDK the ports gets reset to disabled. | 5.12.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4286489 | Optimized (two partition) upgrade and rollback fails when you apply configuration by editing the /etc/nvue.d/startup.yaml file, then run nv config apply startup. To work around this issue, after activating optimized upgrade, but before rebooting, save a copy of the contents of /var/lib/nvue/ to some other location. Then, after activating rollback, but before rebooting, move /var/lib/nvue/ to some other location and copy the previously saved contents to /var/lib/nvue/. | 5.12.0 | 5.11.1, 5.12.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4281438, 4257936 | The first time you run the nv show interface rates command, an internal error occurs. | 5.12.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4277042 | On the NVIDIA SN5600 switch, you see low power alarms immediately after a reboot. The alarms disappear after showing up initially. Certain modules typically show low power alarms on initialization. No action is needed. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4270240 | Statically configured VXLAN FDB entries do not age out. | 5.12.0-5.12.1 | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-512/rn.xml b/content/cumulus-linux-512/rn.xml
index 18ca19dea7..9ccf0a7a42 100644
--- a/content/cumulus-linux-512/rn.xml
+++ b/content/cumulus-linux-512/rn.xml
@@ -52,6 +52,12 @@ sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK t
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON objectnv action upgrade system packages command sometimes fails or might be interrupted after the packages are unpacked but not configured. As a result, you might see issues such as missing files or symlinks, or TACACS+ restricted user shells not working as expected. If the dpkg -l command shows packages with a status of iU instead of ii (the first two characters of the line), run the sudo dpkg --configure -a command to complete package configuration. Rerun package upgrade in case any packages are not downloaded or unpacked.sudo systemctl stop sysmonitor command before running package upgrade with NVUE commands. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4930152 | When you configure layer 3 SVI interfaces with an anycast gateway (VRR) IP address only and no unique IP address, the connected route for the subnet is not programmed in the ASIC, causing packets destined for locally connected hosts to drop after decapsulation. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4924486, 4924487 | A fatal SDK event might occur during i2c or cable read events, observed with the following switchd log message:hal_mlx_host_ifc.c:3531 CRIT Restarting switchd to recover from fatal SDK health event: FW health issue| 5.12.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4922104 | When the system is under load and the
wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0|
| 4918342, 4641291 | In rare circumstances, the switch stops streaming telemetry data for interface counters, buffers, or PHY. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4895501 | Adding vlan 1 as a tagged VLAN to a newly created MLAG bond fails if no previous VLANs are configured on the MLAG bond. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4895298 | When you configure BGP dynamic neighbors and default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4885553 | If ZTP uses a proxy server for image download using onie-install, the image install fails with signing issues. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4881679 | When the system is under load and the wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0, 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4835058 | When you add or remove bond members, the sflow state and rate are incorrect. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4789562 | A switch running Nvidia Cumulus Linux may improperly forward routed packets out of an access port or on the native vlan of a trunk with an 802.1Q tag imposed on the packet. | 5.12.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -60,6 +61,7 @@ pdfhidden: True
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4686865 | An invalid hashed-password string for a local NVUE user causes all nv config apply operations (including unrelated changes) to fail health checks and raise tracebacks when NVUE attempts to recreate the user. | 5.12.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4667010 | When streaming telemetry is enabled, additional logs containing ERROR BULK_COUNTER might be generated by the switch, unexpectedly bypassing log suppression rules. | 5.12.1-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -273,6 +275,7 @@ pdfhidden: True
| 5093873 | When you configure BGP dynamic neighbors and default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4686865 | An invalid hashed-password string for a local NVUE user causes all nv config apply operations (including unrelated changes) to fail health checks and raise tracebacks when NVUE attempts to recreate the user. | 5.12.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4667010 | When streaming telemetry is enabled, additional logs containing ERROR BULK_COUNTER might be generated by the switch, unexpectedly bypassing log suppression rules. | 5.12.1-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-513/rn.xml b/content/cumulus-linux-513/rn.xml
index 5cbc26e078..030c704a80 100644
--- a/content/cumulus-linux-513/rn.xml
+++ b/content/cumulus-linux-513/rn.xml
@@ -58,6 +58,12 @@ sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK t
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON objectnv action upgrade system packages command sometimes fails or might be interrupted after the packages are unpacked but not configured. As a result, you might see issues such as missing files or symlinks, or TACACS+ restricted user shells not working as expected. If the dpkg -l command shows packages with a status of iU instead of ii (the first two characters of the line), run the sudo dpkg --configure -a command to complete package configuration. Rerun package upgrade in case any packages are not downloaded or unpacked.sudo systemctl stop sysmonitor command before running package upgrade with NVUE commands. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4930152 | When you configure layer 3 SVI interfaces with an anycast gateway (VRR) IP address only and no unique IP address, the connected route for the subnet is not programmed in the ASIC, causing packets destined for locally connected hosts to drop after decapsulation. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4924486, 4924487 | A fatal SDK event might occur during i2c or cable read events, observed with the following switchd log message:hal_mlx_host_ifc.c:3531 CRIT Restarting switchd to recover from fatal SDK health event: FW health issue| 5.12.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4922104 | When the system is under load and the
wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0|
+| 4922099 | In a highly volatile network, frequent churn of SOO‑tagged routes can generate a large volume of SOO NHG sync messages to Zebra. When Zebra becomes backed up while processing these NHG updates, its memory usage can grow significantly. | 5.14.0-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0|
| 4918342, 4641291 | In rare circumstances, the switch stops streaming telemetry data for interface counters, buffers, or PHY. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4917759 | BGP sessions configured with an explicit IPv6 link local peer address might result in stale or invalid next hop tracking entries after a session disruption. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4901549 | In a highly volatile network, frequent churn of SOO‑tagged routes can generate a large volume of SOO NHG sync messages to Zebra. When Zebra becomes backed up while processing these NHG updates, its memory usage can grow significantly. | 5.14.0-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0, 5.17.0-5.18.0|
| 4895563 | Routes are present in BGP and Zebra but are missing in the kernel. This occurs when next hops in an NHG become invalid and the kernel deletes the next hops, then notifies the control plane (zebra). The control plane tries to reinstall the routes in the existing NHG with the invalid next hop information so route installation fails. Later, the routes arrive with the correct next hop information in the NHG but there is no mechanism to replace the failed routes and install them again in the kernel. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4895501 | Adding vlan 1 as a tagged VLAN to a newly created MLAG bond fails if no previous VLANs are configured on the MLAG bond. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4895298 | When you configure BGP dynamic neighbors and default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4889939 | In an MLAG configuration, when the MLAG node receives MLAG peer keepalives from an IP address that is not configured as the peer IP address, a peer IP address mismatch conflict occurs. Even after the conflict is resolved, you sometimes see that the MLAG session still retains the peer IP mismatch conflict. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4885553 | If ZTP uses a proxy server for image download using onie-install, the image install fails with signing issues. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4881679 | When the system is under load and the wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0, 5.17.0-5.18.0|
| 4879269 | Under certain conditions, switchd crashes with a segmentation fault (SIGSEGV) when cleaning up the layer 3 nexthop state or when freeing internal hash or cache structures. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4879165 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -75,6 +76,7 @@ pdfhidden: True
| 4783824 | RoCE ingress reserved pools do not display correct values for ports that are not operationally UP. Switch ports that were never operational or not operational after setting RoCE mode do not have RoCE reserved pool buffers allocated but the nv show interface qos roce status command displays an invalid buffer size. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771785 | NVUE drop counters and ethtool output do not show the packets discarded because the destination MAC address does not match the router MAC address. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4769255 | When using the CPU port as a SPAN destination, the switch might become unresponsive and, or reboot. To work around this issue, use SPAN to a local port instead of the CPU port. | 5.14.0-5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4751060, 4637733 | If the switch filesystem is overloaded or memory is exhausted, you see very slow responses from the filesystem and the SDK might fail with a fatal error similar to:sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK thread issue'], irisc=255, desc='Health check: SDK thread [sxSniffer] TID [0x7f81cffff6c0] bit [4] does not respond [5] seconds')| 5.12.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4748963 | In an MLAG configuration with PVRST spanning tree mode configured on both switches, when the primary switch comes back up after a reboot, PVRST mode briefly changes to RSTP, then back to PVRST. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4748176, 4662528, 4652420 | Unsupported hardware modules might cause SDK and firmware health event and traffic loss. | 5.12.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| @@ -91,7 +93,7 @@ pdfhidden: True | 4722449 | NVUE uses a git repository to store configurations, which over time, can grow very large, sometimes filling up all available disk space on the system. When this happens, NVUE commands become very slow or fail entirely due to lack of disk space. In severe cases, NVUE stops working completely. To work around this issue, restart the nvued service to trigger a deep cleanup of the git repository. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4722369 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0| -| 4717888 | When using the CPU port as a SPAN destination, the switch might become unresponsive and, or reboot. To work around this issue, use SPAN to a local port instead of the CPU port. | 5.14.0-5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4714618 | On switches at scale with OTEL enabled, an
interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4704406, 4633883 | TACACS authentication mode is not configured correctly in PAM common authentication and TACACS configuration files, which makes login the authentication mode regardless of the NVUE configuration. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4686865 | An invalid hashed-password string for a local NVUE user causes all nv config apply operations (including unrelated changes) to fail health checks and raise tracebacks when NVUE attempts to recreate the user. | 5.12.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-514/rn.xml b/content/cumulus-linux-514/rn.xml
index 015c1249e5..064606291c 100644
--- a/content/cumulus-linux-514/rn.xml
+++ b/content/cumulus-linux-514/rn.xml
@@ -82,6 +82,12 @@ sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK t
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON objectnv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4714618 | On switches at scale with OTEL enabled, an interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -299,21 +301,24 @@ pdfhidden: True
| Issue ID | Description | Affects | Fixed |
|--- |--- |--- |--- |
| 5152149 | Zebra might crash when recovering routes after a temporary failure to install forwarding next hops. During interface instability or link flapping, some routes might fail to install. Zebra caches those routes for later retry. If a cached route is removed before the next hop is installed successfully, zebra might later access invalid memory while retrying installation and then crash. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
-| 5093941 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093940 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093939 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093938 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093933 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 5093931 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 5093926 | Configuring ECMP Hash seed with NVUE does not program the configuration into hardware with a switchd reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 5093924 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093923 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093919 | In an MLAG configuration with PVRST spanning tree mode configured on both switches, when the primary switch comes back up after a reboot, PVRST mode briefly changes to RSTP, then back to PVRST. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 5093917 | If the switch filesystem is overloaded or memory is exhausted, you see very slow responses from the filesystem and the SDK might fail with a fatal error similar to:sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK thread issue'], irisc=255, desc='Health check: SDK thread [sxSniffer] TID [0x7f81cffff6c0] bit [4] does not respond [5] seconds')| 5.12.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| -| 5093874 | When you configure PTP on a trunk interface, where the selected PTP VLAN is the PVID (untagged native VLAN), the PTP packets might be tagged incorrectly with the VLAN ID. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| -| 5093873 | When you configure BGP dynamic neighbors and
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
+| 5093941 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093940 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093939 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093938 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093933 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093931 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093926 | Configuring ECMP Hash seed with NVUE does not program the configuration into hardware with a switchd reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093924 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093923 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093919 | In an MLAG configuration with PVRST spanning tree mode configured on both switches, when the primary switch comes back up after a reboot, PVRST mode briefly changes to RSTP, then back to PVRST. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093917 | If the switch filesystem is overloaded or memory is exhausted, you see very slow responses from the filesystem and the SDK might fail with a fatal error similar to:sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK thread issue'], irisc=255, desc='Health check: SDK thread [sxSniffer] TID [0x7f81cffff6c0] bit [4] does not respond [5] seconds')| 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 5093874 | When you configure PTP on a trunk interface, where the selected PTP VLAN is the PVID (untagged native VLAN), the PTP packets might be tagged incorrectly with the VLAN ID. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 5093873 | When you configure BGP dynamic neighbors and
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON objectnv config apply command with no changes returns a warning but the pending revision is not detached. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
@@ -322,14 +327,18 @@ pdfhidden: True
| 5057785 | With more than 10k EVPN type 2 prefixes, there is a delay in convergence. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
| 5056914 | Optimized image upgrade to 5.15.x might consume space in the /var directory up to 2.2 times the image size and might not correctly check free space in /var before proceeding. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
| 5040890 | IPv4 BGP aggregate routes are not advertised to peers. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
-| 5018899 | RADIUS Access-Request and Accounting-Request packets carry the loopback address 127.0.1.1 in the NAS-IP-Address attribute instead of the management interface address. RADIUS servers that authorize or log requests based on the NAS-IP-Address reject or fail the authentication requests. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
+| 5027908 | RADIUS Access-Request and Accounting-Request packets carry the loopback address 127.0.1.1 in the NAS-IP-Address attribute instead of the management interface address. RADIUS servers that authorize or log requests based on the NAS-IP-Address reject or fail the authentication requests. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5012295 | Configuring ECMP Hash seed with NVUE does not program the configuration into hardware with a switchd reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4992204 | Cumulus Linux does not support the NVUE nv set nve vxlan port command; you do not see the configured UDP port in the outer VXLAN packet header. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
+| 4986333 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4986329 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4980055 | With very large configurations, nv config apply command performance might be slow. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4968081 | During switch boot, a race condition between Docker container restoration and LLDP daemon startup might cause /var/run/lldpd.socket to be created as a directory instead of a socket file. When this occurs, the LLDP daemon is unable to clean up the path and fails to start permanently, requiring a reboot to recover. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4964407 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4964154 | When you run the nv config apply command or the sudo systemctl reload frr.service command on a switch configured with VRF route leaking that has many BGP peers, VRFs, and BGP learned prefixes, FRR reload might time out. To work around this issue, run sudo systemctl edit frr.service to change the TimeoutSec=2m to a higher value and apply the changes with sudo systemctl daemon-reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
+| 4964154 | When you run the nv config apply command or the sudo systemctl reload frr.service command on a switch configured with VRF route leaking that has many BGP peers, VRFs, and BGP learned prefixes, FRR reload might time out. To work around this issue, run sudo systemctl edit frr.service to change the TimeoutSec=2m to a higher value and apply the changes with sudo systemctl daemon-reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4963562 | Uneven utilization of bond member links results in one member approaching congestion while the parallel member is largely idle. There is no traffic loss; the impact is bandwidth efficiency and potential micro-congestion on the overloaded member. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
+| 4963280 | Under certain scale scenarios, the switch might end up in a state where the PTM component's connection to LLDP breaks. This issue results in LLDP socket contention issues and, in turn, a PTM memory leak. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4957394 | During snmpwalk, memory is leaked for an object that is served by pass persist. The leaked memory is allocated while the SNMP daemon processes GET or GETNEXT for the requests. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4951125 | API calls to NVUE generate a TACACS author request for a local user bypassing the authentication order. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4940786, 4705183 | Transceiver firmware upgrade fails due to PMAOS register access failures. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
@@ -338,10 +347,11 @@ pdfhidden: True
| 4930152 | When you configure layer 3 SVI interfaces with an anycast gateway (VRR) IP address only and no unique IP address, the connected route for the subnet is not programmed in the ASIC, causing packets destined for locally connected hosts to drop after decapsulation. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4926427, 4926426 | When you run the nv config apply command or the sudo systemctl reload frr.service command on a switch configured with VRF route leaking that has many BGP peers, VRFs, and BGP learned prefixes, FRR reload might time out. To work around this issue, run sudo systemctl edit frr.service to change the TimeoutSec=2m to a higher value and apply the changes with sudo systemctl daemon-reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.9.5, 5.17.0-5.18.0|
| 4924486, 4924487 | A fatal SDK event might occur during i2c or cable read events, observed with the following switchd log message:hal_mlx_host_ifc.c:3531 CRIT Restarting switchd to recover from fatal SDK health event: FW health issue| 5.12.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4922104 | When the system is under load and the
wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0|
+| 4922099 | In a highly volatile network, frequent churn of SOO‑tagged routes can generate a large volume of SOO NHG sync messages to Zebra. When Zebra becomes backed up while processing these NHG updates, its memory usage can grow significantly. | 5.14.0-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0|
