Add 10.0 issue data
This commit is contained in:
@@ -0,0 +1,223 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.10
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-190175
|
||||
|
||||
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||
|
||||
## PAN-190223
|
||||
|
||||
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||
|
||||
## PAN-189665
|
||||
|
||||
```caveat
|
||||
FIPS-CC enabled firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
|
||||
|
||||
## PAN-185616
|
||||
|
||||
Fixed an issue where the firewall sent fewer logs to the system log server than expected. With this fix, the firewall accommodates a larger send queue for syslog forwarding to TCP syslog receivers.
|
||||
|
||||
## PAN-185163
|
||||
|
||||
Fixed an issue where the distributord process hit the FD limit, which caused User-ID redistribution to not function properly.
|
||||
|
||||
## PAN-184693
|
||||
|
||||
Fixed an issue that caused the slotd process to stop responding due to an incorrect response from etcd lock API.
|
||||
|
||||
## PAN-183862
|
||||
|
||||
Fixed an issue where, after a CN-NGFW pod failed-over to the second CN-MGMT pod, the configuration was not synchronized between the new CN-MGMT pod and the CN-NGFW pod.
|
||||
|
||||
## PAN-183774
|
||||
|
||||
Fixed an memory leak issue in the mgmtsrvr process, which resulted in an out-of-memory (OOM) condition and high availability (HA) failover.
|
||||
|
||||
## PAN-183239
|
||||
|
||||
Fixed an issue where the firewall randomly disconnected from the WildFire URL cloud.
|
||||
|
||||
## PAN-182903
|
||||
|
||||
Fixed an issue where SD-WAN failover on a hub or branch in full mesh took longer than expected.
|
||||
|
||||
## PAN-181839
|
||||
|
||||
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
|
||||
|
||||
## PAN-181039
|
||||
|
||||
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
|
||||
|
||||
## PAN-181031
|
||||
|
||||
Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod eventually consumed a large amount of space in the /var/log/pan because the old registered stale next-generation firewall logs were not being cleared.
|
||||
|
||||
## PAN-180916
|
||||
|
||||
Fixed an issue where DNS security caused the TTL (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
|
||||
|
||||
## PAN-179982
|
||||
|
||||
Fixed an issue where an OOM condition occurred due to quarantine list redistribution.
|
||||
|
||||
## PAN-179976
|
||||
|
||||
Fixed an issue where the WildFire Inline Machine Learning (ML) did not detect mlav-test-pe-file.exe when traffic was decrypted.
|
||||
|
||||
## PAN-179703
|
||||
|
||||
Fixed an issue where dataplane interfaces weren't released when the secured application pods were deleted.
|
||||
|
||||
## PAN-179413
|
||||
|
||||
Fixed an issue where GRE tunnels flapped during commit jobs.
|
||||
|
||||
## PAN-179321
|
||||
|
||||
A validation error was added to inform an administrator when a policy field contained the value **any**.
|
||||
|
||||
## PAN-179274
|
||||
|
||||
Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the HA1 and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet.
|
||||
|
||||
## PAN-179164
|
||||
|
||||
Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run.
|
||||
|
||||
## PAN-179059
|
||||
|
||||
Fixed an issue where you were unable to delete dynamic address groups one at a time using XML API.
|
||||
|
||||
## PAN-178947
|
||||
|
||||
Fixed an issue where the useridd process stopped responding when a NULL reference attempted to be dereferenced. This issue occurred to IP address users being added.
|
||||
|
||||
## PAN-177907
|
||||
|
||||
Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy.
|
||||
|
||||
## PAN-177878
|
||||
|
||||
Fixed an issue where a role-based admin with **Operational Requests** enabled under the XML API section was unable to set the License Deactivation API key.
|
||||
|
||||
## PAN-177626
|
||||
|
||||
Fixed an issue where aggressive situations caused on-chip descriptor exhaustion.
|
||||
|
||||
## PAN-177551
|
||||
|
||||
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
|
||||
|
||||
## PAN-177187
|
||||
|
||||
Fixed an issue where reports using the decryption summary database and Panorama as data sources returned no results.
|
||||
|
||||
## PAN-177170
|
||||
|
||||
Fixed an issue on Panorama where a log collector group commit deleted the proxy settings configured on dedicated log collectors.
|
||||
|
||||
## PAN-176889
|
||||
|
||||
Fixed an issue where the log collector continuously disconnected from Panorama due to high latency and a high number of packets in Send-Q.
|
||||
|
||||
## PAN-176703
|
||||
|
||||
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
|
||||
|
||||
## PAN-176348
|
||||
|
||||
Fixed an issue where scheduled email alerts were not forwarded to all recipients in the override list.
|
||||
|
||||
## PAN-175716
|
||||
|
||||
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
|
||||
|
||||
## PAN-175628
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP.
|
||||
|
||||
## PAN-175259
|
||||
|
||||
Fixed an issue where a Security policy configured with App-ID and set to **web-browsing** and **application-default service** allowed clear-text web-browsing on tcp/443.
|
||||
|
||||
## PAN-175161
|
||||
|
||||
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
|
||||
|
||||
## PAN-174809
|
||||
|
||||
Fixed an issue where a process (all_pktproc) restarted.
|
||||
|
||||
## PAN-174607
|
||||
|
||||
Fixed an intermittent issue where, when Security profiles were attached to a policy, files that were downloaded across TLS sessions decrypted by the firewall were malformed.
|
||||
|
||||
## PAN-174587
|
||||
|
||||
Fixed an issue where, in the case of multiple AWS Partner Network (APN) connections, the GPRS tunneling protocol (GTPv2) Create Session Requests were sent to the firewall within a short interval, which caused the firewall to create the GTP-sessions incorrectly.
|
||||
|
||||
## PAN-174011
|
||||
|
||||
Fixed an issue where Panorama failed to update shared policies during partial commits when a new device group was created but not yet committed.
|
||||
|
||||
## PAN-171345
|
||||
|
||||
Fixed an issue where firewalls experienced high packet descriptor usage due to internal communication associated with WildFire.
|
||||
|
||||
## PAN-171181
|
||||
|
||||
Fixed an issue where the IPSec tunnel configuration didn't load when a double quotation mark was added to the comment section of the IPSec tunnel **General** tab.
|
||||
|
||||
## PAN-171104
|
||||
|
||||
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
|
||||
|
||||
## PAN-170952
|
||||
|
||||
Fixed script issues that caused diagnostic data to not be collected after path monitor failure.
|
||||
|
||||
## PAN-168400
|
||||
|
||||
Fixed an issue where, after installing Cloud Services plugin 10.2, the **Plugin cloud_services** status (**Dashboard > High Availability**) displayed as **Mismatch**.
|
||||
|
||||
## PAN-168286
|
||||
|
||||
Fixed a memory leak issue in the mgmtsrvr process that was caused by failed commit all operations.
|
||||
|
||||
## PAN-167849
|
||||
|
||||
Fixed an issue where URL Filtering incorrectly identified the firewall serial number in the certificate **Common Name** field as the IP address.
|
||||
|
||||
## PAN-164871
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where deactivating the firewall via XML API using manual mode failed. This occurred because the size of the license token file was incorrect.
|
||||
|
||||
## PAN-163245
|
||||
|
||||
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
|
||||
|
||||
## PAN-161297
|
||||
|
||||
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
|
||||
|
||||
## PAN-155448
|
||||
|
||||
Fixed an issue where credential detection didn't work in IP address-to-username mapping mode because the firewall compared the unnormalized IP-address-to-username mapping format to the normalized username extracted from the payload where the username and password were submitted.
