Add PANOS-12.1 addressed issues

This commit is contained in:
2026-03-16 13:50:43 -05:00
parent a9fb5dc45a
commit 225dbe3798
9 changed files with 1915 additions and 1 deletions
@@ -0,0 +1,36 @@
---
type: Addressed
product: PAN-OS
version: 12.1.2
---
## PAN-242777
Fixed an issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
The supported session limits are:
| Platform | Max Sessions |
| --- | --- |
| PA-5410 | 95K |
| PA-5420 | 95K |
| PA-5430 | 95K |
| PA-5440 | 225K |
| PA-5445 | 250K |
| PA-5450 | 1.28M |
## PAN-291499
```caveat
VM-Series firewalls on Amazon Web Services (AWS) environments only
```
Fixed an issue where newly deployed firewalls were unable to connect to the Strata Logging Service (SLS) until after a reboot, license fetch, or management server restart.
## PAN-288726
Fixed an issue where the useridd process stopped responding due to a Security policy rule ID being set to 0, which caused the last configuration retrieval to fail.
## PAN-287133
Fixed an issue on the Panorama web interface where assigning a policy rule to a group at the top or bottom of the list changed the order of other policy rules.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 12.1.3-h1
---
## PAN-304195
Fixed an issue on the firewall where performing a private data reset caused device telemetry to stop working. This issue also occurred after performing a factory reset and then running the CLI command set system ztp disable.
@@ -0,0 +1,17 @@
---
type: Addressed
product: PAN-OS
version: 12.1.3-h3
---
## PAN-000000
A fix was made to address CVE-2026-0227.
## PAN-306534
Fixed an issue were the all_task process repeatedly restarted due to memory pool corruption when processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred due to incorrect buffer length calculations during memory deallocation when the query name field spanned multiple packets.
## PAN-305480
Fixed an issue where the pan_task process stopped responding while processing DoH JSON format traffic with DoH Security enabled, which caused missing cross-packet bytes in the decoded DNS query type field, and the dataplane went down.
@@ -0,0 +1,41 @@
---
type: Addressed
product: PAN-OS
version: 12.1.3
---
## PAN-298241
Fixed an issue where the NAT IP address pool was exhausted, which led to intermittent connectivity issues with call applications and outbound call failures. This occurred due to the firewall not properly releasing NAT dynamic ports back to the address pool.
## PAN-296490
```caveat
FIPS CC mode enabled only
```
Fixed an issue where Panorama on GCP rebooted every hour after upgrading to 11.1.6-h10.
## PAN-289249
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
## PAN-286576
Fixed an issue where the all_pktproc process restarted, which caused heartbeat failures to occur and a slot to go down due to path monitor failure.
## PAN-272245
Fixed an issue where the dnsproxy process crashed due to memory corruption caused by a race condition when the allow list downloading was impacted by config change.
## PAN-267450
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
## PAN-262831
```caveat
PA-5400f Series firewalls only
```
Fixed an intermittent issue where the all_task process stopped responding, which caused the firewall to restart.
@@ -0,0 +1,25 @@
---
type: Addressed
product: PAN-OS
version: 12.1.4-h2
---
## PAN-311938
Fixed an issue where autocommits failed after an upgrade due to configuration memory allocation issues and 100% policy rule cache usage when both DNS Rewrite and URL Custom Category Match were configured.
## PAN-306451
```caveat
VM-Series firewalls on AWS environments only
```
Fixed an issue where, after upgrading the firewall to an affected release, GlobalProtect clients did not connect with IPSec and instead connected using SSL due to traffic flow being disabled when checking for health check packets.
## PAN-304496
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
## PAN-304195
Fixed an issue on the firewall where performing a private data reset caused device telemetry to stop working. This issue also occurred after performing a factory reset and then running the CLI command set system ztp disable.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 12.1.4-h3
---
## PAN-313572
```caveat
VM-Series firewalls only
```
Fixed an issue where the dataplane restarted due to a segmentation fault.
## PAN-300664
Fixed an issue on the Panorama and firewall web interface where Applications pages became unresponsive after activating the SaaS Inline license.
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
@@ -0,0 +1,177 @@
---
type: Addressed
product: PAN-OS
version: 12.1.4
---
## PAN-000000
A fix was made to address CVE-2026-0227.
## PAN-305480
Fixed an issue where the pan_task process stopped responding while processing DoH JSON format traffic with DoH Security enabled, which caused missing cross-packet bytes in the decoded DNS query type field, and the dataplane went down.
## PAN-305151
Fixed an issue where the configuration was not updated on the AI Firewall in AWS after a successful configuration push from Strata Cloud Manager (SCM).
