Add 10.0 issue data

This commit is contained in:
2026-03-20 15:49:32 -05:00
parent 81ab70ba0f
commit 02a1965aef
21 changed files with 6092 additions and 0 deletions
@@ -0,0 +1,223 @@
---
type: Addressed
product: PAN-OS
version: 10.0.10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-190175
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
## PAN-190223
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
## PAN-189665
```caveat
FIPS-CC enabled firewalls only
```
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
## PAN-185616
Fixed an issue where the firewall sent fewer logs to the system log server than expected. With this fix, the firewall accommodates a larger send queue for syslog forwarding to TCP syslog receivers.
## PAN-185163
Fixed an issue where the distributord process hit the FD limit, which caused User-ID redistribution to not function properly.
## PAN-184693
Fixed an issue that caused the slotd process to stop responding due to an incorrect response from etcd lock API.
## PAN-183862
Fixed an issue where, after a CN-NGFW pod failed-over to the second CN-MGMT pod, the configuration was not synchronized between the new CN-MGMT pod and the CN-NGFW pod.
## PAN-183774
Fixed an memory leak issue in the mgmtsrvr process, which resulted in an out-of-memory (OOM) condition and high availability (HA) failover.
## PAN-183239
Fixed an issue where the firewall randomly disconnected from the WildFire URL cloud.
## PAN-182903
Fixed an issue where SD-WAN failover on a hub or branch in full mesh took longer than expected.
## PAN-181839
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
## PAN-181039
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
## PAN-181031
Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod eventually consumed a large amount of space in the /var/log/pan because the old registered stale next-generation firewall logs were not being cleared.
## PAN-180916
Fixed an issue where DNS security caused the TTL (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
## PAN-179982
Fixed an issue where an OOM condition occurred due to quarantine list redistribution.
## PAN-179976
Fixed an issue where the WildFire Inline Machine Learning (ML) did not detect mlav-test-pe-file.exe when traffic was decrypted.
## PAN-179703
Fixed an issue where dataplane interfaces weren't released when the secured application pods were deleted.
## PAN-179413
Fixed an issue where GRE tunnels flapped during commit jobs.
## PAN-179321
A validation error was added to inform an administrator when a policy field contained the value **any**.
## PAN-179274
Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the HA1 and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet.
## PAN-179164
Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run.
## PAN-179059
Fixed an issue where you were unable to delete dynamic address groups one at a time using XML API.
## PAN-178947
Fixed an issue where the useridd process stopped responding when a NULL reference attempted to be dereferenced. This issue occurred to IP address users being added.
## PAN-177907
Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy.
## PAN-177878
Fixed an issue where a role-based admin with **Operational Requests** enabled under the XML API section was unable to set the License Deactivation API key.
## PAN-177626
Fixed an issue where aggressive situations caused on-chip descriptor exhaustion.
## PAN-177551
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
## PAN-177187
Fixed an issue where reports using the decryption summary database and Panorama as data sources returned no results.
## PAN-177170
Fixed an issue on Panorama where a log collector group commit deleted the proxy settings configured on dedicated log collectors.
## PAN-176889
Fixed an issue where the log collector continuously disconnected from Panorama due to high latency and a high number of packets in Send-Q.
## PAN-176703
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
## PAN-176348
Fixed an issue where scheduled email alerts were not forwarded to all recipients in the override list.
## PAN-175716
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
## PAN-175628
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP.
## PAN-175259
Fixed an issue where a Security policy configured with App-ID and set to **web-browsing** and **application-default service** allowed clear-text web-browsing on tcp/443.
## PAN-175161
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
## PAN-174809
Fixed an issue where a process (all_pktproc) restarted.
## PAN-174607
Fixed an intermittent issue where, when Security profiles were attached to a policy, files that were downloaded across TLS sessions decrypted by the firewall were malformed.
## PAN-174587
Fixed an issue where, in the case of multiple AWS Partner Network (APN) connections, the GPRS tunneling protocol (GTPv2) Create Session Requests were sent to the firewall within a short interval, which caused the firewall to create the GTP-sessions incorrectly.
## PAN-174011
Fixed an issue where Panorama failed to update shared policies during partial commits when a new device group was created but not yet committed.
## PAN-171345
Fixed an issue where firewalls experienced high packet descriptor usage due to internal communication associated with WildFire.
## PAN-171181
Fixed an issue where the IPSec tunnel configuration didn't load when a double quotation mark was added to the comment section of the IPSec tunnel **General** tab.
## PAN-171104
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
## PAN-170952
Fixed script issues that caused diagnostic data to not be collected after path monitor failure.
## PAN-168400
Fixed an issue where, after installing Cloud Services plugin 10.2, the **Plugin cloud_services** status (**Dashboard > High Availability**) displayed as **Mismatch**.
## PAN-168286
Fixed a memory leak issue in the mgmtsrvr process that was caused by failed commit all operations.
## PAN-167849
Fixed an issue where URL Filtering incorrectly identified the firewall serial number in the certificate **Common Name** field as the IP address.
## PAN-164871
```caveat
VM-Series firewalls only
```
Fixed an intermittent issue where deactivating the firewall via XML API using manual mode failed. This occurred because the size of the license token file was incorrect.