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.11-h1
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-192999
|
||||
|
||||
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.11-h3
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-202450
|
||||
|
||||
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-198372
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-193004
|
||||
|
||||
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.11-h4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-237876
|
||||
|
||||
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||
|
||||
## PAN-215576
|
||||
|
||||
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.12-h5
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-239241
|
||||
|
||||
Extended the root certificate for WildFire appliances to December 31, 2032.
|
||||
|
||||
## PAN-237935
|
||||
|
||||
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||
|
||||
## PAN-237876
|
||||
|
||||
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||
|
||||
## PAN-215576
|
||||
|
||||
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||
@@ -0,0 +1,167 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-161613
|
||||
|
||||
Fixed an issue where the **Dashboard** incorrectly displayed the Log Forwarding Card (LFC) port status.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
## PAN-160974
|
||||
|
||||
Fixed an issue on Panorama where, if **Source Address Exclusion** **(Network > Zone Protection > Reconnaissance Protection**) was configured, **Flood Protection** was disabled.
|
||||
|
||||
## PAN-160376
|
||||
|
||||
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
|
||||
|
||||
## PAN-160163
|
||||
|
||||
Fixed an issue where icons in the left sidebar had multiple layers.
|
||||
|
||||
## PAN-159856
|
||||
|
||||
Fixed an issue where, when a factory reset was performed on a Panorama appliance with PAN-OS 10.0, the appliance repeatedly rebooted.
|
||||
|
||||
## PAN-159850
|
||||
|
||||
Fixed an issue where syslog server monitoring stopped working when the first tuple in regex matching was always a whole string.
|
||||
|
||||
## PAN-159826
|
||||
|
||||
Fixed an issue where SSL VPN leaked when the default browser feature on GlobalProtect was not enabled.
|
||||
|
||||
## PAN-159508
|
||||
|
||||
Fixed an IPSec tunnel memory leak issue where IPSec tunnels failed during rekey.
|
||||
|
||||
## PAN-158988
|
||||
|
||||
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
|
||||
|
||||
## PAN-158650
|
||||
|
||||
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
|
||||
|
||||
## PAN-158461
|
||||
|
||||
Fixed an issue where editing an application filter object caused excluded applications to be included.
|
||||
|
||||
## PAN-157885
|
||||
|
||||
Fixed an issue where you could not prioritize the tunnel preference for your branches and hubs in SD-WAN full mesh VPN clusters.
|
||||
|
||||
## PAN-157620
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls deployed in Amazon Web Services (AWS) instance types M5 and C5 only
|
||||
```
|
||||
|
||||
Fixed an issue where a Panorama Virtual Appliance in a high availability (HA) configuration entered a suspended state due to a virtual machine (VM) memory size mismatch.
|
||||
|
||||
## PAN-157319
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
|
||||
```
|
||||
|
||||
Fixed an issue where GlobalProtect logs showed the incorrect client version and did not show event ID information.
|
||||
|
||||
## PAN-156728
|
||||
|
||||
Fixed an issue where GlobalProtect user traffic did not correctly match Security policy rules that had host information profile (HIP) objects and profiles.
|
||||
|
||||
## PAN-156549
|
||||
|
||||
Fixed an issue where the download link was omitted on scheduled email reports for SaaS application usage.
|
||||
|
||||
## PAN-156240
|
||||
|
||||
A fix was made to address an issue where a cryptographically weak pseudo-random number generator (PRNG) was used during authentication to the PAN-OS web interface to enable an attacker to observe their own authenticated secrets on the firewall over a long duration, which enabled them to impersonate another authenticated web interface administrator’s session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
|
||||
|
||||
## PAN-156115
|
||||
|
||||
Fixed an issue where, if the firewall had the standard support license, the **License** tab did not display the license details after an upgrade to PAN-OS 10.0.1.
|
||||
|
||||
## PAN-155824
|
||||
|
||||
Fixed a rare issue where Open Shortest Path First (OSPF) links flapped.
|
||||
|
||||
## PAN-155672
|
||||
|
||||
Fixed an issue where inserting or removing copper and optic modules in PAN-OS 10.0.1 caused a process (brdagent) to stop responding.
|
||||
|
||||
## PAN-154365
|
||||
|
||||
Fixed an issue where Security policy rules targeted by tags incorrectly displayed as deleted when previewing commit changes.
|
||||
|
||||
## PAN-154323
|
||||
|
||||
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
|
||||
|
||||
## PAN-154208
|
||||
|
||||
Fixed an issue where the **Device** icon was not displayed (**Policies > Security > Name > Source > Source Device > Add** or **Policies > Security > Name > Destination > Destination Device > Add**).
|
||||
|
||||
## PAN-154190
|
||||
|
||||
Fixed an issue where Data Loss Prevention (DLP) did not support the upload of Office Open XML (OOXML) files generated from Google suite applications such as Google Docs, Slides, and Sheets.
|
||||
|
||||
## PAN-153705
|
||||
|
||||
Fixed an issue where packets were not evenly distributed among a process (pan_tasks), which caused latency and poor performance.
|
||||
|
||||
## PAN-153547
|
||||
|
||||
Fixed an issue where the login banner size increased.
|
||||
|
||||
## PAN-151997
|
||||
|
||||
Fixed an issue where the option to sinkhole was not displayed in the ACC filter drop-down (**ACC > Threat Activity > Global filters > Action**).
|
||||
|
||||
## PAN-151872
|
||||
|
||||
Fixed an issue where MAC addresses containing certain characters in sequential order caused an issue with TCP connections
|
||||
|
||||
## PAN-151803
|
||||
|
||||
Fixed an issue on Panorama where commits failed when using device-id as a template variable.
|
||||
|
||||
## PAN-151458
|
||||
|
||||
Fixed an issue on firewalls with HA active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
|
||||
|
||||
## PAN-150968
|
||||
|
||||
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
|
||||
|
||||
## PAN-147792
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding due to a buffer overflow.
|
||||
|
||||
## PAN-147221
|
||||
|
||||
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
|
||||
|
||||
## PAN-145417
|
||||
|
||||
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
|
||||
|
||||
## PAN-134461
|
||||
|
||||
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
|
||||
|
||||
## PAN-133863
|
||||
|
||||
Fixed an issue where the Panorama Virtual Appliance in Log Collector mode went into maintenance mode due to a process (reportd) not responding.
|
||||
|
||||
## PAN-122281
|
||||
|
||||
An error check process (mcelog) was added to capture hardware failure reasons detected by the processor.
|
||||
@@ -0,0 +1,333 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.5
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-164922
|
||||
|
||||
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
|
||||
|
||||
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
|
||||
|
||||
## PAN-164674
|
||||
|
||||
Fixed a memory leak issue related to a process (mprelay) that was caused by ARP and route entries not being freed after skipping duplicate updates.
|
||||
|
||||
## PAN-163538
|
||||
|
||||
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
|
||||
|
||||
## PAN-163503
|
||||
|
||||
Fixed an issue on the passive firewall in a high availability (HA) configuration where a SD-WAN virtual network interface (VIF) status check caused associated static routes to be incorrectly withdrawn from the FIB.