| 4918342, 4641291 | In rare circumstances, the switch stops streaming telemetry data for interface counters, buffers, or PHY. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4917759 | BGP sessions configured with an explicit IPv6 link local peer address might result in stale or invalid next hop tracking entries after a session disruption. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4909312 | Cumulus Linux 5.14 removed the OTEL metric nvswitch_interface_if_in_octets because it duplicated nvswitch_interface_ether_stats_octets. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4901549 | In a highly volatile network, frequent churn of SOO‑tagged routes can generate a large volume of SOO NHG sync messages to Zebra. When Zebra becomes backed up while processing these NHG updates, its memory usage can grow significantly. | 5.14.0-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0, 5.17.0-5.18.0|
| 4895563 | Routes are present in BGP and Zebra but are missing in the kernel. This occurs when next hops in an NHG become invalid and the kernel deletes the next hops, then notifies the control plane (zebra). The control plane tries to reinstall the routes in the existing NHG with the invalid next hop information so route installation fails. Later, the routes arrive with the correct next hop information in the NHG but there is no mechanism to replace the failed routes and install them again in the kernel. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4895501 | Adding vlan 1 as a tagged VLAN to a newly created MLAG bond fails if no previous VLANs are configured on the MLAG bond. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4895298 | When you configure BGP dynamic neighbors and default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
@@ -349,7 +359,6 @@ pdfhidden: True
| 4885553 | If ZTP uses a proxy server for image download using onie-install, the image install fails with signing issues. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4884646 | When you run the vtysh -c show bgp l2v evp neigh swp1 routes json command, a memory leak occurs. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
-| 4881679 | When the system is under load and the wd_keepalive process is running at the default rate of one time per minute, the switch might reboot due to starvation of the wd_keepalive process. | 5.13.1-5.15.1, 5.16.0 | 5.16.1, 5.16.6-5.18.0, 5.17.0-5.18.0|
| 4879269 | Under certain conditions, switchd crashes with a segmentation fault (SIGSEGV) when cleaning up the layer 3 nexthop state or when freeing internal hash or cache structures. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4879165 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4875599 | When you configure authentication for a BGP dynamic neighbor, removing the configuration does not bring back the sessions. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
@@ -367,7 +376,7 @@ pdfhidden: True
| 4813804 | The nv config show command output shows each egress buffer configuration separately for each traffic class instead of in a single line configuration. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4813159 | The nv config show command output shows each egress buffer, ingress buffer, and latency configuration separately for each traffic class or port group instead of in single line configuration. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4807528 | On certain platforms, the nv show platform transceiver command shows module flags (for example, CMIS‑style fault/LOS flags) as False for legacy, non‑CMIS optics (such as older QSFP+, QSFP28, and QSFP56 modules) even when the module does not implement these flags. This issue has no functional impact. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4804084 | On switches at scale with OTEL enabled, an interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4804084 | On switches at scale with OTEL enabled, an interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4799272 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4789562 | A switch running Nvidia Cumulus Linux may improperly forward routed packets out of an access port or on the native vlan of a trunk with an 802.1Q tag imposed on the packet. | 5.12.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4789339, 4540985 | The interface_stats process might crash when a transceiver has non-ASCII data in EEPROM fields, such as vendor name or part number. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -375,7 +384,7 @@ pdfhidden: True
| 4783824 | RoCE ingress reserved pools do not display correct values for ports that are not operationally UP. Switch ports that were never operational or not operational after setting RoCE mode do not have RoCE reserved pool buffers allocated but the nv show interface qos roce status command displays an invalid buffer size. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4781499 | The 802.1X RADIUS shared secret is limited to 32 characters instead of 256 characters. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4781498 | When you use a text-based patch file with nv config patch cmd.txt or nv config replace cmd.txt, if the cmd.txt file contains any of the following CLI commands, the patch operation fails and triggers an exception in NVUE:nv set system aaa auth order radius
nv set system ssh-server ciphers
nv set system ssh-server macs
nv set system ssh-server kex-algorithms
nv set system ssh-server pubkey-accepted-algorithms
nv set system ssh-server host-key-algorithms
nv set commands manually. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4776471 | In Cumulus Linux 5.15.0, NTP and DNS configuration commands changed from nv set service to nv set system. However, after upgrading the switch to Cumulus Linux 5.15.1, the nv set service command might still appear in the configuration output because a stale nv set service command remains after the configuration is translated during the upgrade. If you save the configuration with the nv config show -o commands, then reapply the configuration with nv config replace, the command fails if the stale nv set service command is present.nv config replace, remove any stale nv set service commands from the saved configuration file, then reapply the configuration with the nv config replace command. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4776471 | In Cumulus Linux 5.15.0, NTP and DNS configuration commands changed from nv set service to nv set system. However, after upgrading the switch to Cumulus Linux 5.15.1, the nv set service command might still appear in the configuration output because a stale nv set service command remains after the configuration is translated during the upgrade. If you save the configuration with the nv config show -o commands, then reapply the configuration with nv config replace, the command fails if the stale nv set service command is present.nv config replace, remove any stale nv set service commands from the saved configuration file, then reapply the configuration with the nv config replace command. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4776470 | In Cumulus Linux 5.15.0, NTP and DNS configuration commands changed from nv set service to nv set system. However, after upgrading the switch to Cumulus Linux 5.15.1, the nv set service command might still appear in the configuration output because a stale nv set service command remains after the configuration is translated during the upgrade. If you save the configuration with the nv config show -o commands, then reapply the configuration with nv config replace, the command fails if the stale nv set service command is present.nv config replace, remove any stale nv set service commands from the saved configuration file, then reapply the configuration with the nv config replace command. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4776444, 4594612, 4823905 | In rare cases when telemetry is configured on a switch with high interface scale, the following log message might be generated and lead to a kernel crash event:interface_stats_collector[27979]: ERROR intf_stats_collector.go:485 WaitBulkCounterDone error: unable to receive trap info after 15 iterations| 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4776390 | gNMI subscription changes for interface counters, buffer, packet trim, latency or any other statistics produced by the
prometheus-sdk-stats service leads to a change in the service configuration file causing the load interval configuration to be removed. This results in a rate calculation done with an interval of 60s instead of the interval configured in NVUE. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -383,14 +392,17 @@ pdfhidden: True
| 4771785 | NVUE drop counters and ethtool output do not show the packets discarded because the destination MAC address does not match the router MAC address. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4769275 | During power cycles and GPIO events, link initialization might fail due to a race condition during switch configuration. To work around this issue, set the service port to admin UP. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4769258 | After upgrading the switch with onie-install -t, NTP configuration is missing and does not work. This issue does not occur with package or optimized image upgrade. | 5.15.0, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.15.1|
+| 4769256 | Low fan speed alarm events occur while the corresponding fan modules are amber physically. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4769255 | When using the CPU port as a SPAN destination, the switch might become unresponsive and, or reboot. To work around this issue, use SPAN to a local port instead of the CPU port. | 5.14.0-5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4752986, 4851043 | Warm reboot results in approximately 14 second traffic loss. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4751060, 4637733 | If the switch filesystem is overloaded or memory is exhausted, you see very slow responses from the filesystem and the SDK might fail with a fatal error similar to:sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK thread issue'], irisc=255, desc='Health check: SDK thread [sxSniffer] TID [0x7f81cffff6c0] bit [4] does not respond [5] seconds')| 5.12.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4748963 | In an MLAG configuration with PVRST spanning tree mode configured on both switches, when the primary switch comes back up after a reboot, PVRST mode briefly changes to RSTP, then back to PVRST. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4748176, 4662528, 4652420 | Unsupported hardware modules might cause SDK and firmware health event and traffic loss. | 5.12.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4743814 | The switch clears the QoS buffer max usage values in the