## PAN-163245
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
## PAN-161297
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
## PAN-155448
Fixed an issue where credential detection didn't work in IP address-to-username mapping mode because the firewall compared the unnormalized IP-address-to-username mapping format to the normalized username extracted from the payload where the username and password were submitted.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 10.0.11-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-192999
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 10.0.11-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-193004
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.0.11-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,23 @@
---
type: Addressed
product: PAN-OS
version: 10.0.12-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-239241
Extended the root certificate for WildFire appliances to December 31, 2032.
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,167 @@
---
type: Addressed
product: PAN-OS
version: 10.0.4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-161613
Fixed an issue where the **Dashboard** incorrectly displayed the Log Forwarding Card (LFC) port status.
## PAN-161121
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
## PAN-160974
Fixed an issue on Panorama where, if **Source Address Exclusion** **(Network > Zone Protection > Reconnaissance Protection**) was configured, **Flood Protection** was disabled.
## PAN-160376
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
## PAN-160163
Fixed an issue where icons in the left sidebar had multiple layers.
## PAN-159856
Fixed an issue where, when a factory reset was performed on a Panorama appliance with PAN-OS 10.0, the appliance repeatedly rebooted.
## PAN-159850
Fixed an issue where syslog server monitoring stopped working when the first tuple in regex matching was always a whole string.
## PAN-159826
Fixed an issue where SSL VPN leaked when the default browser feature on GlobalProtect was not enabled.
## PAN-159508
Fixed an IPSec tunnel memory leak issue where IPSec tunnels failed during rekey.
## PAN-158988
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
## PAN-158650
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
## PAN-158461
Fixed an issue where editing an application filter object caused excluded applications to be included.
## PAN-157885
Fixed an issue where you could not prioritize the tunnel preference for your branches and hubs in SD-WAN full mesh VPN clusters.
## PAN-157620
```caveat
VM-Series firewalls deployed in Amazon Web Services (AWS) instance types M5 and C5 only
```
Fixed an issue where a Panorama Virtual Appliance in a high availability (HA) configuration entered a suspended state due to a virtual machine (VM) memory size mismatch.
## PAN-157319
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where GlobalProtect logs showed the incorrect client version and did not show event ID information.
## PAN-156728
Fixed an issue where GlobalProtect user traffic did not correctly match Security policy rules that had host information profile (HIP) objects and profiles.
## PAN-156549
Fixed an issue where the download link was omitted on scheduled email reports for SaaS application usage.
## PAN-156240
A fix was made to address an issue where a cryptographically weak pseudo-random number generator (PRNG) was used during authentication to the PAN-OS web interface to enable an attacker to observe their own authenticated secrets on the firewall over a long duration, which enabled them to impersonate another authenticated web interface administrators session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
## PAN-156115
Fixed an issue where, if the firewall had the standard support license, the **License** tab did not display the license details after an upgrade to PAN-OS 10.0.1.
## PAN-155824
Fixed a rare issue where Open Shortest Path First (OSPF) links flapped.
## PAN-155672
Fixed an issue where inserting or removing copper and optic modules in PAN-OS 10.0.1 caused a process (brdagent) to stop responding.
## PAN-154365
Fixed an issue where Security policy rules targeted by tags incorrectly displayed as deleted when previewing commit changes.
## PAN-154323
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
## PAN-154208
Fixed an issue where the **Device** icon was not displayed (**Policies > Security > Name > Source > Source Device > Add** or **Policies > Security > Name > Destination > Destination Device > Add**).
## PAN-154190
Fixed an issue where Data Loss Prevention (DLP) did not support the upload of Office Open XML (OOXML) files generated from Google suite applications such as Google Docs, Slides, and Sheets.
## PAN-153705
Fixed an issue where packets were not evenly distributed among a process (pan_tasks), which caused latency and poor performance.
## PAN-153547
Fixed an issue where the login banner size increased.
## PAN-151997
Fixed an issue where the option to sinkhole was not displayed in the ACC filter drop-down (**ACC > Threat Activity > Global filters > Action**).
## PAN-151872
Fixed an issue where MAC addresses containing certain characters in sequential order caused an issue with TCP connections
## PAN-151803
Fixed an issue on Panorama where commits failed when using device-id as a template variable.
## PAN-151458
Fixed an issue on firewalls with HA active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
## PAN-150968
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
## PAN-147792
Fixed an issue where a process (configd) stopped responding due to a buffer overflow.
## PAN-147221
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
## PAN-145417
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
## PAN-134461
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
## PAN-133863
Fixed an issue where the Panorama Virtual Appliance in Log Collector mode went into maintenance mode due to a process (reportd) not responding.
## PAN-122281
An error check process (mcelog) was added to capture hardware failure reasons detected by the processor.
@@ -0,0 +1,333 @@
---
type: Addressed
product: PAN-OS
version: 10.0.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-164922
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
## PAN-164674
Fixed a memory leak issue related to a process (mprelay) that was caused by ARP and route entries not being freed after skipping duplicate updates.
## PAN-163538
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
## PAN-163503
Fixed an issue on the passive firewall in a high availability (HA) configuration where a SD-WAN virtual network interface (VIF) status check caused associated static routes to be incorrectly withdrawn from the FIB.