|
||||
|
||||
## PAN-163489
|
||||
|
||||
Fixed an issue where an SD-WAN VIF was incorrectly detected as inactive during the commit time, which caused associated route withdrawal.
|
||||
|
||||
## PAN-163415
|
||||
|
||||
Fixed an issue where a memory leak related to the configd process occurred if the SD-WAN plugin was installed and many templates were configured on Panorama.
|
||||
|
||||
## PAN-163274
|
||||
|
||||
Fixed an issue where the SD-WAN hub firewall sent traffic via a VPN tunnel interface that was inactive.
|
||||
|
||||
## PAN-162746
|
||||
|
||||
Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory.
|
||||
|
||||
## PAN-162743
|
||||
|
||||
Fixed an issue where the firewall did not receive updates for the Device Dictionary, which caused the firewall to replace new attributes in the IP address-to-device mappings with unknown.
|
||||
|
||||
## PAN-162534
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) using a Gateway Load Balancer (GWLB) only
|
||||
```
|
||||
|
||||
Fixed an issue where when the VM-Series firewall on AWS is integrated with a GWLB, GlobalProtect did not work.
|
||||
|
||||
## PAN-162256
|
||||
|
||||
Fixed an issue where incorrect WildFire verdicts displayed on Panorama from Cortex Data Lake.
|
||||
|
||||
## PAN-162059
|
||||
|
||||
Fixed an issue where, after a new Layer 3 interface was created in PAN-OS 10.0.3 or 10.0.4, a downgrade to a PAN-OS 9.0 version failed with the error message U pstream NAT not supported in older version. This issue occurred whether SD-WAN was configured on the firewall or not.
|
||||
|
||||
## PAN-161767
|
||||
|
||||
Fixed an issue where, due to a dataplane sync issue, SD-WAN traffic was forwarded to a tunnel that was inactive.
|
||||
|
||||
## PAN-161745
|
||||
|
||||
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
|
||||
|
||||
## PAN-161562
|
||||
|
||||
Enhanced security in how Palo Alto Networks next-generation VM-Series and PA-Series firewalls handle asymmetric traffic.
|
||||
|
||||
## PAN-161428
|
||||
|
||||
Fixed an issue where multiple restarts on a process (all_pktproc) occurred on firewalls in an active/passive HA configuration.
|
||||
|
||||
## PAN-160782
|
||||
|
||||
Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix.
|
||||
|
||||
## PAN-160556
|
||||
|
||||
Fixed an issue that prevented decryption and IP-tag logs from being forwarded to the syslog over TCP.
|
||||
|
||||
## PAN-160499
|
||||
|
||||
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, configuration pushes failed with the error Need to config WMI account and password for querying Microsoft directory servers.
|
||||
|
||||
## PAN-160455
|
||||
|
||||
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
|
||||
|
||||
## PAN-159692
|
||||
|
||||
Fixed an issue where the **/dev/shm** partition increased to 100% disk usage with multiple older versions of WildFire content updates.
|
||||
|
||||
## PAN-159393
|
||||
|
||||
Fixed an issue where some TSL1.3 websites were not accessible when decryption was enabled.
|
||||
|
||||
## PAN-159135
|
||||
|
||||
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
|
||||
|
||||
## PAN-158844
|
||||
|
||||
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
|
||||
|
||||
## PAN-158774
|
||||
|
||||
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
|
||||
|
||||
## PAN-158723
|
||||
|
||||
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
|
||||
|
||||
## PAN-158638
|
||||
|
||||
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
|
||||
|
||||
## PAN-158585
|
||||
|
||||
Fixed a memory leak issue related to the X-Forwarded-For (XFF) security feature.
|
||||
|
||||
## PAN-158328
|
||||
|
||||
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
|
||||
|
||||
## PAN-158293
|
||||
|
||||
Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic.
|
||||
|
||||
## PAN-158122
|
||||
|
||||
Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
|
||||
|
||||
## PAN-157735
|
||||
|
||||
Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis.
|
||||
|
||||
## PAN-157721
|
||||
|
||||
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
|
||||
|
||||
## PAN-157346
|
||||
|
||||
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
|
||||
|
||||
## PAN-157271
|
||||
|
||||
Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled.
|
||||
|
||||
## PAN-157266
|
||||
|
||||
Fixed an issue with the logrcvr process that caused inaccurate netflow values.
|
||||
|
||||
## PAN-157168
|
||||
|
||||
Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands
|
||||
|
||||
## PAN-157049
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
|
||||
|
||||
## PAN-156982
|
||||
|
||||
Fixed an issue where the firewall didn't resolve domain names with multiple nested Canonical Name (CNAME) records when caching was enabled.
|
||||
|
||||
## PAN-156891
|
||||
|
||||
Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable.
|
||||
|
||||
## PAN-156716
|
||||
|
||||
Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address.
|
||||
|
||||
## PAN-156498
|
||||
|
||||
Fixed an issue where the User-ID Agent did not reconnect after being disconnected.
|
||||
|
||||
## PAN-156264
|
||||
|
||||
Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI.
|
||||
|
||||
## PAN-156225
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to PAN-OS 9.1.5.
|
||||
|
||||
## PAN-155656
|
||||
|
||||
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
|
||||
|
||||
## PAN-155294
|
||||
|
||||
Fixed an issue where iPad devices did not display Authentication Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
|
||||
|
||||
## PAN-154899
|
||||
|
||||
Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages.
|
||||
|
||||
## PAN-154844
|
||||
|
||||
Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr.
|
||||
|
||||
## PAN-154812
|
||||
|
||||
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
|
||||
|
||||
## PAN-154376
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||
|
||||
## PAN-154195
|
||||
|
||||
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
|
||||
|
||||
## PAN-154145
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the management plane CPU was incorrectly reported to be high.
|
||||
|
||||
## PAN-153614
|
||||
|
||||
Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format.
|
||||
|
||||
## PAN-153213
|
||||
|
||||
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
|
||||
|
||||
## PAN-152998
|
||||
|
||||
Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected.
|
||||
|
||||
## PAN-152813
|
||||
|
||||
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
|
||||
|
||||
## PAN-152458
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Hyper-V only
|
||||
```
|
||||
|
||||
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
|
||||
|
||||
## PAN-151808
|
||||
|
||||
Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates.
|
||||
|
||||
## PAN-151218
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the `crashinfo` file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot.
|
||||
|
||||
## PAN-150867
|
||||
|
||||
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
|
||||
|
||||
## PAN-150798
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
|
||||
|
||||
## PAN-150023
|
||||
|
||||
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
|
||||
|
||||
## PAN-148549
|
||||
|
||||
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
|
||||
|
||||
## PAN-147783
|
||||
|
||||
Checks were added to help prevent the dataplane from restarting.
|
||||
|
||||
## PAN-147228
|
||||
|
||||
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
|
||||
|
||||
## PAN-144538
|
||||
|
||||
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
|
||||
|
||||
## PAN-144470
|
||||
|
||||
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
|
||||
|
||||
## PAN-142473
|
||||
|
||||
Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue.
|
||||
|
||||
## PAN-136478
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls
|
||||
```
|
||||
|
||||
where syslog forwarding over TCP did not work in a multi-vsys environment.