nv show interface qos buffer egress-traffic-class command output when a gNMI client subscribes to any QoS buffer metrics. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4742452, 4426737 | NVUE is unable to apply the original startup configuration or any changes that modify user accounts after the internal repository becomes invalid, leaving the applied revision in NVUE empty while the device continues to use the configuration stored directly under /etc/. This leads to a mismatch between what NVUE reports and the actual running state of the system. | 5.13.1-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4740671 | Low fan speed alarm events occur while the corresponding fan modules are amber physically. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4740606, 4783693 | When you configure a port with a 802.1x IPv6 profile, then remove 802.1x, the port might block all ingress and egress traffic, including LLDP frames. This behavior is unintended and might impact network visibility and connectivity.tc qdisc del dev| 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| +| 4738956 | When a Spectrum-4 or Spectrum-5 switch interface is connected to a ConnectX-7 NIC that performs a soft reset, adaptive routing and Spectrum-X features fail to start on the interface. To work around this issue, flap the interface. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0| | 4734606 | Physical interface based static IPv6 address assignment does not work for DHCPv6 with inbound DHCP requests (discover packets) on an SVI interface. To work around this issue, configure the IPv6 pool for the subnet to assign the IPv6 address from the pool. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| | 4734395 |clsact 2>/dev/null
tc qdisc del devingress 2>/dev/null
tc qdisc del devegress 2>/dev/null
mlxlink output sometimes displays additional special characters while still reporting valid data. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4734374 | The SNMP AgentX subsystem crashes with a segmentation fault when trying to cancel events from within event callbacks due to multiple Agentx reconnecting one after the other on the device. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -398,16 +410,14 @@ pdfhidden: True
| 4732177 | On the NVIDIA SN5610 switch, the nv show platform transceiver command output for 3rd party optics is missing fields such as rx-los and tx-los. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4731091, 4857885 | During optimized image upgrade, the switch logs an error because a new file is added. There is no functional impact. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4729839 | In an MLAG configuration, when you reboot the primary MLAG switch with PVRST spanning tree mode configured on both MLAG switches, PVRST mode briefly changes to RSTP, then back to PVRST when the primary switch comes back up. | 5.11.3-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4726412 | When a Spectrum-4 or Spectrum-5 switch interface is connected to a ConnectX-7 NIC that performs a soft reset, adaptive routing and Spectrum-X features fail to start on the interface. To work around this issue, flap the interface. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722539 | Optimized image upgrade with warm boot mode is supported in Cumulus Linux 5.13 and later. When you try to run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv action boot-next command during optimized image upgrade in Cumulus Linux 5.12 and earlier to any target release while the system is in warm boot mode, the boot-next operation fails with the following error:cumulus@switch:~$ nv action boot-next system image other
Error: Action failed with the following issue:>br>
Failed to set boot-next due to Unknown error
nv show system reboot command before you perform optimized image upgrade and switch to cold boot mode if necessary with the nv set system reboot mode cold command. You can then proceed with the optimized image upgrade boot-next operation. | 5.11.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4722449 | NVUE uses a git repository to store configurations, which over time, can grow very large, sometimes filling up all available disk space on the system. When this happens, NVUE commands become very slow or fail entirely due to lack of disk space. In severe cases, NVUE stops working completely. To work around this issue, restart the nvued service to trigger a deep cleanup of the git repository. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4722369 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4721298 | When node or VM migration occurs between the MLAG pair and the EVPN-MH pair, the MLAG MAC database becomes out of sync with kernel FDB. The migrated MAC addresses remain as local in MLAG MAC database whereas in the kernel, all MAC addresses are updated correctly as remote with the layer 2 next hop ID. To work around this issue, flap the MLAG bond interface to clear the MLAG local database. | 5.11.0-5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4717888 | When using the CPU port as a SPAN destination, the switch might become unresponsive and, or reboot. To work around this issue, use SPAN to a local port instead of the CPU port. | 5.14.0-5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4717494 | When you run the nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0| -| 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4716836 | After upgrading the switch with onie-install -t, NTP configuration is missing and does not work. This issue does not occur with package or optimized image upgrade. | 5.15.0 | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4717494 | When you run the nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4714618 | On switches at scale with OTEL enabled, an interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4709579 | Using package upgrade in Cumulus Linux 5.15 and earlier might show syslog errors similar to BTF: failed to validate kernel module -22. These syslog errors are largely inconsequential and occur when loading new modules on an older kernel. Kernel modules still function correctly but BTF debug information might be unavailable until the switch reboots after upgrade. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4707967 | When you use NVUE to configure a user with a username that is used as a group name in the system, you see the following error message:User name {} is already in use as OS group name 'and could not be used as username. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -430,6 +440,8 @@ pdfhidden: True
| 4650961 | When you bring a bond down, then up with the ifdown and ifup commands, the sflow rate is not configured correctly after the bond comes up and the sflow sample is not generated. To work around this issue, bring the member port down, then up. | 5.15.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4648833, 4662556, 4687350 | Interfaces using PAM4 DAC cables on switches with Spectrum-4 and later might not come up after a link flap or reboot if auto-negotiation is disabled. Auto-negotiation is required for PAM4 DAC cables on these switches. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4643073, 4643425 | Concurrent mlxfwmanager --query executions triggered by gNMI telemetry polling might cause MFT deadlock, resulting in repeated core dumps, nvued restarts, and control plane unresponsiveness. | 5.14.0-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4641344 | The switch sends out IPv6 neighbor discovery (ND) router advertisement through an interface that does not have router advertisement enabled. To prevent this issue, do not change or remove the remote-as of a peer-group that is used by BGP unnumbered peers. To work around this issue, restart FRR. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4641343 | The switch sends out IPv6 neighbor discovery (ND) router advertisement through an interface that does not have router advertisement enabled. To prevent this issue, do not change or remove the remote-as of a peer-group that is used by BGP unnumbered peers. To work around this issue, restart FRR. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4608614 | When setting up SSH keys, you have to run nv config apply twice for the configuration to take effect. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4582679 | If a node has Suppress Route Advertisement enabled and routes are re-learned; for example, when a peer sends the route again due to route policy changes, or you enable or disable graceful shutdown, not all routes are offloaded, which might cause discrepancies in traffic. | 5.9.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4579237, 4579234 | If interface statistics telemetry is running on the switch, an interface_stats_collector core file might generate during statistics collection. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -438,24 +450,33 @@ pdfhidden: True
| 4549896 | When you try to set a VXLAN with a bridge, you see the error sx_sdk: 22985 [BRIDGE] [ERROR ]: Port(0x200A000D)) already added to a bridge. You can safely ignore this error. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4548512 | When a connected route for an SVI interface with VRR configured is installed by FRR, the route might be installed with the next hop interface of the VRR device instead of the SVI. For example, instead of interface vlan10, the route might install against vlan10-v0. This prevents next-hop tracking and route installation into hardware.clagd restart, switchd restart, and so on.sudo systemctl restart frr.service command. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4547463, 4705370 | When you run nv action boot-next commands during optimized image upgrade, the commands time out. This does not indicate that an issue occurred; the system might still be executing the action.nv action boot-next command by doing a grep for ActionKey.*boot-next in the /var/log/nvued.log file. For example, the value 3 in the Ran Job running ActionKey('@boot-next', '/system/image', (), 3, (('partition', 'partition1'),)) line indicates the Request ID.curl -u ':\' -X GET https://127.0.0.1:8765/nvue_v1/action/ -k command from the shell to show the status of the action command. If the value of state is action_success, the action command completed successfully. If the value of state is running, the system is still processing. If the value of state is action_error, the system encountered an error./var/tmp directory, which the switch uses for temporary files. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4535804 | If you use a bridge name other than br_default, PTP neighbors fail to establish because the PTP packets are sourced from an unexpected IP address.base-interface for the VLAN interface with the nv set interface base-interface command. | 5.10.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4535749 | The uc-discards field in the nv show interface counters qos egress-queue-stats command output is actually the number of packets discarded per queue, but it is wrongly interpreted as bytes. To work around this issue, convert the data shown in bytes to packets by multiplying by 1024 if the data is in KB, 1024x1024 if the data is in MB, and 1024x1024x1024 if the data is in GB. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4535699 | When you configure the RADIUS authentication order with local first and radius second, the RADIUS user is authenticated as a default user name. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4534357 | During Cumulus Linux upgrade or downgrade, rsyslog might crash because the management (eth0) port is unavailable, which triggers a use-after-free fault and produces a cl-support file as a response. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4531960 | The GNMI Subscription to xpath interfaces/interface[name=swp61s0]/state/counters/out-pkts with a high sample interval results in an initial response of zero but in subsequent updates, the value is correct. You do not see this issue when the sample interval is 1 second. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4513849 | After upgrading from Cumulus Linux 5.12 on the NVIDIA SN5400 switch bonus port, PTP does not converge. To work around this issue, disable, then enable the bonus port after upgrade. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4509255, 4546858 | In PTP two-step, the hardware incorrectly modifies the SYNC message correction field. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4508830 | Cumulus Linux allows you to add bond ports of mismatched speeds (such as 10G and 25G) to the same LACP bond without error and the bond reports UP. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4501632, 4530257 | NVIDIA recommends you wait for approximately 60 seconds after running nv config apply before power cycling the switch so that the NVUE database has time to sync to the filesystem. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4495383, 4493988 | NVUE configuration yaml file translation converts unset commands to set commands because the translation logic expects only set commands. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4495231 | If the hardware clock date is later than 2038-01-19 03:14:07 UTC, the image might fail to install due to a grub-install failure on the EFI filesystem, which is a VFAT filesystem. As a result, you see the grub prompt immediately after reboot. To work around this issue, reboot from the grub prompt to go into ONIE. From ONIE, use the date command to set a date before 2038-01-19, then run the hwclock --systohc command to add it to the hardware clock. You can then use onie-nos-install to install the image. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4475401 | External input such as Ctrl+\ might trigger core dumps on the serial console from /bin/login. This behavior is caused by external sources, such as console servers or automation tools, and does not reflect a fault in the operating system. As a potential result, the serial console might become unresponsive. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 4475111 | When you try to convert a layer 3 port that is part of ECMP to a bond member, you might see a failure in the switchd logs. This issue does not have any functional impact. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.4|
+| 4475111 | When you try to convert a layer 3 port that is part of ECMP to a bond member, you might see a failure in the switchd logs. This issue does not have any functional impact. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4475074 | The SN5610 switch records a High FEC Bin Error at room temperature. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.11.2|
| 4440766 | When you try to delete a trusted ca key, Cumulus Linux shows an incorrect error message. To remove a trusted ca key, you must unset the key ID, not the key literal. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423368 | When all links go down or the switch reboots, you see next hop group churn from Zebra to the SOO next hop group. This issue might cause some convergence degradation. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423360 | After a remote link flap, neighbor entries using the link might not get resolved immediately. Only when some traffic uses the nexthop will they be resolved. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423352 | ZTP scripts return an error due to incorrect ASCI to UTF-8 conversion. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423335 | When you configure TACACS with NVUE or merge an NVUE configuration file that includes TACACS configuration with the nv config patch command, you see an unrecoverable error when running additional NVUE commands. To work around this issue, restart the NVUE service with systemctl restart nvued.service. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423248 | If you unset an interface static IP address when the interface IP gateway is configured, the nv config apply command fails with an ifreload.service error. To work around this issue, unset both the static IP address and gateway together. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423244 | When you enable, then disable adaptive routing, the BGP neighbors might go down because of an unresolved MAC address. To work around this issue, configure another attribute on the interface. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423235 | The snmpd service generates debugging logs of sudo calls. To work around this issue, disable sudo logging for the specific commands run by the Debian-snmp user in the /etc/sudoers.d/snmp file by adding Defaults:Debian-snmp !syslog. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423175 | When you configure an API port with a TCP port already in use, the nginx server fails to restart. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4413589 | A MAC-only EVPN type-2 route is wrongly advertised with the layer 3 VNI label in the BGP NLRI (Network Layer Reachability Information). Although this does not have any functional impact, it is not the desired RFC behavior. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4370954 | After enabling, then disabling truncation on a SPAN session, truncated packets are still received on the SPAN destination. To work around this issue, remove the SPAN session configuration, reboot the switch, then reconfigure the SPAN session without truncation. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4337278 | Statically configured VXLAN entries sometimes age out after a peer link flap. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4329931 | Cumulus Linux incorrectly allows SyncE and PPS to be enabled at the same time. Upgrading systems with both features configured using NVUE to 5.12.0 or later results in a failure to apply the startup configuration as part of the first boot of the upgraded version. To work around the issue, unset one of the features before you upgrade. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4309876 | When you configure an invalid switch port (swp), NVUE adds the invalid configuration instead of rejecting it. The invalid interface in the configuration does not have any functional impact. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
diff --git a/content/cumulus-linux-515/rn.xml b/content/cumulus-linux-515/rn.xml
index 5236c41edd..621d71a41c 100644
--- a/content/cumulus-linux-515/rn.xml
+++ b/content/cumulus-linux-515/rn.xml
@@ -106,6 +106,12 @@ sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK t
config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076894 | The gNMI /interfaces/interface[name]/ethernet/state/port-speed path might show the wrong speed. | 5.16.6-5.17.0 | 5.18.0|
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -175,6 +176,7 @@ pdfhidden: True
| 4731091, 4857885 | During optimized image upgrade, the switch logs an error because a new file is added. There is no functional impact. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722589, 4866475 | In a large scale configuration, a full MIB walk times out. | 5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717494 | When you run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4667792 | Usernames longer than 32 characters do not authenticate against the switch. Avoid using long usernames. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -308,7 +310,7 @@ pdfhidden: True
| Issue ID | Description | Affects |
|--- |--- |--- |
| 5161741 | The gNMI /network-instances/network-instance[name]/protocols/protocol[identifier][name]/bgp/neighbors/neighbor[neighbor-address]/state/session-state metric intermittently returns no data. | | |
-| 5161727 | All the Docker dependent services such as UMF and gNMI have periodic checks around the Docker service. If the Docker service restarts for any reason, it triggers a restart of all the docker dependent services. If the Docker service is down for a long time, it exceeds the maximum number of restarts within the systemd rate-limit interval for the Docker dependent services. As a result, all the Docker dependent services (including gNMI) end up in a failed state. | 5.16.1 | |
+| 5161727 | Repeated networking or Docker lifecycle events can rapidly restart Docker-backed services such as UMF and gNMI. | | |
| 5159907 | When a gNMI client uses a long sample interval, the gNMI server takes a long time to respond even after the gNMI client is reachable. The back-off time interval is now limited to one minute. | | |
| 5159856 | On the Spectrum-4 and Spectrum-5 switch, you might encounter capacitor failures caused by high temperatures; as a result, ports remain down. Thermal algorithm updates are provided to increase cooling fans speed. | 5.16.1 | |
| 5159352 | The nv show platform firmware command shows an incorrect CPLD firmware version. | 5.16.1 | |
@@ -333,7 +335,6 @@ pdfhidden: True
| Issue ID | Description | Affects | Fixed |
|--- |--- |--- |--- |
| 5175518 | The switchd watchdog crashes due to a netlink buffer overflow triggered by continuous next hop group churn. | 5.16.1, 5.16.6-5.18.0 | |
-| 5161727 | All the Docker dependent services such as UMF and gNMI have periodic checks around the Docker service. If the Docker service restarts for any reason, it triggers a restart of all the docker dependent services. If the Docker service is down for a long time, it exceeds the maximum number of restarts within the systemd rate-limit interval for the Docker dependent services. As a result, all the Docker dependent services (including gNMI) end up in a failed state. | 5.16.1 | 5.16.6-5.18.0|
| 5159856 | On the Spectrum-4 and Spectrum-5 switch, you might encounter capacitor failures caused by high temperatures; as a result, ports remain down. Thermal algorithm updates are provided to increase cooling fans speed. | 5.16.1 | 5.16.6-5.18.0|
| 5159352 | The nv show platform firmware command shows an incorrect CPLD firmware version. | 5.16.1 | 5.16.6-5.18.0|
| 5157264 | When you enable VRF leaking by manually attaching export RTs to the layer 2 VNI, the remote side ends up importing an EVPN type-2 route with an IPv6 link local address in the tenant VRF. These routes do not have a valid router MAC address, which is essential for layer 3 traffic forwarding in the tenant VRF and layer 3 VNI. | 5.16.0-5.16.1 | 5.16.6-5.18.0|
@@ -366,6 +367,7 @@ pdfhidden: True
| 5093864 | Known registered multicast traffic is duplicated to receivers behind an EVPN-MH dual-homed access switch. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722589, 4866475 | In a large scale configuration, a full MIB walk times out. | 5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717494 | When you run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4667792 | Usernames longer than 32 characters do not authenticate against the switch. Avoid using long usernames. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -672,6 +675,7 @@ pdfhidden: True
| 5093864 | Known registered multicast traffic is duplicated to receivers behind an EVPN-MH dual-homed access switch. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5072600 | The nv show mlag -o json command returns a plain text error instead of a JSON object/var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4722589, 4866475 | In a large scale configuration, a full MIB walk times out. | 5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0| +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717494 | When you run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4667792 | Usernames longer than 32 characters do not authenticate against the switch. Avoid using long usernames. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
diff --git a/content/cumulus-linux-516/rn.xml b/content/cumulus-linux-516/rn.xml
index 1cb286979b..0b8e97e40d 100644
--- a/content/cumulus-linux-516/rn.xml
+++ b/content/cumulus-linux-516/rn.xml
@@ -166,6 +166,12 @@ sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK t
l1-show command output does not show eyes and grades for bonus or service port swp65s0 and swp65s1. | 5.17.0 | 5.18.0|
+| 5140100 | When you configure a Spectrum-6 switch in half-resource mode, a MAC address configured with NVUE for an interface on a switch port might not get programmed in hardware as intended for the layer 3 port. In Spectrum-X deployments, this issue might affect HWPLB functionality. | 5.17.0-5.18.0 | |