## PAN-163489
Fixed an issue where an SD-WAN VIF was incorrectly detected as inactive during the commit time, which caused associated route withdrawal.
## PAN-163415
Fixed an issue where a memory leak related to the configd process occurred if the SD-WAN plugin was installed and many templates were configured on Panorama.
## PAN-163274
Fixed an issue where the SD-WAN hub firewall sent traffic via a VPN tunnel interface that was inactive.
## PAN-162746
Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory.
## PAN-162743
Fixed an issue where the firewall did not receive updates for the Device Dictionary, which caused the firewall to replace new attributes in the IP address-to-device mappings with unknown.
## PAN-162534
```caveat
VM-Series firewalls on Amazon Web Services (AWS) using a Gateway Load Balancer (GWLB) only
```
Fixed an issue where when the VM-Series firewall on AWS is integrated with a GWLB, GlobalProtect did not work.
## PAN-162256
Fixed an issue where incorrect WildFire verdicts displayed on Panorama from Cortex Data Lake.
## PAN-162059
Fixed an issue where, after a new Layer 3 interface was created in PAN-OS 10.0.3 or 10.0.4, a downgrade to a PAN-OS 9.0 version failed with the error message U pstream NAT not supported in older version. This issue occurred whether SD-WAN was configured on the firewall or not.
## PAN-161767
Fixed an issue where, due to a dataplane sync issue, SD-WAN traffic was forwarded to a tunnel that was inactive.
## PAN-161745
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
## PAN-161562
Enhanced security in how Palo Alto Networks next-generation VM-Series and PA-Series firewalls handle asymmetric traffic.
## PAN-161428
Fixed an issue where multiple restarts on a process (all_pktproc) occurred on firewalls in an active/passive HA configuration.
## PAN-160782
Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix.
## PAN-160556
Fixed an issue that prevented decryption and IP-tag logs from being forwarded to the syslog over TCP.
## PAN-160499
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, configuration pushes failed with the error Need to config WMI account and password for querying Microsoft directory servers.
## PAN-160455
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
## PAN-159692
Fixed an issue where the **/dev/shm** partition increased to 100% disk usage with multiple older versions of WildFire content updates.
## PAN-159393
Fixed an issue where some TSL1.3 websites were not accessible when decryption was enabled.
## PAN-159135
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
## PAN-158844
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
## PAN-158774
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
## PAN-158723
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
## PAN-158638
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
## PAN-158585
Fixed a memory leak issue related to the X-Forwarded-For (XFF) security feature.
## PAN-158328
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
## PAN-158293
Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic.
## PAN-158122
Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
## PAN-157735
Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis.
## PAN-157721
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
## PAN-157346
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
## PAN-157271
Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled.
## PAN-157266
Fixed an issue with the logrcvr process that caused inaccurate netflow values.
## PAN-157168
Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands
## PAN-157049
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
## PAN-156982
Fixed an issue where the firewall didn't resolve domain names with multiple nested Canonical Name (CNAME) records when caching was enabled.
## PAN-156891
Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable.
## PAN-156716
Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address.
## PAN-156498
Fixed an issue where the User-ID Agent did not reconnect after being disconnected.
## PAN-156264
Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI.
## PAN-156225
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to PAN-OS 9.1.5.
## PAN-155656
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
## PAN-155294
Fixed an issue where iPad devices did not display Authentication Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
## PAN-154899
Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages.
## PAN-154844
Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr.
## PAN-154812
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
## PAN-154376
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-154195
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
## PAN-154145
```caveat
VM-Series firewalls only
```
Fixed an issue where the management plane CPU was incorrectly reported to be high.
## PAN-153614
Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format.
## PAN-153213
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
## PAN-152998
Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected.
## PAN-152813
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
## PAN-152458
```caveat
VM-Series firewalls on Microsoft Hyper-V only
```
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
## PAN-151808
Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates.
## PAN-151218
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the `crashinfo` file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot.
## PAN-150867
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
## PAN-150798
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
## PAN-150023
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
## PAN-148549
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
## PAN-147783
Checks were added to help prevent the dataplane from restarting.
## PAN-147228
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
## PAN-144538
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
## PAN-144470
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
## PAN-142473
Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue.
## PAN-136478
```caveat
PA-7000 Series firewalls
```
where syslog forwarding over TCP did not work in a multi-vsys environment.
## PAN-136347
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
## PAN-134799
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
## PAN-129927
```caveat
VM-Series firewalls only
```
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
@@ -0,0 +1,319 @@
---
type: Addressed
product: PAN-OS
version: 10.0.6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-168298
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
## PAN-167401
Fixed an issue where, when a firewall or Panorama appliance configured with a proxy was upgraded to PAN-OS 10.0.3 or a later release, it failed to connect to edge service.
## PAN-166994
Fixed an issue where the management failed to publish custom metrics to cloud monitoring tools, which caused pod auto-scaling to not work.
## PAN-166677
Fixed an issue on the firewall where a process (devsrvr) stopped responding during a commit.
## PAN-166570
Fixed an issue where authentication failure messages were overwritten when a commit was in progress.
## PAN-166306
Fixed an issue where commit jobs failed when validating HIP objects and profiles.