|
||||
|
||||
## PAN-136347
|
||||
|
||||
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
|
||||
|
||||
## PAN-134799
|
||||
|
||||
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
|
||||
|
||||
## PAN-129927
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
|
||||
@@ -0,0 +1,319 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.6
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-168298
|
||||
|
||||
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
|
||||
|
||||
## PAN-167401
|
||||
|
||||
Fixed an issue where, when a firewall or Panorama appliance configured with a proxy was upgraded to PAN-OS 10.0.3 or a later release, it failed to connect to edge service.
|
||||
|
||||
## PAN-166994
|
||||
|
||||
Fixed an issue where the management failed to publish custom metrics to cloud monitoring tools, which caused pod auto-scaling to not work.
|
||||
|
||||
## PAN-166677
|
||||
|
||||
Fixed an issue on the firewall where a process (devsrvr) stopped responding during a commit.
|
||||
|
||||
## PAN-166570
|
||||
|
||||
Fixed an issue where authentication failure messages were overwritten when a commit was in progress.
|
||||
|
||||
## PAN-166306
|
||||
|
||||
Fixed an issue where commit jobs failed when validating HIP objects and profiles.
|
||||
|
||||
## PAN-166241
|
||||
|
||||
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
|
||||
|
||||
## PAN-165194
|
||||
|
||||
Fixed an issue where multiple messages were exchanged between secondary and primary Data Plane Development Kit (DPDK) processes, which caused a process (brdagent) to stop responding.
|
||||
|
||||
## PAN-164846
|
||||
|
||||
Fixed an issue where packet buffers were depleted.
|
||||
|
||||
## PAN-164564
|
||||
|
||||
Fixed an issue where stats API attempted to get stats from an unavailable port.
|
||||
|
||||
## PAN-164328
|
||||
|
||||
Fixed an issue where the firewall incorrectly dropped GPRS tunneling protocol (GTPv2) Bearer Resource Failure Indication messages with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
|
||||
|
||||
## PAN-164094
|
||||
|
||||
Fixed an issue where two process (devsrvr and useridd) did not synchronize IP tags, which caused Dynamic Address Groups to not populate.
|
||||
|
||||
## PAN-163261
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped GTPv2 Modify Bearer Request packets with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
|
||||
|
||||
## PAN-162663
|
||||
|
||||
Fixed an intermittent issue on the firewall where packets dropped in decrypted SSL/TLS sessions.
|
||||
|
||||
## PAN-162594
|
||||
|
||||
Fixed an issue where blank configuration for tokens in a content-driven FreeDNS Afraid.org Dynamic API v1 DDNS configuration were not enabled.
|
||||
|
||||
## PAN-161499
|
||||
|
||||
Fixed an issue where, after an upgrade from PAN-OS 9.1.5 to PAN-OS 10.0.3, Panorama admin sessions were created with 30 days to expire on the firewalls.
|
||||
|
||||
## PAN-161112
|
||||
|
||||
Fixed an issue where a process (useridd) repeatedly exceeded the virtual memory limit, which caused the process to stop responding.
|
||||
|
||||
## PAN-160939
|
||||
|
||||
Fixed an issue where the firewall dropped GTPv1 Forward Relocation Requests with the following error message: Abnormal GTP-U message with invalid IE.
|
||||
|
||||
## PAN-160870
|
||||
|
||||
```caveat
|
||||
ZTP-capable firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the default Zero Touch Provisioning (ZTP) configuration was still present on the firewall even when ZTP was disabled, which caused commit failures.
|
||||
|
||||
## PAN-160744
|
||||
|
||||
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
|
||||
|
||||
## PAN-160434
|
||||
|
||||
Fixed an issue where firewalls stopped processing Layer-3-tagged traffic after Panorama pushed VLAN sub-interface configurations to the firewall with the **commit_all** operation.
|
||||
|
||||
## PAN-159944
|
||||
|
||||
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
|
||||
|
||||
## PAN-159936
|
||||
|
||||
Fixed an issue where BGP route stopped advertising a redistribute route when a similar new redistribute route was configured.
|
||||
|
||||
## PAN-159054
|
||||
|
||||
Fixed an issue where you were unable to add more than 500 DHCP relay agent objects in the firewall templates from Panorama.
|
||||
|
||||
## PAN-158972
|
||||
|
||||
Fixed an issue on the firewall where a process (useridd) stopped responding and generated a core dump after being restarted by the administrator.
|
||||
|
||||
## PAN-158407
|
||||
|
||||
Fixed an issue where configuring the BGP export policy with the match criteria set to next hops, redistributed connected routes incorrectly matched this criteria.
|
||||
|
||||
## PAN-158262
|
||||
|
||||
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
|
||||
|
||||
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
|
||||
|
||||
## PAN-158036
|
||||
|
||||
Fixed an issue on the firewall where custom application signatures based on PROPFIND http-method didn't trigger if webdav application ID was blocked by a Security policy.
|
||||
|
||||
Note: To utilize this fix, you must install content version 8367-6513 or later.
|
||||
|
||||
## PAN-157964
|
||||
|
||||
Fixed an issue where adding a container application from the **Apps Seen** list did not remove the child application from the list.
|
||||
|
||||
## PAN-157834
|
||||
|
||||
Fixed an issue with missing zone entries in CSV or PDF export files.
|
||||
|
||||
## PAN-157479
|
||||
|
||||
Fixed an issue on the firewall where a process (useridd) stopped responding when group-mapping profiles were configured with an LDAP server profile with the type **e-dictionary**.
|
||||
|
||||
## PAN-157447
|
||||
|
||||
Fixed an issue where a process (flow_mgmt) repeatedly restarted with a segmentation violation (SIGSEGV) signal and the following trace: flow_mgmt:pan_flow_dos_ager_invoke pan_sw_timer_100ms pan_sw_timer_invoke.
|
||||
|
||||
## PAN-157311
|
||||
|
||||
Fixed an issue where, if the **OK** button is clicked before tags are loaded when editing an address object that contained tags via the firewall web interface, associated tags are removed.
|
||||
|
||||
## PAN-157238
|
||||
|
||||
Fixed an issue where, when a non-SAML authentication policy was used, the SAML **Use Single Sign-On** option was displayed.
|
||||
|
||||
## PAN-157136
|
||||
|
||||
Fixed an issue where a memory leak associated with a process (pan_dha) caused an OOM condition on the firewall due to a configuration sync triggered by a commit on an HA cluster.
|
||||
|
||||
## PAN-156896
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall frequently stopped responding with the following log: CONFIG_UPDATE_INC : Incremental update to DP failed please try to commit force the latest config.
|
||||
|
||||
## PAN-156669
|
||||
|
||||
Fixed an issue in Panorama where, when a variable object description was set, the description was automatically copied to template description.
|
||||
|
||||
## PAN-156396
|
||||
|
||||
Fixed an issue where the CTD queue was full, which caused traffic to be dropped with the counter ctd_exceed_pkt_limit.
|
||||
|
||||
## PAN-156380
|
||||
|
||||
Fixed an issue where running show commands related to SD-WAN caused a process (pan_comm) to stop responding.
|
||||
|
||||
## PAN-156199
|
||||
|
||||
Fixed an issue where, in the **Email Scheduler** (**Monitor > PDF Reports**), the **Recurrence** parameter unexpectedly changed from **Daily** to **Disable** when the web interface language was not English.