| 5135125 | On switches with the Spectrum-4 ASIC, a port configured with a breakout might encounter a firmware (SDK or FW) fatal event when traffic first begins forwarding on the broken-out port. The switch resets the ASIC automatically and restarts switchd to recover. | 5.16.1, 5.16.6-5.17.0 | 5.18.0|
| 5130675 | The MFT tool crashes. | 5.17.0 | 5.18.0|
| 5124026 | The HFT counter metrics exported over OTLP use incorrect timestamp and metric-type semantics. | 5.17.0 | 5.18.0|
@@ -48,6 +49,7 @@ pdfhidden: True
| 5093864 | Known registered multicast traffic is duplicated to receivers behind an EVPN-MH dual-homed access switch. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 5078019 | The cl-support file takes approximately three minutes to generate with IPv6 routes and and an srv6 full scale configuration. | 5.17.0 | 5.18.0|
| 5076894 | The gNMI /interfaces/interface[name]/ethernet/state/port-speed path might show the wrong speed. | 5.16.6-5.17.0 | 5.18.0|
| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -118,6 +120,7 @@ pdfhidden: True
| 4774686, 4764590 | The final hop does not respond to traceroute with the layer 4 protocol set to TCP or UDP. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4771988, 4958439 | After you enable BFD offload, BFD control packet counters stop incrementing. Control plane BFD sessions are not affected by this issue and there is no BFD functionality impact in case of kernel offload. | 5.16.0-5.16.1, 5.16.6-5.17.0 | 5.18.0|
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717494 | When you run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4667792 | Usernames longer than 32 characters do not authenticate against the switch. Avoid using long usernames. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
diff --git a/content/cumulus-linux-517/rn.xml b/content/cumulus-linux-517/rn.xml
index dd4e09a21f..0ccb06a9f6 100644
--- a/content/cumulus-linux-517/rn.xml
+++ b/content/cumulus-linux-517/rn.xml
@@ -49,6 +49,12 @@
nv-gnmi.service fails and the switch collects a tech support bundle after the first step of the process (nv action upgrade system packages to latest. The package upgrade process triggers a switch reboot straight afterwards as a second and final step. There is no functional impact after switch reboot completes. | 5.18.0 | |
| 5175518 | The switchd watchdog crashes due to a netlink buffer overflow triggered by continuous next hop group churn. | 5.16.1, 5.16.6-5.18.0 | |
| 5174873 | On an EVPN MH topology with route leaking, if we enable Layer 3 VXLAN Device Mode from existing Single VXLAN Device for All Layer 3 VNIs model, FDB/mac entry is not installed in hardware for some remote VTEP router macs. This affects L3 VxLAN traffic through the VTEPs whose RMACs are not installed on the DUT. | 5.18.0 | |
| 5174595 | On an EVPN MH topology with route leaking, if we enable Layer 3 VXLAN Device Mode from existing Single VXLAN Device for All Layer 3 VNIs model, cl-route-check errors are observed. Neighbor entry is not resolved for the next hop and hence traffic on the routes shown in cl-route-check errors will be impacted. | 5.18.0 | |
@@ -21,7 +23,30 @@ pdfhidden: True
| 5159852, 4667526 | When you configure multiple parallel IPv6 numbered eBGP sessions between the same pair of switches, some sessions can remain in an Idle state during simultaneous link or session bringup. Affected sessions repeatedly report Cease/Connection Collision Resolution. To work around this issue, configure update-source separately for every numbered IPv6 BGP neighbor on both switches, using the local IPv6 address assigned to that neighbor’s link.nv show evpn l3vxi --output json command returns an empty dictionary ({}). To work around this issue, run the nv show evpn l3vxi --rev=applied --output json command instead. | 5.18.0 | |
| 5146099 | When operating at 100 percent line rate traffic runs from IXIA, the system experiences packet loss or latency in different traffic RFC tests. To work around this issue, configure the line rate at 99.9 percent and use ports from different IXIA Resource Groups. | 5.18.0 | |
+| 5140100 | When you configure a Spectrum-6 switch in half-resource mode, a MAC address configured with NVUE for an interface on a switch port might not get programmed in hardware as intended for the layer 3 port. In Spectrum-X deployments, this issue might affect HWPLB functionality. | 5.17.0-5.18.0 | |
| 5107338 | onie-install, onie-select, and cl-image-upgrade now allow only one instance of each to run at the same time, except for read (status check), which you can use at any time. | 5.18.0 | |
+| 5093941 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093940 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093939 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093938 | When nvued.log triggers log rotation, it also forces rotation of all three logs (nvued, nv-cli, and nv-api). As a result, the nv-cli logs are rotated unnecessarily, which might eventually lead to missing nv-cli.log entries due to excessive rotations. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093933 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093931 | When you configure dynamic NAT and traffic enters the switch on a bridge port that is routed through a VLAN SVI (the standard MLAG bridge topology), NAT flows are not offloaded to the ASIC. An upstream kernel change clears an internal flag during the bridge-to-host handoff that the NAT offload path depends on to signal the hardware. As a result, all dynamic NAT flows fall back to software forwarding on the CPU, reducing throughput by over 99%. Static NAT and deployments using direct layer 3 ports (no bridge) are not affected. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093926 | Configuring ECMP Hash seed with NVUE does not program the configuration into hardware with a switchd reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093924 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093923 | Certain platforms with a SATA disk for NCQ might cause IO errors sending the SSD into read-only mode. You might see ports going down until the switch reboots. There is no observable performance impact due to this issue. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093919 | In an MLAG configuration with PVRST spanning tree mode configured on both switches, when the primary switch comes back up after a reboot, PVRST mode briefly changes to RSTP, then back to PVRST. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093917 | If the switch filesystem is overloaded or memory is exhausted, you see very slow responses from the filesystem and the SDK might fail with a fatal error similar to:sxd_kernel: Health-Check: new failure (dev=1, severity='Fatal', cause=10 ['SDK thread issue'], irisc=255, desc='Health check: SDK thread [sxSniffer] TID [0x7f81cffff6c0] bit [4] does not respond [5] seconds')| 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 5093874 | When you configure PTP on a trunk interface, where the selected PTP VLAN is the PVID (untagged native VLAN), the PTP packets might be tagged incorrectly with the VLAN ID. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 5093873 | When you configure BGP dynamic neighbors and
default-originate with a route map, the default route stops being advertised to those neighbors after an FRR restart, reboot, or after the BGP session re-establishes (after a link flap or a hard clear on the peer). To work around this issue and to ensure that the default route advertises correctly, remove, then readd the default-originate with the route map command or toggle default-route-origination off, then on. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093865 | Known registered multicast traffic is duplicated to receivers behind an EVPN-MH dual-homed access switch. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093864 | Known registered multicast traffic is duplicated to receivers behind an EVPN-MH dual-homed access switch. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093853 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5081381 | When you run the config apply command with no configuration changes, the command leaves a stale pending revision. | 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5076748 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5076747 | PXE boot intermittently fails when the host is dual attached to two switches on a bond with LACP bypass enabled and the bridge in PVST mode. This issue occurs in MLAG and non-MLAG scenarios. To work around this issue, either unplug, then replug the ethernet cable or set the STP protocol to RSTP. | 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 5057192 | With svi-force-up enabled, the SVI link state is unexpectedly NO-CARRIER and LOWERLAYERDOWN when all VLAN member ports are down. This results in loss of reachability to IP addresses configured on SVIs. To work around this issue, add and apply vlan-bridge-binding off to each SVI with a snippet; for example:| 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 5057191 | With- set:
system:
config:
snippet:
ifupdown2_eni:
vlanXXX: \|
vlan-bridge-binding off
svi-force-up enabled, the SVI link state is unexpectedly NO-CARRIER and LOWERLAYERDOWN when all VLAN member ports are down. This results in loss of reachability to IP addresses configured on SVIs. To work around this issue, add and apply vlan-bridge-binding off to each SVI with a snippet; for example:| 5.16.0-5.16.1, 5.16.6-5.18.0 | | | 5008545, 5108365 | After upgrading Cumulus Linux, NVUE becomes unresponsive and the collector stops receiving gNMI telemetry data. | 5.16.1, 5.16.6-5.18.0 | | | 5003807 | Sometimes, gNMI does not export SRv6 and Packet Trimming AI ethernet statistics metrics. | 5.16.1, 5.16.6-5.18.0 | | | 5002002 | When using an IPv6 VXLAN tunnel IP address, FRR treats the received type-3 EVPN route as a withdraw. | 5.16.1, 5.16.6-5.18.0 | | @@ -30,17 +55,31 @@ pdfhidden: True | 4992289 | After optimized image upgrade, the SSH service fails and NVUE shows an error- set:
system:
config:
snippet:
ifupdown2_eni:
vlanXXX: \|
vlan-bridge-binding off
Failed to translate the startup configuration, will continue with the original startup. | 5.16.1, 5.16.6-5.18.0 | |
| 4989426 | The nv show interface qos-roce-status command causes HIGH CPU. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4988339 | You might see the following Sxd-kernel errors about late completion and new maximum time between iterations detected.kernel: [875348.575113] sxd_kernel: dev_id=1: Receive late completion for dqn (0) idx (65)| 5.16.1, 5.16.6-5.18.0 | | +| 4986343 | PTM does not refresh certain entries and the PTM's neighbor status command (ptmctl -d) continues to show a neighbor that is already gone. This condition clears when the expected neighbor gets discovered. | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4986333 | LLDP session flaps might result in a PTMD process crash due to a double free memory block. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4986329 | When many BFD sessions are configured at scale,
kernel: [899873.236610] sxd_kernel: dev_id=1: Health-Check: New maximum time between iterations detected: 7224 msecs (jiffies_now=4519869758, last_work_launch_jiffies=4519867952, HZ=250)
ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4982910 | The mellanox platform driver fails to register a pm_power_off handler for legacy platforms. As a result, it falls through to ACPI power off which doesn't work correctly on the BIOS and causes a reset. | 5.17.0-5.18.0 | |