## PAN-166241
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
## PAN-165194
Fixed an issue where multiple messages were exchanged between secondary and primary Data Plane Development Kit (DPDK) processes, which caused a process (brdagent) to stop responding.
## PAN-164846
Fixed an issue where packet buffers were depleted.
## PAN-164564
Fixed an issue where stats API attempted to get stats from an unavailable port.
## PAN-164328
Fixed an issue where the firewall incorrectly dropped GPRS tunneling protocol (GTPv2) Bearer Resource Failure Indication messages with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
## PAN-164094
Fixed an issue where two process (devsrvr and useridd) did not synchronize IP tags, which caused Dynamic Address Groups to not populate.
## PAN-163261
Fixed an intermittent issue where the firewall dropped GTPv2 Modify Bearer Request packets with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
## PAN-162663
Fixed an intermittent issue on the firewall where packets dropped in decrypted SSL/TLS sessions.
## PAN-162594
Fixed an issue where blank configuration for tokens in a content-driven FreeDNS Afraid.org Dynamic API v1 DDNS configuration were not enabled.
## PAN-161499
Fixed an issue where, after an upgrade from PAN-OS 9.1.5 to PAN-OS 10.0.3, Panorama admin sessions were created with 30 days to expire on the firewalls.
## PAN-161112
Fixed an issue where a process (useridd) repeatedly exceeded the virtual memory limit, which caused the process to stop responding.
## PAN-160939
Fixed an issue where the firewall dropped GTPv1 Forward Relocation Requests with the following error message: Abnormal GTP-U message with invalid IE.
## PAN-160870
```caveat
ZTP-capable firewalls only
```
Fixed an issue where the default Zero Touch Provisioning (ZTP) configuration was still present on the firewall even when ZTP was disabled, which caused commit failures.
## PAN-160744
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
## PAN-160434
Fixed an issue where firewalls stopped processing Layer-3-tagged traffic after Panorama pushed VLAN sub-interface configurations to the firewall with the **commit_all** operation.
## PAN-159944
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
## PAN-159936
Fixed an issue where BGP route stopped advertising a redistribute route when a similar new redistribute route was configured.
## PAN-159054
Fixed an issue where you were unable to add more than 500 DHCP relay agent objects in the firewall templates from Panorama.
## PAN-158972
Fixed an issue on the firewall where a process (useridd) stopped responding and generated a core dump after being restarted by the administrator.
## PAN-158407
Fixed an issue where configuring the BGP export policy with the match criteria set to next hops, redistributed connected routes incorrectly matched this criteria.
## PAN-158262
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
## PAN-158036
Fixed an issue on the firewall where custom application signatures based on PROPFIND http-method didn't trigger if webdav application ID was blocked by a Security policy.
Note: To utilize this fix, you must install content version 8367-6513 or later.
## PAN-157964
Fixed an issue where adding a container application from the **Apps Seen** list did not remove the child application from the list.
## PAN-157834
Fixed an issue with missing zone entries in CSV or PDF export files.
## PAN-157479
Fixed an issue on the firewall where a process (useridd) stopped responding when group-mapping profiles were configured with an LDAP server profile with the type **e-dictionary**.
## PAN-157447
Fixed an issue where a process (flow_mgmt) repeatedly restarted with a segmentation violation (SIGSEGV) signal and the following trace: flow_mgmt:pan_flow_dos_ager_invoke pan_sw_timer_100ms pan_sw_timer_invoke.
## PAN-157311
Fixed an issue where, if the **OK** button is clicked before tags are loaded when editing an address object that contained tags via the firewall web interface, associated tags are removed.
## PAN-157238
Fixed an issue where, when a non-SAML authentication policy was used, the SAML **Use Single Sign-On** option was displayed.
## PAN-157136
Fixed an issue where a memory leak associated with a process (pan_dha) caused an OOM condition on the firewall due to a configuration sync triggered by a commit on an HA cluster.
## PAN-156896
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall frequently stopped responding with the following log: CONFIG_UPDATE_INC : Incremental update to DP failed please try to commit force the latest config.
## PAN-156669
Fixed an issue in Panorama where, when a variable object description was set, the description was automatically copied to template description.
## PAN-156396
Fixed an issue where the CTD queue was full, which caused traffic to be dropped with the counter ctd_exceed_pkt_limit.
## PAN-156380
Fixed an issue where running show commands related to SD-WAN caused a process (pan_comm) to stop responding.
## PAN-156199
Fixed an issue where, in the **Email Scheduler** (**Monitor > PDF Reports**), the **Recurrence** parameter unexpectedly changed from **Daily** to **Disable** when the web interface language was not English.
## PAN-156113
Fixed an issue where the management interface incorrectly used the configured default gateway for local network traffic when service routes were configured.
## PAN-156098
Fixed an issue where netflow packets sent from the firewall contained excess padding, which resulted in the packet length exceeding 1400 bytes.
## PAN-156001
Fixed an issue where the downloaded GTP event packet capture from **Monitor > Logs > GTP** displayed a different packet than the one that actually triggered the event.
## PAN-155772
Fixed an issue where the Panorama web interface did not display the secondary IP address configuring it under the template stack.
## PAN-155758
```caveat
7000-Series firewalls only
```
Fixed an issue where, when a subinterface was configured as a Log Card interface, the commit failed unless an IP address was assigned to the parent interface.