|
||||
|
||||
## PAN-156113
|
||||
|
||||
Fixed an issue where the management interface incorrectly used the configured default gateway for local network traffic when service routes were configured.
|
||||
|
||||
## PAN-156098
|
||||
|
||||
Fixed an issue where netflow packets sent from the firewall contained excess padding, which resulted in the packet length exceeding 1400 bytes.
|
||||
|
||||
## PAN-156001
|
||||
|
||||
Fixed an issue where the downloaded GTP event packet capture from **Monitor > Logs > GTP** displayed a different packet than the one that actually triggered the event.
|
||||
|
||||
## PAN-155772
|
||||
|
||||
Fixed an issue where the Panorama web interface did not display the secondary IP address configuring it under the template stack.
|
||||
|
||||
## PAN-155758
|
||||
|
||||
```caveat
|
||||
7000-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, when a subinterface was configured as a Log Card interface, the commit failed unless an IP address was assigned to the parent interface.
|
||||
|
||||
## PAN-155593
|
||||
|
||||
Fixed an issue where the firewall was unable to match HIP objects with a 3-digit code version.
|
||||
|
||||
## PAN-155457
|
||||
|
||||
Fixed an issue where PAN-OS custom logos were not uploaded due to the upper case file extensions.
|
||||
|
||||
## PAN-155147
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure that use accelerated networking interfaces with DPDK mode
|
||||
```
|
||||
|
||||
Fixed an issue where hot plug notifications caused traffic disruption.
|
||||
|
||||
## PAN-155126
|
||||
|
||||
Fixed an issue where editing the LDAP server IP address (**Device > Templates > Server Profiles > LDAP > LDAP Server Profile**) removed the bind password.
|
||||
|
||||
## PAN-155049
|
||||
|
||||
Fixed an issue with SSLVPN memory leaks related to the GlobalProtect portal **Config Selection Criteria**.
|
||||
|
||||
## PAN-154820
|
||||
|
||||
Fixed an issue where policy-based forwarding (PBF) monitoring failed when the egress interface was a tunnel.
|
||||
|
||||
## PAN-154603
|
||||
|
||||
Fixed an issue where, when SSL/TLS was required, LDAP server authentication attempted StartTLS first.
|
||||
|
||||
## PAN-154602
|
||||
|
||||
Fixed an issue where GlobalProtect users got disconnected after modifying floating IP HA configuration.
|
||||
|
||||
## PAN-154571
|
||||
|
||||
Fixed an issue where, if source-ip-enforcement.enable was true, GlobalProtect configurations on the template stack level were unable to be modified, and the schema used the default choice.
|
||||
|
||||
## PAN-154557
|
||||
|
||||
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
|
||||
|
||||
## PAN-154487
|
||||
|
||||
Fixed an issue where the GlobalProtect log description field size decreased.
|
||||
|
||||
## PAN-154403
|
||||
|
||||
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
|
||||
|
||||
## PAN-154109
|
||||
|
||||
Fixed an issue where using XML special characters in the **Uninstalled GlobalProtect APP** password in the application configuration (**Networks > GlobalProtect > Portals > Agent > App**) disrupted portal connectivity.
|
||||
|
||||
## PAN-153816
|
||||
|
||||
Fixed an issue where the firewall booted up in Extensible Firmware Interface (EFI) Shell when performing factory reset with selected image file.
|
||||
|
||||
## PAN-153592
|
||||
|
||||
Fixed an issue where, after upgrading Panorama from PAN-OS 8.1.9 to PAN-OS 9.1.3, the option to preview changes for dynamic address groups or templates from Panorama did not work.
|
||||
|
||||
## PAN-153316
|
||||
|
||||
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit. -To disable the virtual memory limit, use debug software disable-virt-limit. -To enable the virtual memory limit, use debug software enable-virt-limit.
|
||||
|
||||
## PAN-152497
|
||||
|
||||
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
|
||||
|
||||
## PAN-151521
|
||||
|
||||
Fixed an issue where a process (logrcvr) continuously restarted at pan_hash_iter_next_i.
|
||||
|
||||
## PAN-151395
|
||||
|
||||
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
|
||||
|
||||
## PAN-150298
|
||||
|
||||
Fixed an issue where Android clients matched HIP objects configured for Apple products.
|
||||
|
||||
## PAN-149867
|
||||
|
||||
Fixed an issue where a process (authd) ignored null domain authentication profiles in a sequence and only returned non-null domains to GlobalProtect.
|
||||
|
||||
## PAN-149853
|
||||
|
||||
Fixed an issue on Panorama where the **loc** attribute was not set as **shared** when creating dynamic-address-group-specific configurations during a Panorama commit.
|
||||
|
||||
## PAN-147827
|
||||
|
||||
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
|
||||
|
||||
## PAN-147081
|
||||
|
||||
Fixed an issue where routes learned from the GlobalProtect Large Scale VPN (LSVPN) Gateway were cleared from the routing table when ECMP was toggled (enabled or disabled).
|
||||
|
||||
## PAN-146048
|
||||
|
||||
Fixed an issue where a satellite firewall was unable to authenticate to a LSVPN gateway when the issued certificate from Simple Certificate Enrollment Protocol (SCEP) had encryption bits set to 3072. With this fix, the maximum private key size of 3072 bits, along with the 1024-bit size and the 2048-bit size, is able to authenticate when selected to create the SCEP profile.
|
||||
|
||||
## PAN-142621
|
||||
|
||||
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
|
||||
|
||||
## PAN-140243
|
||||
|
||||
Fixed an issue where non-web-based traffic that was part of the User-ID zone exclude list still matched the configured authentication policy.
|
||||
|
||||
## PAN-134007
|
||||
|
||||
Fixed an issue where the Log Forwarding Card (LFC) advertised the wrong MAC Address to the connected switch.
|
||||
@@ -0,0 +1,587 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.7
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## WF500-5568
|
||||
|
||||
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
|
||||
|
||||
## WF500-5559
|
||||
|
||||
Fixed an issue where an intermittent error while analyzing signed PE samples on the WildFire appliance might have caused analysis failures.
|
||||
|
||||
## WF500-5509
|
||||
|
||||
```caveat
|
||||
WF-500 appliance only
|
||||
```
|
||||
|
||||
Fixed an issue where cloud inquiries were logged under the **SD-WAN** subtype.
|
||||
|
||||
## PAN-173080
|
||||
|
||||
Fixed an issue where the User-ID connection limit was reached even when only a few User-ID agents were connected to the service.
|
||||
|
||||
## PAN-172518
|
||||
|
||||
Fixed an issue where a race condition occurred and caused a process (useridd) to restart.
|
||||
|
||||
## PAN-172125
|
||||
|
||||
Fixed an intermittent issue where processing HIP messages in the (useridd) process caused a memory leak.
|
||||
|
||||
## PAN-171878
|
||||
|
||||
Fixed an issue with SD-WAN path selection logic that caused a dataplane to stop responding.
|
||||
|
||||
## PAN-171442
|
||||
|
||||
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing and cross-zone load balancing enabled where packets were forwarded to the incorrect GWLB interface.
|
||||
|
||||
## PAN-171203
|
||||
|
||||
Fixed an issue in a high availability (HA) configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||
|
||||
## PAN-170989
|
||||
|
||||
Fixed an issue memory usage consumption issue on a process (useridd).
