diff --git a/reference/PAN-OS/addressed/10.2.7-h1.html b/reference/PAN-OS/addressed/10.2.7-h1.html new file mode 100644 index 0000000..94d1705 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h1.html @@ -0,0 +1,49 @@ + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-237871
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
+
PAN-236926
+
+
+ Fixed an issue where Elasticsearch shards failed if they were + allocated when tunnels were down, and shards that failed remained + unallocated when tunnels went back up. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h12.html b/reference/PAN-OS/addressed/10.2.7-h12.html new file mode 100644 index 0000000..a54ec18 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h12.html @@ -0,0 +1,277 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-263226
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy + nodes. +
+
+
PAN-261917
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were + decrypted in traffic log when using a Google Chrome browser with PQC + enabled +
+
+
PAN-258996
+
+
+ Fixed an issue where the firewall displayed the SFP ports as + PowerDown when the SFP + transceiver was removed and reinserted or the port was shut down and + brought back up on the peer device. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall entered maintenance mode after enabling kernel data + collection during the silent reboot. +
+
+
PAN-253546
+
+
+ Fixed an issue where a TLS client hello was split into multiple + packets and arrived out of order, so the packets were dropped and the + session terminated. +
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
+
PAN-251661
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header + inflation. +
+
+
PAN-251563
+
+
+ Added CPLD enhancement to capture external power issues. +
+
+
PAN-250152
+
+
+ Fixed an issue related to shared-to-shared optimization. To utilize + this fix, contact Palo Alto Networks Tech Support. +
+
+
PAN-249814
+
+
+ Fixed an issue where multiple + all_task + processes stopped responding, which caused the dataplane to fail. +
+
+
PAN-247257
+
+
+ Fixed an issue where the + useridd + process stopped responding, which caused the firewall to reboot. +
+
+
PAN-244648
+
+
+ Fixed an issue where, when FIPS was enabled in maintenance mode, the + firewall rebooted and returned to maintenance mode. +
+
+
PAN-240612
+
+
Fixed a kernel panic caused by a third-party issue.
+
+
PAN-244013
+
+
+ Fixed an issue where the web interface did not display newly added + Anti-Spyware signatures or Vulnerability Signatures. +
+
+
PAN-239662
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the NSSA default route from the active firewall was not + generated to advertise even though the backbone area default route was + advertised during a graceful restart. +
+
+
PAN-238625
+
+
+ Fixed an issue where, when the physical interface went down, the + SD-WAN ethernet connection state still showed + UP/path-monitor due to the Active + URL SaaS monitor connection state remaining UP/path-monitor. +
+
+
PAN-233191
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the Data Processing Card (DPC) restarted due to path monitor failure + after QSFP28 disconnected from the Network Processing Card (NPC). +
+
+
PAN-226768
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on iOS + endpoints and the gateway was configured to accept cookies, the app + remained in the Connecting stage + after authentication, and the GlobalProtect log displayed the error + message + User is not in allow list. This + occurred when the app was restarted or when the app attempted to + reconnect after disconnection. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h16.html b/reference/PAN-OS/addressed/10.2.7-h16.html new file mode 100644 index 0000000..e508597 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h16.html @@ -0,0 +1,172 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-264871
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when viewing IP addresses on dynamic + address groups with a large number of IP addresses. +
+
+
PAN-262340
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and + all FQDN traffic was denied by the interzone-default policy rule. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused + pan_task + processes to stop responding. +
+
+
PAN-250787
+
+
+ Fixed an issue where network issues between the firewall and the log + collector caused + logrcvr + process memory exhaustion. +
+
+
PAN-242910
+
+
+ Fixed an issue where a custom based non Superuser was unable to push + to firewalls. +
+
+
PAN-231823
+
+
+ Fixed an issue where server profile details in the + configd + process log were incorrectly displayed in plaintext +
+
+
PAN-230755
+
+
+ Fixed an issue where the + devsrvr + process intermittently restarted when processing traffic with a Cloud + App ID. +
+
+
PAN-226361
+
+
+ Fixed an issue where sessions bypassed L7 inspection or ended + unexpectedly with the error + resources unavailable when the + firewall incorrectly interpreted the Content and Threat Detection + (CTD) global packet queue as being full. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h18.html b/reference/PAN-OS/addressed/10.2.7-h18.html new file mode 100644 index 0000000..3be5b50 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h18.html @@ -0,0 +1,157 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused + pan_task + + processes to stop responding. +