## PAN-155593
Fixed an issue where the firewall was unable to match HIP objects with a 3-digit code version.
## PAN-155457
Fixed an issue where PAN-OS custom logos were not uploaded due to the upper case file extensions.
## PAN-155147
```caveat
VM-Series firewalls on Microsoft Azure that use accelerated networking interfaces with DPDK mode
```
Fixed an issue where hot plug notifications caused traffic disruption.
## PAN-155126
Fixed an issue where editing the LDAP server IP address (**Device > Templates > Server Profiles > LDAP > LDAP Server Profile**) removed the bind password.
## PAN-155049
Fixed an issue with SSLVPN memory leaks related to the GlobalProtect portal **Config Selection Criteria**.
## PAN-154820
Fixed an issue where policy-based forwarding (PBF) monitoring failed when the egress interface was a tunnel.
## PAN-154603
Fixed an issue where, when SSL/TLS was required, LDAP server authentication attempted StartTLS first.
## PAN-154602
Fixed an issue where GlobalProtect users got disconnected after modifying floating IP HA configuration.
## PAN-154571
Fixed an issue where, if source-ip-enforcement.enable was true, GlobalProtect configurations on the template stack level were unable to be modified, and the schema used the default choice.
## PAN-154557
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
## PAN-154487
Fixed an issue where the GlobalProtect log description field size decreased.
## PAN-154403
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
## PAN-154109
Fixed an issue where using XML special characters in the **Uninstalled GlobalProtect APP** password in the application configuration (**Networks > GlobalProtect > Portals > Agent > App**) disrupted portal connectivity.
## PAN-153816
Fixed an issue where the firewall booted up in Extensible Firmware Interface (EFI) Shell when performing factory reset with selected image file.
## PAN-153592
Fixed an issue where, after upgrading Panorama from PAN-OS 8.1.9 to PAN-OS 9.1.3, the option to preview changes for dynamic address groups or templates from Panorama did not work.
## PAN-153316
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit. -To disable the virtual memory limit, use debug software disable-virt-limit. -To enable the virtual memory limit, use debug software enable-virt-limit.
## PAN-152497
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
## PAN-151521
Fixed an issue where a process (logrcvr) continuously restarted at pan_hash_iter_next_i.
## PAN-151395
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
## PAN-150298
Fixed an issue where Android clients matched HIP objects configured for Apple products.
## PAN-149867
Fixed an issue where a process (authd) ignored null domain authentication profiles in a sequence and only returned non-null domains to GlobalProtect.
## PAN-149853
Fixed an issue on Panorama where the **loc** attribute was not set as **shared** when creating dynamic-address-group-specific configurations during a Panorama commit.
## PAN-147827
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
## PAN-147081
Fixed an issue where routes learned from the GlobalProtect Large Scale VPN (LSVPN) Gateway were cleared from the routing table when ECMP was toggled (enabled or disabled).
## PAN-146048
Fixed an issue where a satellite firewall was unable to authenticate to a LSVPN gateway when the issued certificate from Simple Certificate Enrollment Protocol (SCEP) had encryption bits set to 3072. With this fix, the maximum private key size of 3072 bits, along with the 1024-bit size and the 2048-bit size, is able to authenticate when selected to create the SCEP profile.
## PAN-142621
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
## PAN-140243
Fixed an issue where non-web-based traffic that was part of the User-ID zone exclude list still matched the configured authentication policy.
## PAN-134007
Fixed an issue where the Log Forwarding Card (LFC) advertised the wrong MAC Address to the connected switch.
@@ -0,0 +1,587 @@
---
type: Addressed
product: PAN-OS
version: 10.0.7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5568
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
## WF500-5559
Fixed an issue where an intermittent error while analyzing signed PE samples on the WildFire appliance might have caused analysis failures.
## WF500-5509
```caveat
WF-500 appliance only
```
Fixed an issue where cloud inquiries were logged under the **SD-WAN** subtype.
## PAN-173080
Fixed an issue where the User-ID connection limit was reached even when only a few User-ID agents were connected to the service.
## PAN-172518
Fixed an issue where a race condition occurred and caused a process (useridd) to restart.
## PAN-172125
Fixed an intermittent issue where processing HIP messages in the (useridd) process caused a memory leak.
## PAN-171878
Fixed an issue with SD-WAN path selection logic that caused a dataplane to stop responding.
## PAN-171442
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing and cross-zone load balancing enabled where packets were forwarded to the incorrect GWLB interface.
## PAN-171203
Fixed an issue in a high availability (HA) configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
## PAN-170989
Fixed an issue memory usage consumption issue on a process (useridd).
## PAN-170932
Fixed an issue in Telemetry settings where the **OK** button was disabled when **Telemetry Region** was set to **None**.
## PAN-170825
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
## PAN-170740
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
## PAN-170681
Fixed an issue where the data redistribution agent and the data redistribution client failed to connect due to the agent not sending a SSL Server hello response.
## PAN-170610
Fixed an issue where SD-WAN SaaS monitoring traffic was incorrectly dropped by a Security policy that included a deny rule.