## PAN-304195
Fixed an issue on the firewall where performing a private data reset caused device telemetry to stop working. This issue also occurred after performing a factory reset and then running the CLI command set system ztp disable.
## PAN-304075
Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled.
## PAN-303836
Resolved an issue in which intermittent session-table resets on the AIRS VM triggered packet drops, leading to packet loss in egress response traffic
## PAN-303700
Fixed an issue where GlobalProtect users were incorrectly dropped by the default Security policy rule after upgrading to PAN-OS 12.1.2 when IPv6 firewalling was disabled. This occurred due to policy rules configured with geographic regions matching traffic incorrectly.
## PAN-303559
Fixed an issue where, after manuallly creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
## PAN-302908
Fixed an issue where the firewall did not forward STP frames on Layer 2 VLAN interfaces, which prevented the construction of loop-free topologies with connected switches.
## PAN-301801
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
## PAN-301496
Fixed an issue where the DNS cache capacity was insufficient for environments with a large number of FQDN address objects, which caused the firewall to repeatedly send DNS requests for the same FQDN objects even after it received valid responses.
## PAN-300837
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
## PAN-300372
```caveat
Panorama virtual appliances only
```
Fixed an issue where maintenance mode was not accessible to do Factory Reset or switch to FIPSCC mode.
## PAN-300096
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
## PAN-299815
Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
## PAN-299678
Fixed an issue where the firewall repeatedly rebooted when downgrading to an affected release.
## PAN-299193
Fixed an issue on the firewall where, after upgrading, autocommits repeatedly failed until after a second reboot due to a timing issue between content loading on the management plane card (MPC) and the log receiver startup.
## PAN-298684
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
## PAN-298654
Fixed an issue where the firewall generated false positive threat logs during updates to a large domain list (EDL) when a DNS lookup for a domain being added or removed occurred during the update process. This resulted in a threat log being generated for a different, unrelated domain that remained on the list.
## PAN-298514
Fixed an issue where WildFire clusters operating in FIPS-CC mode were not supported in earlier PAN-OS 12.1 releases.
## PAN-297972
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
## PAN-297797
Fixed an issue where, during a refresh of a large External Dynamic List (EDL), traffic that matched a domain on the list was incorrectly identified as a different domain, which resulted in false positive threat logs.
## PAN-297708
Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.
## PAN-297005
Fixed an issue where exporting custom reports resulted in empty CSV files.
## PAN-296635
Fixed an issue where the reportd process on passive Panorama management servers leaked memory due to scheduled report handling from the Strata Logging Service (SLS). This memory leak occurred daily, consuming available memory until the process was restarted.
## PAN-296478
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute JavaScript links, resulting in an authorization error. This occurred because the firewall was incorrectly injecting text into URLs when JavaScript buttons or dropdown menus were clicked within the Clientless VPN portal.
## PAN-296453
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
## PAN-296202
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where, when a commit operation was in progress, newly deployed IP address tags that used the XML API were not immediately reflected in address group resolution, which delayed IP address mapping to address groups and caused traffic to be incorrectly allowed or denied.
## PAN-295221
Fixed an issue where, after upgrading Panorama and Log Collectors from PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
## PAN-292393
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
## PAN-291716
Fixed an issue where during a commit, the firewall experienced an out-of-memory (OOM) condition due to a memory leak and displayed an error message. This issue caused the device to stop responding and reboot unexpectedly.
## PAN-291661
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
## PAN-290665
Fixed an issue with firewalls enabled with Security profiles where certain traffic conditions caused high dataplane CPU utilization and packet buffer exhaustion, which caused LACP flapping conditions.
## PAN-290640
```caveat
VM-Series firewalls on Microsoft Azure environments in HA configurations only
```
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
## PAN-290453
Fixed an issue where PA-7500 firewalls experienced silent traffic drops. During migration from PA-7050 to PA-7500 firewalls connected in series, intermittent connection losses occurred for some applications. Traffic leaving the PA-7050 was not received or processed by the PA-7500, even with direct connections and replaced cables/SFPs. Global counters did not indicate any drops on the PA-7500.
## PAN-288598
Fixed an issue where Panorama exported the serial number of a managed collector instead of the collector name when exporting a PDF or CSV file.
## PAN-287387
Fixed an issue on Panorama where API jobs failed with the error message Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a large number of address objects in a single set call.
## PAN-282640
Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
## PAN-274333
Fixed an issue where the Logging Service License Status displayed as red even though a valid license was installed on the firewall.
## PAN-262353
Fixed an issue where, when Panorama was upgraded but log collectors were on an earlier version, logs from a log collector group were not viewable on a Panorama.
File diff suppressed because it is too large Load Diff