|
||||
|
||||
## PAN-170932
|
||||
|
||||
Fixed an issue in Telemetry settings where the **OK** button was disabled when **Telemetry Region** was set to **None**.
|
||||
|
||||
## PAN-170825
|
||||
|
||||
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
|
||||
|
||||
## PAN-170740
|
||||
|
||||
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
|
||||
|
||||
## PAN-170681
|
||||
|
||||
Fixed an issue where the data redistribution agent and the data redistribution client failed to connect due to the agent not sending a SSL Server hello response.
|
||||
|
||||
## PAN-170610
|
||||
|
||||
Fixed an issue where SD-WAN SaaS monitoring traffic was incorrectly dropped by a Security policy that included a deny rule.
|
||||
|
||||
## PAN-170314
|
||||
|
||||
Fixed an issue where PAN-DB URL cloud updates failed because a process (devsrvr) did not fetch serial numbers, which prevented the PAN_DB URL cloud from connecting after first deployment.
|
||||
|
||||
## PAN-170083
|
||||
|
||||
Fixed an intermittent issue where packet pointer corruption occurred, which resulted in a dataplane restart.
|
||||
|
||||
## PAN-169712
|
||||
|
||||
Fixed an intermittent issue where traffic falsely matched a converted Suricata rule.
|
||||
|
||||
## PAN-169197
|
||||
|
||||
Fixed a rare issue where generating a tech support file caused the useridd process to stop responding.
|
||||
|
||||
## PAN-169161
|
||||
|
||||
Fixed an issue where, after a pan_comm process restart, the configuration wasn't synced between the management and the dataplane pod.
|
||||
|
||||
## PAN-169064
|
||||
|
||||
Fixed an issue where the management CPU remained at 100% due to a large number of configured User-ID agents.
|
||||
|
||||
## PAN-168888
|
||||
|
||||
Fixed an issue where, when a maximum session count was configured, the SD-WAN plugin caused commit failures on Panorama.
|
||||
|
||||
## PAN-168718
|
||||
|
||||
Fixed an issue where, when a client or server received partial application data, the record was partially processed by legacy code. This caused decryption to fail when a decryption profile protocol was set to a maximum of TLSv1.3.
|
||||
|
||||
## PAN-168574
|
||||
|
||||
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, a configuration pushed to firewalls running on PAN-OS 9.1 failed during an autocommit with the following error message: Need to config WMI account and password for querying Microsoft directory servers.
|
||||
|
||||
## PAN-168418
|
||||
|
||||
Fixed an issue where, when an MLAV URL with an exception list was configured and forward proxy was enabled, a process (all_pktproc) repeatedly restarted, which resulted in the firewall rebooting.
|
||||
|
||||
## PAN-167989
|
||||
|
||||
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
|
||||
|
||||
## PAN-167872
|
||||
|
||||
Fixed an issue related to a process (all_pktproc) that occurred in long-lived sessions that spanned two content upgrades.
|
||||
|
||||
## PAN-167637
|
||||
|
||||
Fixed an issue where users connecting to the US East gateway encountered a delay in DNS responses.
|
||||
|
||||
## PAN-167541
|
||||
|
||||
Fixed an issue where large External Dynamic Lists (EDLs) caused commit issues due to a hard limit being reached.
|
||||
|
||||
## PAN-167443
|
||||
|
||||
Fixed an issue where commits failed and generated pan_comm SIGSEGV CORE files.
|
||||
|
||||
## PAN-167306
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure only
|
||||
```
|
||||
|
||||
Fixed an issue where, when a second disk was added, /opt/panlogs was mounted on an incorrect partition.
|
||||
|
||||
## PAN-167099
|
||||
|
||||
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
|
||||
|
||||
## PAN-167098
|
||||
|
||||
Fixed an issue where a configd process memory corruption occurred when Panorama was exposed to multiple XML API calls on Dynamic Address Groups updates.
|
||||
|
||||
## PAN-166836
|
||||
|
||||
Fixed an issue where session failed due to resource unavailability.
|
||||
|
||||
## PAN-166572
|
||||
|
||||
Fixed an issue where a process (configd) restarted when browsing policies on Panorama.
|
||||
|
||||
## PAN-166420
|
||||
|
||||
In 10.0.x Query Traffic log option is missing for Address groups under source and destination in the security policy tab
|
||||
|
||||
## PAN-166328
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls with NPCs only
|
||||
```
|
||||
|
||||
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
|
||||
|
||||
## PAN-166296
|
||||
|
||||
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
|
||||
|
||||
## PAN-166021
|
||||
|
||||
Fixed an issue where log queries that included a username did not return with any output.
|
||||
|
||||
## PAN-165661
|
||||
|
||||
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
|
||||
|
||||
## PAN-165399
|
||||
|
||||
Fixed an issue where the multi-factor authentication (MFA) Challenge message did not display during login when the GlobalProtect portal was accessed by the web browser.
|
||||
|
||||
## PAN-165235
|
||||
|
||||
Fixed an issue where the handover handling between LTE and 3G on S5 and S8 to Gn/Gp was not working properly and led to stateful inspection failures.
|
||||
|
||||
## PAN-165025
|
||||
|
||||
Fixed an issue where, when default interzone and intrazone Security policy rules were overwritten, the rules did not display hit counts.
|
||||
|
||||
## PAN-164646
|
||||
|
||||
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
|
||||
|
||||
## PAN-164571
|
||||
|
||||
Fixed an issue where DHCP leases were not properly synchronized between HA peers after a device or dhcpd process restart. With this fix, the DHCP lease details display correctly on both the active and the passive device.
|
||||
|
||||
## PAN-164446
|
||||
|
||||
Fixed an issue on Panorama where a commit failed with the following error message: Local-AS number does not fit in 2-byte AS format, even though the AS format was set to 4 bytes.
|
||||
|
||||
## PAN-164431
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall rebooted into maintenance mode after installing a capacity license in FIPS-CC mode.
|
||||
|
||||
## PAN-164392
|
||||
|
||||
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak related to a process (logrcvr).
|
||||
|
||||
## PAN-164338
|
||||
|
||||
Fixed an issue where, when using the CLI or API, configurations for policy rule services or applications that either used custom settings and default settings together, or used multiple default settings together, successfully commit instead of failing or displaying a warning.
|
||||
|
||||
**Note** To use this fix, you must delete previous application or service settings in the configuration.
|
||||
|
||||
## PAN-164056
|
||||
|
||||
Fixed a memory issue for Large Scale VPN with multiple dataplane systems.
|
||||
|
||||
## PAN-163940
|
||||
|
||||
Fixed an issue where the firewall truncated the application name when doing a NetFlow export to the NetFlow analyzer.
|
||||
|
||||
## PAN-163800
|
||||
|
||||
Fixed an intermittent issue where the presence of an Anti-Spyware profile in a Security policy rule that matched DNS traffic caused DNS responses to be malformed in transit.
|
||||
|
||||
## PAN-163280
|
||||
|
||||
Fixed an issue where, after upgrading to a PAN-OS 10.0 release version, a commit failed due to an admin-role-related validation error that displayed the following message: device unexpected here.
|
||||
|
||||
## PAN-163270
|
||||
|
||||
Fixed an issue where the login banner was not aligned properly when it contained multiple sequential whitespaces.