## PAN-170314
Fixed an issue where PAN-DB URL cloud updates failed because a process (devsrvr) did not fetch serial numbers, which prevented the PAN_DB URL cloud from connecting after first deployment.
## PAN-170083
Fixed an intermittent issue where packet pointer corruption occurred, which resulted in a dataplane restart.
## PAN-169712
Fixed an intermittent issue where traffic falsely matched a converted Suricata rule.
## PAN-169197
Fixed a rare issue where generating a tech support file caused the useridd process to stop responding.
## PAN-169161
Fixed an issue where, after a pan_comm process restart, the configuration wasn't synced between the management and the dataplane pod.
## PAN-169064
Fixed an issue where the management CPU remained at 100% due to a large number of configured User-ID agents.
## PAN-168888
Fixed an issue where, when a maximum session count was configured, the SD-WAN plugin caused commit failures on Panorama.
## PAN-168718
Fixed an issue where, when a client or server received partial application data, the record was partially processed by legacy code. This caused decryption to fail when a decryption profile protocol was set to a maximum of TLSv1.3.
## PAN-168574
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, a configuration pushed to firewalls running on PAN-OS 9.1 failed during an autocommit with the following error message: Need to config WMI account and password for querying Microsoft directory servers.
## PAN-168418
Fixed an issue where, when an MLAV URL with an exception list was configured and forward proxy was enabled, a process (all_pktproc) repeatedly restarted, which resulted in the firewall rebooting.
## PAN-167989
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
## PAN-167872
Fixed an issue related to a process (all_pktproc) that occurred in long-lived sessions that spanned two content upgrades.
## PAN-167637
Fixed an issue where users connecting to the US East gateway encountered a delay in DNS responses.
## PAN-167541
Fixed an issue where large External Dynamic Lists (EDLs) caused commit issues due to a hard limit being reached.
## PAN-167443
Fixed an issue where commits failed and generated pan_comm SIGSEGV CORE files.
## PAN-167306
```caveat
VM-Series firewalls on Microsoft Azure only
```
Fixed an issue where, when a second disk was added, /opt/panlogs was mounted on an incorrect partition.
## PAN-167099
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
## PAN-167098
Fixed an issue where a configd process memory corruption occurred when Panorama was exposed to multiple XML API calls on Dynamic Address Groups updates.
## PAN-166836
Fixed an issue where session failed due to resource unavailability.
## PAN-166572
Fixed an issue where a process (configd) restarted when browsing policies on Panorama.
## PAN-166420
In 10.0.x Query Traffic log option is missing for Address groups under source and destination in the security policy tab
## PAN-166328
```caveat
PA-7000 Series firewalls with NPCs only
```
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
## PAN-166296
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
## PAN-166021
Fixed an issue where log queries that included a username did not return with any output.
## PAN-165661
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
## PAN-165399
Fixed an issue where the multi-factor authentication (MFA) Challenge message did not display during login when the GlobalProtect portal was accessed by the web browser.
## PAN-165235
Fixed an issue where the handover handling between LTE and 3G on S5 and S8 to Gn/Gp was not working properly and led to stateful inspection failures.
## PAN-165025
Fixed an issue where, when default interzone and intrazone Security policy rules were overwritten, the rules did not display hit counts.
## PAN-164646
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
## PAN-164571
Fixed an issue where DHCP leases were not properly synchronized between HA peers after a device or dhcpd process restart. With this fix, the DHCP lease details display correctly on both the active and the passive device.
## PAN-164446
Fixed an issue on Panorama where a commit failed with the following error message: Local-AS number does not fit in 2-byte AS format, even though the AS format was set to 4 bytes.
## PAN-164431
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall rebooted into maintenance mode after installing a capacity license in FIPS-CC mode.
## PAN-164392
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak related to a process (logrcvr).
## PAN-164338
Fixed an issue where, when using the CLI or API, configurations for policy rule services or applications that either used custom settings and default settings together, or used multiple default settings together, successfully commit instead of failing or displaying a warning.
**Note** To use this fix, you must delete previous application or service settings in the configuration.
## PAN-164056
Fixed a memory issue for Large Scale VPN with multiple dataplane systems.
## PAN-163940
Fixed an issue where the firewall truncated the application name when doing a NetFlow export to the NetFlow analyzer.
## PAN-163800
Fixed an intermittent issue where the presence of an Anti-Spyware profile in a Security policy rule that matched DNS traffic caused DNS responses to be malformed in transit.
## PAN-163280
Fixed an issue where, after upgrading to a PAN-OS 10.0 release version, a commit failed due to an admin-role-related validation error that displayed the following message: device unexpected here.
## PAN-163270
Fixed an issue where the login banner was not aligned properly when it contained multiple sequential whitespaces.
## PAN-162600
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
## PAN-161869
Fixed an issue where a core dump occurred on a process (flow_ctrl) after a commit if a policy-based forwarding (PBF) rule referenced an interface that had a DHCP IP address assignment.
## PAN-161289
Fixed an issue where predict session didn't update the associated rules when Security policies shifted after a commit.
