Add 10.0 issue data

This commit is contained in:
2026-03-20 15:49:32 -05:00
parent 81ab70ba0f
commit 02a1965aef
21 changed files with 6092 additions and 0 deletions
@@ -0,0 +1,333 @@
---
type: Addressed
product: PAN-OS
version: 10.0.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-164922
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
## PAN-164674
Fixed a memory leak issue related to a process (mprelay) that was caused by ARP and route entries not being freed after skipping duplicate updates.
## PAN-163538
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
## PAN-163503
Fixed an issue on the passive firewall in a high availability (HA) configuration where a SD-WAN virtual network interface (VIF) status check caused associated static routes to be incorrectly withdrawn from the FIB.
## PAN-163489
Fixed an issue where an SD-WAN VIF was incorrectly detected as inactive during the commit time, which caused associated route withdrawal.
## PAN-163415
Fixed an issue where a memory leak related to the configd process occurred if the SD-WAN plugin was installed and many templates were configured on Panorama.
## PAN-163274
Fixed an issue where the SD-WAN hub firewall sent traffic via a VPN tunnel interface that was inactive.
## PAN-162746
Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory.
## PAN-162743
Fixed an issue where the firewall did not receive updates for the Device Dictionary, which caused the firewall to replace new attributes in the IP address-to-device mappings with unknown.
## PAN-162534
```caveat
VM-Series firewalls on Amazon Web Services (AWS) using a Gateway Load Balancer (GWLB) only
```
Fixed an issue where when the VM-Series firewall on AWS is integrated with a GWLB, GlobalProtect did not work.
## PAN-162256
Fixed an issue where incorrect WildFire verdicts displayed on Panorama from Cortex Data Lake.
## PAN-162059
Fixed an issue where, after a new Layer 3 interface was created in PAN-OS 10.0.3 or 10.0.4, a downgrade to a PAN-OS 9.0 version failed with the error message U pstream NAT not supported in older version. This issue occurred whether SD-WAN was configured on the firewall or not.
## PAN-161767
Fixed an issue where, due to a dataplane sync issue, SD-WAN traffic was forwarded to a tunnel that was inactive.
## PAN-161745
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
## PAN-161562
Enhanced security in how Palo Alto Networks next-generation VM-Series and PA-Series firewalls handle asymmetric traffic.
## PAN-161428
Fixed an issue where multiple restarts on a process (all_pktproc) occurred on firewalls in an active/passive HA configuration.
## PAN-160782
Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix.
## PAN-160556
Fixed an issue that prevented decryption and IP-tag logs from being forwarded to the syslog over TCP.
## PAN-160499
Fixed an issue on Panorama where, after an upgrade to a PAN-OS 10.0 release version, configuration pushes failed with the error Need to config WMI account and password for querying Microsoft directory servers.
## PAN-160455
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
## PAN-159692
Fixed an issue where the **/dev/shm** partition increased to 100% disk usage with multiple older versions of WildFire content updates.
## PAN-159393
Fixed an issue where some TSL1.3 websites were not accessible when decryption was enabled.
## PAN-159135
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
## PAN-158844
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
## PAN-158774
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
## PAN-158723
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
## PAN-158638
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
## PAN-158585
Fixed a memory leak issue related to the X-Forwarded-For (XFF) security feature.
## PAN-158328
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
## PAN-158293
Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic.
## PAN-158122
Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
## PAN-157735
Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis.
## PAN-157721
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
## PAN-157346
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
## PAN-157271
Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled.
## PAN-157266
Fixed an issue with the logrcvr process that caused inaccurate netflow values.
## PAN-157168
Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands
## PAN-157049
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
## PAN-156982
Fixed an issue where the firewall didn't resolve domain names with multiple nested Canonical Name (CNAME) records when caching was enabled.
## PAN-156891
Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable.
## PAN-156716
Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address.
## PAN-156498
Fixed an issue where the User-ID Agent did not reconnect after being disconnected.
## PAN-156264
Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI.
## PAN-156225
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to PAN-OS 9.1.5.
## PAN-155656
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
## PAN-155294
Fixed an issue where iPad devices did not display Authentication Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
## PAN-154899
Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages.
## PAN-154844
Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr.
## PAN-154812
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
## PAN-154376
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-154195
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
## PAN-154145
```caveat
VM-Series firewalls only
```
Fixed an issue where the management plane CPU was incorrectly reported to be high.
## PAN-153614
Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format.
## PAN-153213
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
## PAN-152998
Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected.
## PAN-152813
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
## PAN-152458
```caveat
VM-Series firewalls on Microsoft Hyper-V only
```
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
## PAN-151808
Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates.
## PAN-151218
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the `crashinfo` file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot.
## PAN-150867
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
## PAN-150798
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
## PAN-150023
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
## PAN-148549
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
## PAN-147783
Checks were added to help prevent the dataplane from restarting.
## PAN-147228
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
## PAN-144538
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
## PAN-144470
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
## PAN-142473
Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue.
## PAN-136478
```caveat
PA-7000 Series firewalls
```
where syslog forwarding over TCP did not work in a multi-vsys environment.
## PAN-136347
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
## PAN-134799
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
## PAN-129927
```caveat
VM-Series firewalls only
```
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.