|
||||
|
||||
## PAN-162600
|
||||
|
||||
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
|
||||
|
||||
## PAN-161869
|
||||
|
||||
Fixed an issue where a core dump occurred on a process (flow_ctrl) after a commit if a policy-based forwarding (PBF) rule referenced an interface that had a DHCP IP address assignment.
|
||||
|
||||
## PAN-161289
|
||||
|
||||
Fixed an issue where predict session didn't update the associated rules when Security policies shifted after a commit.
|
||||
|
||||
## PAN-161218
|
||||
|
||||
The following CLI commands were added to enable the customer to set the dataplane utilization limit. The default setting is the recommended value of 500; a value of 0 removes dataplane CTD limits: -debug dataplane show ctd wildfire max -debug dataplane set ctd wildfire max <0-5000>
|
||||
|
||||
## PAN-161025
|
||||
|
||||
Fixed an issue in Panorama where an administrator with the role of Panorama administrator did not have the option to download or install GlobalProtect clients (**Panorama > Device Deployment > GlobalProtect**).
|
||||
|
||||
## PAN-160997
|
||||
|
||||
Fixed an issue where the metadata from the firewall's authentication profile was unable to export. This issue occurred when the authentication profile and the SAML Identity Provider sever profile were created with **VSYS** in the **Location**and were pushed from Panorama template stack values. To utilize this fix, you must upgrade both Panorama and the firewall.
|
||||
|
||||
## PAN-160843
|
||||
|
||||
Fixed an issue where the Multiprotocol Label Switching (MPLS) interface wasn't monitored when private traffic wasn't VPN encapsulated.
|
||||
|
||||
## PAN-160831
|
||||
|
||||
Fixed an intermittent issue where importing a new firewalls configuration into Panorama failed due to conflicting virtual system (vsys) names, even when the **Device Group Name Prefix** was used to make the name unique.
|
||||
|
||||
## PAN-160818
|
||||
|
||||
Fixed an issue where Panorama repeatedly displayed the following error message: HA Failover: updates not received from all sources: Pending plugins.
|
||||
|
||||
## PAN-160540
|
||||
|
||||
Fixed an issue where tunnel traffic was dropped intermittently when Quality of Service (QoS) Profile was assigned but the profile had no limits defined.
|
||||
|
||||
## PAN-160432
|
||||
|
||||
Fixed an issue where, after selecting a PAN-OS release to upgrade to in **Device Association > To SW Version**, the upgrade failed after connecting to Panorama.
|
||||
|
||||
## PAN-160254
|
||||
|
||||
Fixed a memory leak issue related to a process (reportd) where memory was not freed after an ElasticSearch request.
|
||||
|
||||
## PAN-160253
|
||||
|
||||
Fixed an issue where only one medium-severity system log was generated if either the EDL file wasn't updated at the remote end or the downloaded file wasn't a text file.
|
||||
|
||||
## PAN-160247
|
||||
|
||||
Fixed an issue where system logs incorrectly displayed as **Critical**.
|
||||
|
||||
## PAN-160238
|
||||
|
||||
Fixed an issue where intermittent virtual extensible LAN (VXLAN) packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
|
||||
|
||||
## PAN-160150
|
||||
|
||||
Fixed an intermittent issue where, when a race condition occurred, a process (rasmgr) stopped responding, which caused GlobalProtect user authentication failure.
|
||||
|
||||
## PAN-160053
|
||||
|
||||
Fixed an issue in Panorama where a process (configd) stopped responding due to a race condition in the mongodb process.
|
||||
|
||||
## PAN-159973
|
||||
|
||||
Fixed an issue where a local commit in the Panorama management server caused the status to get out of sync on the managed WildFire appliance.
|
||||
|
||||
## PAN-159700
|
||||
|
||||
Fixed an issue where importing PAN-TRAPS.my to the SNMP manager caused the following error to display: Registration failed, registration failed, because there are unreferenced definition names in the MIB file.
|
||||
|
||||
## PAN-159592
|
||||
|
||||
Fixed an issue where a Japanese keyword search displayed garbled characters during SAML authentication.
|
||||
|
||||
## PAN-159536
|
||||
|
||||
Fixed an issue where, when the CLI command oscp-exclude-nonce-yes was enabled for a certificate profile, a nonce value was still included in the Online Certificate Status Protocol (OCSP) request.
|
||||
|
||||
## PAN-159499
|
||||
|
||||
Fixed an issue where you were unable to select the configured QoS profile under the template stack.
|
||||
|
||||
## PAN-159293
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Certification Revocation List (CRL) in Distinguished Encoding Rules (DER) format incorrectly returned errors despite being able to successfully pull the CRL to verify that the syslog server certificate was still valid.
|
||||
|
||||
## PAN-159224
|
||||
|
||||
Fixed an memory leak issue related to a process (mgmtsrvr), which was caused by a certificate loading operation.
|
||||
|
||||
## PAN-159214
|
||||
|
||||
Fixed an issue where a .txt file was corrupted, which caused the web interface to not display the requested information.
|
||||
|
||||
## PAN-159122
|
||||
|
||||
Fixed an issue where, when a new tag was created, a custom application with the same name was also created.
|
||||
|
||||
## PAN-158932
|
||||
|
||||
Fixed an issue where an increase was observed on spyware_state, which caused latency.
|
||||
|
||||
## PAN-158654
|
||||
|
||||
Fixed a memory leak issue in the management server process.
|
||||
|
||||
## PAN-158649
|
||||
|
||||
Fixed an issue where commits to the Prisma Access Remote networks from Panorama were failing when the management server on the cloud firewall failed to exit cleanly and reported the following error: pan_check_cert_status(pan_crl_ocsp.c:284): sysd write failed (TIMEOUT)
|
||||
|
||||
## PAN-158639
|
||||
|
||||
Fixed an issue on Panorama where logs that were forwarded to a collector group did not appear, and the log collector displayed the following error message: es.init-status not ready in logjobq.
|
||||
|
||||
## PAN-158450
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, for SNMPv2-MIB:sysServices, snmpwalk returned the following error message: No Such Instance currently exists at this OID.
|
||||
|
||||
## PAN-158372
|
||||
|
||||
Fixed a buffer overflow issue related to the useridd process.
|
||||
|
||||
## PAN-158337
|
||||
|
||||
Fixed an issue where warnings displayed during a commit or validate when BGP peers used in an import/export rule were disabled.
|
||||
|
||||
## PAN-158161
|
||||
|
||||
Fixed an issue where the policy-based forwarding (PBF) monitor was failing on the tunnel interface when QoS was enabled.
|
||||
|
||||
## PAN-158119
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where TFTP traffic with a high packet rate was not offloaded even after hitting an application override policy with a custom application.
|
||||
|
||||
## PAN-158020
|
||||
|
||||
Fixed an issue where HIP reports were not visible on the web interface due to a domain override configuration.
|
||||
|
||||
## PAN-157938
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls with multiple DHCP interfaces only
|
||||
```
|
||||
|
||||
Fixed an issue where leases renewed more quickly than needed, which caused unnecessary SPF recalculations.
|
||||
|
||||
## PAN-157908
|
||||
|
||||
Fixed an issue where false system alarms for the IP tag log database exceeded the alarm threshold value.
|
||||
|
||||
## PAN-157903
|
||||
|
||||
Fixed an issue where the **To** field of an email was truncated in threat logs when the field of the original email exceeded 512 bytes.