+
+
PAN-255653
+
+
+ Fixed a high availability (HA) failover issue where, when Management + Processing Card (MPC) or Base Card (BC) failures occurred, the HA link + went down, which caused fpp-down events on one firewall. +
+
+
PAN-240450
+
+
+ Fixed an issue where commits failed when pushing a configuration to a + large number of device groups (vsys) on a firewall. +
+
+
PAN-234560
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses + instead of IPv4 addresses. +
+
+
PAN-226361
+
+
+ Fixed an issue where sessions bypassed L7 inspection or ended + unexpectedly with the error + resources unavailable when the + firewall incorrectly interpreted the Content and Threat Detection + (CTD) global packet queue as being full. +
+
+
PAN-219805
+
+
+ Fixed an issue where the + reportd + process stopped responding due to a race condition. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h19.html b/reference/PAN-OS/addressed/10.2.7-h19.html new file mode 100644 index 0000000..4a3ca3a --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h19.html @@ -0,0 +1,95 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-273730
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where the web interface became unresponsive after upgrading to PAN-OS + 10.2.7-h8. +
+
+
PAN-268727
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy + was enabled and header insertion modified packets. +
+
+
PAN-260131
+
+
+ Fixed an issue where the firewall consumed a large amount of memory + when forwarding raw logs. +
+
+
PAN-248752
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-850 firewalls only) Fixed an issue where the firewall did not have enough Linux memory + on the dataplane, which caused the firewall to restart. +
+
+
PAN-246772
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a + path monitor failure caused by an out-of-memory (OOM) condition + related to the + pan_task + process. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h21.html b/reference/PAN-OS/addressed/10.2.7-h21.html new file mode 100644 index 0000000..17ef264 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h21.html @@ -0,0 +1,207 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-274570
+
+
+ Fixed an issue where the + devsrvr + process restarted after a failed commit due to an invalid memory + access. +
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-268823
+
+
+ Fixed an issue where + Monitor > Log Display did not + display all logs when you applied a filter. +
+
+
PAN-268260
+
+
+ Fixed an issue on hardware firewalls where, when SSL decryption was + enabled and Client Hello messages spanned multiple TCP segments, some + SSL decrypted sessions failed. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-261332
+
+
+ A fix was made to address + CVE-2024-2552. +
+
+
PAN-257327
+
+
+ (PA-5440 firewalls only) Fixed an issue where a + failover event occurred unexpectedly on the firewall. +
+
+
PAN-244950
+
+
+ A fix was made to address + CVE-2024-2550. +
+
+
PAN-243244
+
+
+ Fixed an issue where decryption failed for TLSv1.3 with the error + message early close notify. +
+
+
PAN-240596
+
+
+ Fixed an issue where the + all_task + process stopped responding due to an invalid memory address +
+
+
PAN-225090
+
+
+ Fixed an issue on Panorama where + Commit and Push was greyed out when + making changes to a template or device group. +
+
+
PAN-222188
+
+
+ A CLI command was introduced to address an issue where SNMP monitoring + performance was slower than expected, which resulted in + snmpwalk timeouts. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h24.html b/reference/PAN-OS/addressed/10.2.7-h24.html new file mode 100644 index 0000000..31fcf50 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h24.html @@ -0,0 +1,399 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-276822
+
+
+ Fixed an issue where the packet buffer size increased significantly + when WildFire File Forwarding was continued after a threat detection + and then canceled. +
+
+
PAN-273994
+
+
+ A fix was made to address + CVE-2025-0111. +
+
+
PAN-273971
+
+
+ A fix was made to address + CVE-2025-0108. +
+
+
PAN-273964
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after + upgrading to a PAN-OS 10.2 release. +
+
+
PAN-273278
+
+
+ A fix was made to address + CVE-2025-0109. +
+
+
PAN-271926
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC + error when the firewall was configured to decrypt and inspect TLS + traffic. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-268951
+
+
+ Fixed a CPS counter query issue that caused SNMP polling timeouts on + the firewall. +
+
+
PAN-268260
+
+
+ Fixed an issue on hardware firewalls where, when SSL decryption was + enabled and Client Hello messages spanned multiple TCP segments, some + SSL decrypted sessions failed. +
+
+
PAN-267704
+
+
+ Fixed an issue where the firewall did not send an ICMP error packet to + Envoy when the MSS was exceeded. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-259055