+| 4964154 | When you run the nv config apply command or the sudo systemctl reload frr.service command on a switch configured with VRF route leaking that has many BGP peers, VRFs, and BGP learned prefixes, FRR reload might time out. To work around this issue, run sudo systemctl edit frr.service to change the TimeoutSec=2m to a higher value and apply the changes with sudo systemctl daemon-reload. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4963280 | Under certain scale scenarios, the switch might end up in a state where the PTM component's connection to LLDP breaks. This issue results in LLDP socket contention issues and, in turn, a PTM memory leak. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4963271 | PTM does not refresh certain entries and the PTM's neighbor status command (ptmctl -d) continues to show a neighbor that is already gone. This condition clears when the expected neighbor gets discovered. | 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4891440 | The nv show interface qos-roce-status command causes HIGH CPU. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4875306 | You might see traffic drops on SLAAC and 802.1x interfaces. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4841491 | When the Management-Privilege-Level or Cisco-Avpair is not found, a user is created with privilege level 0 instead of privilege level 1. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4804084 | On switches at scale with OTEL enabled, an interface_stats_collector crash might occur with the following logs:interface_stats_collector[3429270]: ERROR
buffer_stats_collector.go:1875 SDK bulk counter read failed
interface_stats_collector[3429270]: fatal error: concurrent map iteration and map write
interface_stats_collector[3429270]: goroutine 5610 gp=0xc007814c40 m=16 mp=0xc000552808 [running]: | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4776471 | In Cumulus Linux 5.15.0, NTP and DNS configuration commands changed from nv set service to nv set system. However, after upgrading the switch to Cumulus Linux 5.15.1, the nv set service command might still appear in the configuration output because a stale nv set service command remains after the configuration is translated during the upgrade. If you save the configuration with the nv config show -o commands, then reapply the configuration with nv config replace, the command fails if the stale nv set service command is present.nv config replace, remove any stale nv set service commands from the saved configuration file, then reapply the configuration with the nv config replace command. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4774686, 4764590 | The final hop does not respond to traceroute with the layer 4 protocol set to TCP or UDP. | 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4722680 | If you install RADIUS client packages when rolling back a two partition upgrade, the /var/lib/nvue, /var/lib/ntpsec, and /var/lib/snmp directories might have incorrect ownership after rollback and the nvued service might fail to start up. To work around this issue, run the following commands:sudo chown -R nvue /var/lib/nvue| 5.11.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4717494 | When you run the
sudo chown -R ntpsec /var/lib/ntpsec
sudo chown -R Debian-snmp /var/lib/snmp
sudo reboot
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. To work around this issue, run the following commands to retrieve IPv6 routing information:nv show vrf default router rib ipv6| 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | | +| 4717493 | When you run the
nv show vrf default router rib ipv6 route
nv show vrf default router rib command, NVUE returns an ItemDoesNotExist error. This error occurs because the vtysh show ip route vrf default brief json command does not return any output, which propagates through NVUE. To work around this issue, run the nv show vrf default router rib ipv6 and nv show vrf default router rib ipv6 route commands instead. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4667792 | Usernames longer than 32 characters do not authenticate against the switch. Avoid using long usernames. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4662854 | If you configure a DSCP match as ANY, the gNMI subscription does not show DSCP as ANY. The OpenConfig model supports only integer DSCP values. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4657192, 4414675 | On the NVIDIA SN5640 switch, after you configure a port as unsplit, links do not come up while optics are in use. To work around this issue, use copper cables. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4648833, 4662556, 4687350 | Interfaces using PAM4 DAC cables on switches with Spectrum-4 and later might not come up after a link flap or reboot if auto-negotiation is disabled. Auto-negotiation is required for PAM4 DAC cables on these switches. | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4641344 | The switch sends out IPv6 neighbor discovery (ND) router advertisement through an interface that does not have router advertisement enabled. To prevent this issue, do not change or remove the remote-as of a peer-group that is used by BGP unnumbered peers. To work around this issue, restart FRR. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4641343 | The switch sends out IPv6 neighbor discovery (ND) router advertisement through an interface that does not have router advertisement enabled. To prevent this issue, do not change or remove the remote-as of a peer-group that is used by BGP unnumbered peers. To work around this issue, restart FRR. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4608614 | When setting up SSH keys, you have to run nv config apply twice for the configuration to take effect. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4582679 | If a node has Suppress Route Advertisement enabled and routes are re-learned; for example, when a peer sends the route again due to route policy changes, or you enable or disable graceful shutdown, not all routes are offloaded, which might cause discrepancies in traffic. | 5.9.4-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4579237, 4579234 | If interface statistics telemetry is running on the switch, an interface_stats_collector core file might generate during statistics collection. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -48,24 +87,33 @@ pdfhidden: True
| 4549896 | When you try to set a VXLAN with a bridge, you see the error sx_sdk: 22985 [BRIDGE] [ERROR ]: Port(0x200A000D)) already added to a bridge. You can safely ignore this error. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4548512 | When a connected route for an SVI interface with VRR configured is installed by FRR, the route might be installed with the next hop interface of the VRR device instead of the SVI. For example, instead of interface vlan10, the route might install against vlan10-v0. This prevents next-hop tracking and route installation into hardware.clagd restart, switchd restart, and so on.sudo systemctl restart frr.service command. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4547463, 4705370 | When you run nv action boot-next commands during optimized image upgrade, the commands time out. This does not indicate that an issue occurred; the system might still be executing the action.nv action boot-next command by doing a grep for ActionKey.*boot-next in the /var/log/nvued.log file. For example, the value 3 in the Ran Job running ActionKey('@boot-next', '/system/image', (), 3, (('partition', 'partition1'),)) line indicates the Request ID.curl -u ':\' -X GET https://127.0.0.1:8765/nvue_v1/action/ -k command from the shell to show the status of the action command. If the value of state is action_success, the action command completed successfully. If the value of state is running, the system is still processing. If the value of state is action_error, the system encountered an error./var/tmp directory, which the switch uses for temporary files. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4535804 | If you use a bridge name other than br_default, PTP neighbors fail to establish because the PTP packets are sourced from an unexpected IP address.base-interface for the VLAN interface with the nv set interface base-interface command. | 5.10.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4535749 | The uc-discards field in the nv show interface counters qos egress-queue-stats command output is actually the number of packets discarded per queue, but it is wrongly interpreted as bytes. To work around this issue, convert the data shown in bytes to packets by multiplying by 1024 if the data is in KB, 1024x1024 if the data is in MB, and 1024x1024x1024 if the data is in GB. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4535699 | When you configure the RADIUS authentication order with local first and radius second, the RADIUS user is authenticated as a default user name. | 5.11.3-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4534357 | During Cumulus Linux upgrade or downgrade, rsyslog might crash because the management (eth0) port is unavailable, which triggers a use-after-free fault and produces a cl-support file as a response. | 5.13.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4531960 | The GNMI Subscription to xpath interfaces/interface[name=swp61s0]/state/counters/out-pkts with a high sample interval results in an initial response of zero but in subsequent updates, the value is correct. You do not see this issue when the sample interval is 1 second. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4513849 | After upgrading from Cumulus Linux 5.12 on the NVIDIA SN5400 switch bonus port, PTP does not converge. To work around this issue, disable, then enable the bonus port after upgrade. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4509255, 4546858 | In PTP two-step, the hardware incorrectly modifies the SYNC message correction field. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4508830 | Cumulus Linux allows you to add bond ports of mismatched speeds (such as 10G and 25G) to the same LACP bond without error and the bond reports UP. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4501632, 4530257 | NVIDIA recommends you wait for approximately 60 seconds after running nv config apply before power cycling the switch so that the NVUE database has time to sync to the filesystem. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4495383, 4493988 | NVUE configuration yaml file translation converts unset commands to set commands because the translation logic expects only set commands. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4495231 | If the hardware clock date is later than 2038-01-19 03:14:07 UTC, the image might fail to install due to a grub-install failure on the EFI filesystem, which is a VFAT filesystem. As a result, you see the grub prompt immediately after reboot. To work around this issue, reboot from the grub prompt to go into ONIE. From ONIE, use the date command to set a date before 2038-01-19, then run the hwclock --systohc command to add it to the hardware clock. You can then use onie-nos-install to install the image. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4475401 | External input such as Ctrl+\ might trigger core dumps on the serial console from /bin/login. This behavior is caused by external sources, such as console servers or automation tools, and does not reflect a fault in the operating system. As a potential result, the serial console might become unresponsive. | 5.14.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 4475111 | When you try to convert a layer 3 port that is part of ECMP to a bond member, you might see a failure in the switchd logs. This issue does not have any functional impact. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.4|