|
||||
|
||||
## PAN-157835
|
||||
|
||||
Fixed an issue where DNS Proxy rules that contained uppercase characters were not normalized to lowercase, which prevented the rules from being matched.
|
||||
|
||||
## PAN-157715
|
||||
|
||||
Fixed an intermittent issue where SMB file transfer operations failed due to packet drops that were caused by the Content and Threat Detection (CTD) queue filling up quickly. This fix introduces a new CLI command which, when enabled, prevents these failures: set system setting ctd nonblocking-pattern-match-qsizecheck [enable|disable].
|
||||
|
||||
## PAN-157632
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped GTP-U traffic with the message TEID=0x00000000.
|
||||
|
||||
## PAN-157570
|
||||
|
||||
Fixed an issue where device deployment from Panorama to the firewalls failed with the error message Failed to get DLSRVR client key. This issue occurred only on firewalls where the request system-private-data-reset CLI command had been issued in the past.
|
||||
|
||||
## PAN-157518
|
||||
|
||||
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
|
||||
|
||||
## PAN-157472
|
||||
|
||||
```caveat
|
||||
PA_5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, after a factory reset, the firewall displayed the following error message: data_plane_X: Exited 1 times, must be manually recovered..
|
||||
|
||||
## PAN-157213
|
||||
|
||||
```caveat
|
||||
ZTP firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall failed to connect to Panorama when Zero Touch Provisioning (ZTP) was disabled.
|
||||
|
||||
## PAN-157074
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding, which caused corruption.
|
||||
|
||||
## PAN-157035
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
|
||||
|
||||
## PAN-157027
|
||||
|
||||
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
|
||||
|
||||
## PAN-157026
|
||||
|
||||
Fixed an issue where the firewall did not display unified logs.
|
||||
|
||||
## PAN-156552
|
||||
|
||||
Fixed a discrepancy in Panorama between application usage data and the application name in the **ACC** tab.
|
||||
|
||||
## PAN-156393
|
||||
|
||||
Fixed an issue where NetFlow updates were sent without honoring the configured active timeout value.
|
||||
|
||||
## PAN-156388
|
||||
|
||||
Fixed an issue where a process (useridd) stopped responding while attempting to remove all HIP reports on the disk.
|
||||
|
||||
## PAN-155903
|
||||
|
||||
Fixed an issue where zone protection and spoofed IP address protection didn't properly drop unroutable packets.
|
||||
|
||||
## PAN-155659
|
||||
|
||||
Fixed an issue where individual users were unable to populate the **allowed user/user group** field when configuring the GlobalProtect Clientless VPN.
|
||||
|
||||
## PAN-155657
|
||||
|
||||
Fixed an issue where the default log level for mprelay was set to INFO and caused commits to stop working on VM-Series firewalls in AWS using EBS backed volumes when route monitor was configured.
|
||||
|
||||
## PAN-154905
|
||||
|
||||
```caveat
|
||||
Panorama appliances on PAN-OS 10.0 releases only
|
||||
```
|
||||
|
||||
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
|
||||
|
||||
## PAN-154526
|
||||
|
||||
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
|
||||
|
||||
## PAN-154441
|
||||
|
||||
Fixed an issue where the Radius EAP authentication stopped working and the authd process restarted.
|
||||
|
||||
## PAN-154433
|
||||
|
||||
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
|
||||
|
||||
## PAN-154362
|
||||
|
||||
Fixed an issue where Panorama failed to push dynamic user groups to the managed firewalls.
|
||||
|
||||
## PAN-154334
|
||||
|
||||
Fixed an issue where the inactivity logout timeout did not reflect on the GlobalProtect mapping timeout.
|
||||
|
||||
## PAN-153288
|
||||
|
||||
Fixed an issue where the software QoS shaping queue processing was not properly applied on multicast traffic.
|
||||
|
||||
## PAN-151751
|
||||
|
||||
Fixed an issue where GlobalProtect logs did not populate on the destination syslog server in Log Event Extended Format (LEEF) and common event format (CEF).
|
||||
|
||||
## PAN-151273
|
||||
|
||||
Fixed an issue where the commit event was not recorded in the config logs during a **Commit and Push** on the Panorama management server.
|
||||
|
||||
## PAN-150530
|
||||
|
||||
Fixed an issue in the External Dynamic List (EDL) where printed log messages repeated until the end of the description field.
|
||||
|
||||
## PAN-150388
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding when viewing logs in the web interface.
|
||||
|
||||
## PAN-150080
|
||||
|
||||
Fixed an issue where, even when tunnel interface was set to **down**, the following alert displayed: Tunnel GRE_Tunnels is going down(critical).
|
||||
|
||||
## PAN-147736
|
||||
|
||||
Fixed an issue on the firewall web interface where the Cortex Data Lake **Logging Service Status** pop-up window did not show correct information.
|
||||
|
||||
## PAN-146250
|
||||
|
||||
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
|
||||
|
||||
## PAN-144305
|
||||
|
||||
Fixed an issue where merged configurations were unable to be exported from Panorama-managed firewalls using the PAN-OS XML API.
|
||||
|
||||
## PAN-144057
|
||||
|
||||
Fixed a rare issue where, when aggregate ethernet (AE) groups were deleted and re-added, the AE interface no longer had an SDB node to send link the location to. As a result, the dataplane was unable to identify a connected route for the interface address.
|
||||
|
||||
## PAN-141494
|
||||
|
||||
Fixed an issue with the group-mapping mode credential detection feature that failed to block users when logging in using corporate credentials.
|
||||
|
||||
## PAN-138727
|
||||
|
||||
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
|
||||
|
||||
## PAN-138134
|
||||
|
||||
Fixed an issue on Panorama where a template configuration push was blocked when the managed firewall did not have a plugin referenced in the template configuration.
|
||||
|
||||
## PAN-138066
|
||||
|
||||
Fixed an issue where an incorrect Certificate Authority (CA) was used for communicating to the Zero Touch Provisioning (ZTP) service.
|
||||
|
||||
## PAN-116515
|
||||
|
||||
Fixed an issue where IKE Gateway configurations with different crypto profiles on the same IP address with dynamic peers failed with the following error message: IKEv1 gateway should use the same crypto profiles configured on the same interface or local IP address.
|
||||
|
||||
With this fix, you are able to configure IKE Gateways with different crypto profiles on the same IP address with dynamic peers when IKEv1 auto mode is applied.
|
||||
|
||||
## PAN-113093
|
||||
|
||||
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.8-h10
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-202450
|
||||
|
||||
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-198372
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-193004
|
||||
|
||||
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.8-h11
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-237876
|
||||
|
||||
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||
|
||||
## PAN-215576
|
||||
|
||||
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.8-h4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-178283
|
||||
|
||||
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
|
||||
|
||||
## PAN-177762
|
||||
|
||||
Fixed an issue where wificlient in PAN-OS 10.0 and later releases caused processing delays, on-chip descriptor spikes, and buffer usage.
|
||||
|
||||
## PAN-174244
|
||||
|
||||
Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall.
|
||||
|
||||
## PAN-173469
|
||||
|
||||
Fixed an intermittent issue where websites were blocked and categorized as not resolved.
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 10.0.8-h8
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-184592
|
||||
|
||||
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
|
||||
|
||||
## PAN-183767
|
||||
|
||||
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
|
||||
Reference in New Issue
Block a user