+
+
+ Fixed an issue where the firewall stopped responding when receiving + SNMPv3 traps. +
+
+
PAN-257390
+
+
+ (PA-5250 firewalls only) Fixed an issue where + the + logrcvr + process stopped responding due to a segmentation fault. +
+
+
PAN-244907
+
+
+ A fix was made to address + CVE-2024-9468. +
+
+
PAN-243244
+
+
+ Fixed an issue where decryption failed for TLSv1.3 with the error + message early close notify. +
+
+
PAN-240397
+
+
+ Fixed an issue where the + useridd + process memory usage increased with each MDM reconnected attempt. +
+
+
PAN-232550
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512 + Auth protocol. +
+
+
PAN-231395
+
+
+ Fixed an intermittent issue where the OCSP query failed. +
+
+
PAN-224938
+
+
+ Fixed an issue where the CLI command settings for + set system setting logging max-log-rate + did not persist after a + mgmtsrvr process restart. +
+
+
PAN-222484
+
+
+ A fix was made to address + CVE-2024-5920. +
+
+
PAN-222193
+
+
+ Fixed an issue where the length of the TCP timestamp option was not + considered when the proxy sent out data, which caused oversized + packets to be sent out and fragmented or dropped. +
+
+
PAN-213956
+
+
+ Fixed an issue where the firewall interface did not go down even after + the peer link/switch port went down. +
+
+
PAN-207003
+
+
+ Fixed an issue where the + logrcvr process netflow buffer was + not reset which resulted in duplicate netflow records. +
+
+
PAN-164885
+
+
+ Fixed an issue on Panorama where + Commit and Push or + Push to Devices operations failed + when an external dynamic list was configured to check for updates + every 5 minutes due to the commit and external dynamic fetch processes + overlapping. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h3.html b/reference/PAN-OS/addressed/10.2.7-h3.html new file mode 100644 index 0000000..f1a3bec --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h3.html @@ -0,0 +1,453 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-240197
+
+
+ Fixed an issue where configuration changes made in Panorama and pushed + to the firewall were not reflected on the firewall. +
+
+
PAN-239144
+
+
+ Fixed an issue where the web interface was slower than expected when + logging in, committing, and pushing changes after upgrading to PAN-OS + 10.2.7. +
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237935
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which + were previously set to expire on September 2, 2024. +
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-234929
+
+
+ Fixed an issue where tabs in the + ACC such as + Network Activity + Threat Activity and + Blocked Activity did not display + data when you applied a Time filter + of Last 15 Minutes, + Last Hour, + Last 6 Hours, or + Last 12 Hours, and the data that was + displayed with the + Last 24 Hours filter was not + accurate. Reports that were run against summary logs also did not + display accurate results. +
+
+
PAN-234279
+
+
+ Fixed an issue where the + ikemgr + process crashed due to an IKEv1 timing issue, which caused commits to + fail with the following error message: + Client ikemgr requesting last config in the middle of a + commit/validate, aborting current commit. +
+
+
PAN-232377
+
+
+ Fixed an issue where the + AddrObjRefresh job failed when + the + useridd + process restarted. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-231169
+
+
+ (PA-220 firewalls only) Fixed an issue where an + unused plugin incorrectly used memory. +
+
+
PAN-228273
+
+
+ (Panorama appliances in FIPS-CC mode only) + Fixed an issue where the Elasticsearch cluster did not come up, and + the + show log-collector-es-cluster health + CLI command displayed the status as red. This caused log ingestion + issues for Panorama appliances in Panorama mode or Log Collector mode. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-224954
+
+
+ Fixed an issue where, after upgrading and rebooting a Panorama + appliance in Panorama or Log Collector mode, managed firewalls + continuously disconnected. +
+
+
PAN-224067
+
+
+ Fixed an issue where cookie authentication did not work for + GlobalProtect when an authentication override domain was configured in + the SAML authentication profile. +
+
+
PAN-224060
+
+
+ (PA-220 Series firewalls only) Fixed an issue + where multiple dataplane processes stopped responding after an + upgrade. +
+
+
PAN-223652
+
+
+ Fixed an issue where data was not thread safe and led to concurrent + read/write issues that caused GPSVC to stop working unexpectedly. +
+
+
PAN-223270
+
+
+ Fixed an issue with Virtual Wire links on firewalls in active/active + HA configurations where the forwarding path was not preserved in + HTTP/2 cleartext traffic with asymmetric routing. +
+
+
PAN-222002
+
+
+ Fixed an issue where content updates failed with the error message + Unable to get key pancontent-8.0.pass from cryptod. Error -9. +
+
+
PAN-218988
+
+
+ Fixed an issue in FIPS mode where, when importing a certificate with a + new private key, and the certificate used the name of an existing + certificate on the Panorama, the following error message was + displayed: + Mismatched public and private keys. +
+
+
PAN-218057