## PAN-161218
The following CLI commands were added to enable the customer to set the dataplane utilization limit. The default setting is the recommended value of 500; a value of 0 removes dataplane CTD limits: -debug dataplane show ctd wildfire max -debug dataplane set ctd wildfire max <0-5000>
## PAN-161025
Fixed an issue in Panorama where an administrator with the role of Panorama administrator did not have the option to download or install GlobalProtect clients (**Panorama > Device Deployment > GlobalProtect**).
## PAN-160997
Fixed an issue where the metadata from the firewall's authentication profile was unable to export. This issue occurred when the authentication profile and the SAML Identity Provider sever profile were created with **VSYS** in the **Location**and were pushed from Panorama template stack values. To utilize this fix, you must upgrade both Panorama and the firewall.
## PAN-160843
Fixed an issue where the Multiprotocol Label Switching (MPLS) interface wasn't monitored when private traffic wasn't VPN encapsulated.
## PAN-160831
Fixed an intermittent issue where importing a new firewalls configuration into Panorama failed due to conflicting virtual system (vsys) names, even when the **Device Group Name Prefix** was used to make the name unique.
## PAN-160818
Fixed an issue where Panorama repeatedly displayed the following error message: HA Failover: updates not received from all sources: Pending plugins.
## PAN-160540
Fixed an issue where tunnel traffic was dropped intermittently when Quality of Service (QoS) Profile was assigned but the profile had no limits defined.
## PAN-160432
Fixed an issue where, after selecting a PAN-OS release to upgrade to in **Device Association > To SW Version**, the upgrade failed after connecting to Panorama.
## PAN-160254
Fixed a memory leak issue related to a process (reportd) where memory was not freed after an ElasticSearch request.
## PAN-160253
Fixed an issue where only one medium-severity system log was generated if either the EDL file wasn't updated at the remote end or the downloaded file wasn't a text file.
## PAN-160247
Fixed an issue where system logs incorrectly displayed as **Critical**.
## PAN-160238
Fixed an issue where intermittent virtual extensible LAN (VXLAN) packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
## PAN-160150
Fixed an intermittent issue where, when a race condition occurred, a process (rasmgr) stopped responding, which caused GlobalProtect user authentication failure.
## PAN-160053
Fixed an issue in Panorama where a process (configd) stopped responding due to a race condition in the mongodb process.
## PAN-159973
Fixed an issue where a local commit in the Panorama management server caused the status to get out of sync on the managed WildFire appliance.
## PAN-159700
Fixed an issue where importing PAN-TRAPS.my to the SNMP manager caused the following error to display: Registration failed, registration failed, because there are unreferenced definition names in the MIB file.
## PAN-159592
Fixed an issue where a Japanese keyword search displayed garbled characters during SAML authentication.
## PAN-159536
Fixed an issue where, when the CLI command oscp-exclude-nonce-yes was enabled for a certificate profile, a nonce value was still included in the Online Certificate Status Protocol (OCSP) request.
## PAN-159499
Fixed an issue where you were unable to select the configured QoS profile under the template stack.
## PAN-159293
```caveat
VM-Series firewalls only
```
Fixed an issue where the Certification Revocation List (CRL) in Distinguished Encoding Rules (DER) format incorrectly returned errors despite being able to successfully pull the CRL to verify that the syslog server certificate was still valid.
## PAN-159224
Fixed an memory leak issue related to a process (mgmtsrvr), which was caused by a certificate loading operation.
## PAN-159214
Fixed an issue where a .txt file was corrupted, which caused the web interface to not display the requested information.
## PAN-159122
Fixed an issue where, when a new tag was created, a custom application with the same name was also created.
## PAN-158932
Fixed an issue where an increase was observed on spyware_state, which caused latency.
## PAN-158654
Fixed a memory leak issue in the management server process.
## PAN-158649
Fixed an issue where commits to the Prisma Access Remote networks from Panorama were failing when the management server on the cloud firewall failed to exit cleanly and reported the following error: pan_check_cert_status(pan_crl_ocsp.c:284): sysd write failed (TIMEOUT)
## PAN-158639
Fixed an issue on Panorama where logs that were forwarded to a collector group did not appear, and the log collector displayed the following error message: es.init-status not ready in logjobq.
## PAN-158450
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where, for SNMPv2-MIB:sysServices, snmpwalk returned the following error message: No Such Instance currently exists at this OID.
## PAN-158372
Fixed a buffer overflow issue related to the useridd process.
## PAN-158337
Fixed an issue where warnings displayed during a commit or validate when BGP peers used in an import/export rule were disabled.
## PAN-158161
Fixed an issue where the policy-based forwarding (PBF) monitor was failing on the tunnel interface when QoS was enabled.
## PAN-158119
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where TFTP traffic with a high packet rate was not offloaded even after hitting an application override policy with a custom application.
## PAN-158020
Fixed an issue where HIP reports were not visible on the web interface due to a domain override configuration.
## PAN-157938
```caveat
VM-Series firewalls with multiple DHCP interfaces only
```
Fixed an issue where leases renewed more quickly than needed, which caused unnecessary SPF recalculations.
## PAN-157908
Fixed an issue where false system alarms for the IP tag log database exceeded the alarm threshold value.
## PAN-157903
Fixed an issue where the **To** field of an email was truncated in threat logs when the field of the original email exceeded 512 bytes.
## PAN-157835
Fixed an issue where DNS Proxy rules that contained uppercase characters were not normalized to lowercase, which prevented the rules from being matched.