+| 4475111 | When you try to convert a layer 3 port that is part of ECMP to a bond member, you might see a failure in the switchd logs. This issue does not have any functional impact. | 5.11.2-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4475074 | The SN5610 switch records a High FEC Bin Error at room temperature. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.11.2|
| 4440766 | When you try to delete a trusted ca key, Cumulus Linux shows an incorrect error message. To remove a trusted ca key, you must unset the key ID, not the key literal. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423368 | When all links go down or the switch reboots, you see next hop group churn from Zebra to the SOO next hop group. This issue might cause some convergence degradation. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423360 | After a remote link flap, neighbor entries using the link might not get resolved immediately. Only when some traffic uses the nexthop will they be resolved. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423352 | ZTP scripts return an error due to incorrect ASCI to UTF-8 conversion. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423335 | When you configure TACACS with NVUE or merge an NVUE configuration file that includes TACACS configuration with the nv config patch command, you see an unrecoverable error when running additional NVUE commands. To work around this issue, restart the NVUE service with systemctl restart nvued.service. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423248 | If you unset an interface static IP address when the interface IP gateway is configured, the nv config apply command fails with an ifreload.service error. To work around this issue, unset both the static IP address and gateway together. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423244 | When you enable, then disable adaptive routing, the BGP neighbors might go down because of an unresolved MAC address. To work around this issue, configure another attribute on the interface. | 5.9.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4423235 | The snmpd service generates debugging logs of sudo calls. To work around this issue, disable sudo logging for the specific commands run by the Debian-snmp user in the /etc/sudoers.d/snmp file by adding Defaults:Debian-snmp !syslog. | 5.11.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4423175 | When you configure an API port with a TCP port already in use, the nginx server fails to restart. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4413589 | A MAC-only EVPN type-2 route is wrongly advertised with the layer 3 VNI label in the BGP NLRI (Network Layer Reachability Information). Although this does not have any functional impact, it is not the desired RFC behavior. | 5.13.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4370954 | After enabling, then disabling truncation on a SPAN session, truncated packets are still received on the SPAN destination. To work around this issue, remove the SPAN session configuration, reboot the switch, then reconfigure the SPAN session without truncation. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4337278 | Statically configured VXLAN entries sometimes age out after a peer link flap. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4329931 | Cumulus Linux incorrectly allows SyncE and PPS to be enabled at the same time. Upgrading systems with both features configured using NVUE to 5.12.0 or later results in a failure to apply the startup configuration as part of the first boot of the upgraded version. To work around the issue, unset one of the features before you upgrade. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4309876 | When you configure an invalid switch port (swp), NVUE adds the invalid configuration instead of rejecting it. The invalid interface in the configuration does not have any functional impact. | 5.12.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
@@ -182,6 +230,7 @@ pdfhidden: True
| 5099633 | There are long delays with NTP time synchronization when the system time changes (rolls back). | 5.16.1, 5.16.6-5.17.0 | |
| 5099224 | When interfaces experience authentication failures and retries due to Radius or host misconfiguration, NVUE commands such as nv show interface dot1x-summary and nv show interface dot1x-ipv6-summary become slow and unresponsive. To work around this issue, ensure the RADIUS server is reachable and configured correctly, and that client credentials and certificates are valid. The slowdown is triggered by repeated authentication failures causing deauthentication and re-authentication cycles. Resolving the underlying authentication failures eliminates the blocking behavior. | 5.16.6-5.17.0 | |
| 5095504 | Statically configuring an IPv4 or IPv6 address for an 802.1x enabled port that is also configured for dynamic IPv6 is allowed. However, when you upgrade the switch with this configuration, upgrade fails. To work around this issue, remove the statically assigned IPv4 or IPv6 address configured on the 802.1x enabled port configured for Dynamic IPv6 and re-attempt the upgrade. | 5.17.0 | |
+| 5095340 | Repeated networking or Docker lifecycle events can rapidly restart Docker-backed services such as UMF and gNMI. | | |
| 5093840 | Some of the BGP EVPN routes are not installed in the FIB/ASIC. | | |
| 5080564 | You can't stage both ZTP and a startup.yaml file at the same time. | | |
| 5080543 | After a switch reboot, the NVUE EVPN operational view (nv show vrf --view=evpn) might report scaled layer 3 VNIs as down with a null router-mac, system-mac, or SVI while FRR correctly reports them as Up. This is an operational-data synchronization issue in the NVUE view with no impact to EVPN forwarding or routing. | | |
diff --git a/content/cumulus-linux-518/rn.xml b/content/cumulus-linux-518/rn.xml
index 1c094a295c..d3b64b5e33 100644
--- a/content/cumulus-linux-518/rn.xml
+++ b/content/cumulus-linux-518/rn.xml
@@ -7,6 +7,18 @@
nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717501 | In the Spanning Tree PVRST environment, when one bridge interface goes down, it causes all the other bridge interfaces to enter a blocking state for approximately ten seconds. Even though the down port is not the root port, all the other bridge ports are flushed and not in service for about ten seconds. | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -160,12 +161,12 @@ pdfhidden: True
| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4850551 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4840299 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4797691 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4815029 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.5|
| 4789097 | The switch deletes a static blackhole route even when the blackhole type specified in the delete command does not match the configured type. | 5.9.4-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4714845 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4663076, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717752, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -344,11 +345,11 @@ pdfhidden: True
| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4850551 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4840299 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4797691 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4815029 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.5|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4714845 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4663076, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717752, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -503,11 +504,11 @@ pdfhidden: True
| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
+| 4850551 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4840299 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4797691 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4815029 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.5|
| 4771521 | Layer 3 multicast traffic does not forward when OMF (Optimized Multicast Flooding) and PIM is enabled. To work around this issue, flap the router port. | 5.9.2-5.15.1 | 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4714845 | The switch installs suboptimal routes in the routing table and advertises them out. | 5.9.2-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4663076, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4717752, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -707,8 +708,8 @@ pdfhidden: True
| 4882392 | If you run the nv show evpn access-vlan-info vlan command after deleting a bond interface, which is part of a bridge, the server encounters an internal error. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6 | 5.17.0-5.18.0|
| 4871161 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4840299 | If you use NVUE commands to change the BGP autonomous system number (ASN) for existing VRFs without deleting the associated EVPN VNI, FRR reload fails and shows an error during nv config apply. Be sure to delete the layer 3 VNI before changing the BGP ASN or restart FRR after the AS change. | 5.9.1-5.9.4 | 5.9.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4797691 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4663076, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4815029 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.5|
+| 4717752, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
@@ -893,8 +894,8 @@ pdfhidden: True
| 5093852 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4986329 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
| 4963277 | When many BFD sessions are configured at scale, ptmd might crash when one of the BFD sessions flaps. | 5.3.1-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | |
-| 4797691 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1 | 5.9.5, 5.16.0-5.16.1, 5.16.6-5.18.0|
-| 4663076, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
+| 4815029 | The message that the switch displays when you generate a cl-support file or as a post login banner contains an invalid Cumulus Support email address, which is no longer the formal channel for reporting support issues. | 5.0.0-5.9.4, 5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0 | 5.9.5|
+| 4717752, 3963232 | When you add or remove routes in a virtual router with numerous configured routes, you might see incorrect routing of certain IP addresses. This can result in packets exiting through incorrect ports or being discarded. | 5.3.1-5.9.4 | 5.9.5-5.15.1, 5.11.5-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4647646 | If you configure policy-based routing (PBR) rules for more than 32 interfaces, only the rules assigned to the first 32 interfaces are installed in the kernel. | 4.4.2-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4637200 | When more than one IPv4 and/or IPv6 addresses are configured on a remote interface, NVUE LLDP commands such as nv show interface lldp-detail only reflect one address. To work around this issue, use lldpctl to view LLDP information. For example, sudo lldpctl -d -f json swp1. | 5.9.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
| 4633514 | When the switch processes large numbers of mroute updates in an MLAG configuration, FRR might crash. | 5.8.0-5.14.0 | 5.15.0-5.15.1, 5.16.0-5.16.1, 5.16.6-5.18.0|
diff --git a/content/cumulus-linux-59/rn.xml b/content/cumulus-linux-59/rn.xml
index fc41037276..0d893e2bfd 100644
--- a/content/cumulus-linux-59/rn.xml
+++ b/content/cumulus-linux-59/rn.xml
@@ -79,6 +79,12 @@