## PAN-157715
Fixed an intermittent issue where SMB file transfer operations failed due to packet drops that were caused by the Content and Threat Detection (CTD) queue filling up quickly. This fix introduces a new CLI command which, when enabled, prevents these failures: set system setting ctd nonblocking-pattern-match-qsizecheck [enable|disable].
## PAN-157632
Fixed an intermittent issue where the firewall dropped GTP-U traffic with the message TEID=0x00000000.
## PAN-157570
Fixed an issue where device deployment from Panorama to the firewalls failed with the error message Failed to get DLSRVR client key. This issue occurred only on firewalls where the request system-private-data-reset CLI command had been issued in the past.
## PAN-157518
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
## PAN-157472
```caveat
PA_5200 Series firewalls only
```
Fixed an issue where, after a factory reset, the firewall displayed the following error message: data_plane_X: Exited 1 times, must be manually recovered..
## PAN-157213
```caveat
ZTP firewalls only
```
Fixed an issue where the firewall failed to connect to Panorama when Zero Touch Provisioning (ZTP) was disabled.
## PAN-157074
Fixed an issue where a process (configd) stopped responding, which caused corruption.
## PAN-157035
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
## PAN-157027
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
## PAN-157026
Fixed an issue where the firewall did not display unified logs.
## PAN-156552
Fixed a discrepancy in Panorama between application usage data and the application name in the **ACC** tab.
## PAN-156393
Fixed an issue where NetFlow updates were sent without honoring the configured active timeout value.
## PAN-156388
Fixed an issue where a process (useridd) stopped responding while attempting to remove all HIP reports on the disk.
## PAN-155903
Fixed an issue where zone protection and spoofed IP address protection didn't properly drop unroutable packets.
## PAN-155659
Fixed an issue where individual users were unable to populate the **allowed user/user group** field when configuring the GlobalProtect Clientless VPN.
## PAN-155657
Fixed an issue where the default log level for mprelay was set to INFO and caused commits to stop working on VM-Series firewalls in AWS using EBS backed volumes when route monitor was configured.
## PAN-154905
```caveat
Panorama appliances on PAN-OS 10.0 releases only
```
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
## PAN-154526
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
## PAN-154441
Fixed an issue where the Radius EAP authentication stopped working and the authd process restarted.
## PAN-154433
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
## PAN-154362
Fixed an issue where Panorama failed to push dynamic user groups to the managed firewalls.
## PAN-154334
Fixed an issue where the inactivity logout timeout did not reflect on the GlobalProtect mapping timeout.
## PAN-153288
Fixed an issue where the software QoS shaping queue processing was not properly applied on multicast traffic.
## PAN-151751
Fixed an issue where GlobalProtect logs did not populate on the destination syslog server in Log Event Extended Format (LEEF) and common event format (CEF).
## PAN-151273
Fixed an issue where the commit event was not recorded in the config logs during a **Commit and Push** on the Panorama management server.
## PAN-150530
Fixed an issue in the External Dynamic List (EDL) where printed log messages repeated until the end of the description field.
## PAN-150388
Fixed an issue where a process (mgmtsrvr) stopped responding when viewing logs in the web interface.
## PAN-150080
Fixed an issue where, even when tunnel interface was set to **down**, the following alert displayed: Tunnel GRE_Tunnels is going down(critical).
## PAN-147736
Fixed an issue on the firewall web interface where the Cortex Data Lake **Logging Service Status** pop-up window did not show correct information.
## PAN-146250
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
## PAN-144305
Fixed an issue where merged configurations were unable to be exported from Panorama-managed firewalls using the PAN-OS XML API.
## PAN-144057
Fixed a rare issue where, when aggregate ethernet (AE) groups were deleted and re-added, the AE interface no longer had an SDB node to send link the location to. As a result, the dataplane was unable to identify a connected route for the interface address.
## PAN-141494
Fixed an issue with the group-mapping mode credential detection feature that failed to block users when logging in using corporate credentials.
## PAN-138727
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
## PAN-138134
Fixed an issue on Panorama where a template configuration push was blocked when the managed firewall did not have a plugin referenced in the template configuration.
## PAN-138066
Fixed an issue where an incorrect Certificate Authority (CA) was used for communicating to the Zero Touch Provisioning (ZTP) service.
## PAN-116515
Fixed an issue where IKE Gateway configurations with different crypto profiles on the same IP address with dynamic peers failed with the following error message: IKEv1 gateway should use the same crypto profiles configured on the same interface or local IP address.
With this fix, you are able to configure IKE Gateways with different crypto profiles on the same IP address with dynamic peers when IKEv1 auto mode is applied.
## PAN-113093
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 10.0.8-h10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-193004
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.0.8-h11
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,23 @@
---
type: Addressed
product: PAN-OS
version: 10.0.8-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-178283
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
## PAN-177762
Fixed an issue where wificlient in PAN-OS 10.0 and later releases caused processing delays, on-chip descriptor spikes, and buffer usage.
## PAN-174244
Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall.
## PAN-173469
Fixed an intermittent issue where websites were blocked and categorized as not resolved.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.0.8-h8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-184592
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
## PAN-183767
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.