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where internal path monitoring failed due to a heartbeat miss. +
+
+
PAN-217289
+
+
+ Fixed an intermittent issue where HTTP/2 traffic caused buffer + depletion. +
+
+
PAN-216214
+
+
+ (Panorama managed firewalls in active/active HA configurations + only) Fixed an issue where the HA (high availability) status displayed as + Out of Sync (Panorama > Managed Devices > Health) if local firewall configurations were made on one of the HA peers. + This caused the next HA configuration sync to overwrite the local + firewall configuration made on the HA peer. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
+
PAN-208395
+
+
+ Fixed an issue where user authentication failed in multi-vsys + environments with the error message + User is not in allowlist when an + authentication profile was created in a shared configuration space. +
+
+
PAN-202361
+
+
+ Fixed an issue where packets queued to the + pan_task + process were still transmitted when the process was not responding. +
+
+
PAN-189769
+
+ Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) + deployments with overlay routing enabled where, when a single firewall + was the backend of multiple GWLBs, packets were re-encapsulated with an + incorrect source IP address. +
+
PAN-181706
+
+
+ Fixed an issue where the + logrcvr + process stopped responding after upgrading to PAN-OS 10.1. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h6.html b/reference/PAN-OS/addressed/10.2.7-h6.html new file mode 100644 index 0000000..7cb4c68 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h6.html @@ -0,0 +1,319 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-246431
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8. +
+
+
+ Fixed an issue where a + Push to Device operation remained at + the state None when performing a + selective push to device groups and templates that included both + connected and disconnected firewalls. +
+
+
PAN-242910
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8. +
+
+
+ Fixed an issue where a custom based non Superuser was unable to push + to firewalls. +
+
+
PAN-242627
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8. +
+
+
Fixed an issue where selective push did not work.
+
+
PAN-242561
+
+
+ Fixed an issue where GlobalProtect tunnels disconnected shortly after + being established when SSL was used as the transfer protocol. +
+
+
PAN-242027
+
+
+ Fixed an issue where the + all-task + process repeatedly restarted during memory allocation failures. +
+
+
PAN-239367
+
+
+ Fixed an issue on the firewall where a memory leak associated with the + logrcvr + process occurred. +
+
+
PAN-238643
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8. +
+
+
+ Fixed an issue where a memory leak caused multiple processes to stop + responding when VM Information Sources was configured. +
+
+
PAN-237208
+
+
+ Fixed an issue where the + reportd + process stopped and the firewall rebooted. +
+
+
+ PAN-235840 +
+
+
+ Fixed an issue where, after a configuration push from Panorama to + managed firewalls, the status displayed as + None and the push took longer than + expected. +
+
+
+ PAN-233789 +
+
+
+ Fixed an issue with commit and push and push operations where the user + was not correctly bound to the scope, which caused all device groups + to be selected for a selective push. +
+
+
+ PAN-231148 +
+
+
+ Fixed an issue where no DHCP option list was defined when using + GlobalProtect. +
+
+
+ PAN-229090 +
+
+
+ Fixed an issue where the + logrcvr + process stopped responding during memory allocation failures. +
+
+
PAN-228515
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8. +
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed + as yellow or red due to Elasticsearch SSH tunnel flaps. +
+
+
+ PAN-223259 +
+
+
+ Fixed an issue where selective pushes failed with the error message + Failed to generate selective push configuration. Unable to retrieve + last in-sync configuration for the device, either a push was never + done or version is too old. Please try a full push. +
+
+
+ PAN-217293 +
+
+
+ Fixed a rare issue where URLs were not accessible when the header + length was greater than 16,000 over HTTP/2. +
+
+
+ PAN-199070 +
+
+
+ Fixed an issue where the + all_task + and + pan_task + processes stopped responding, which impacted traffic. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7-h8.html b/reference/PAN-OS/addressed/10.2.7-h8.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h8.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7.h32.html b/reference/PAN-OS/addressed/10.2.7.h32.html new file mode 100644 index 0000000..c0958c0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7.h32.html @@ -0,0 +1,460 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-292393
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in + active/active HA pairs when the TFTP control channel was processed by + one firewall and the data channel was processed by the other. This + occurred because the firewall receiving the data channel failed to + match the predicted session due to asynchronous processing of HA + messages. +
+
+
PAN-285756
+
+
+ Fixed an issue on the web interface where, when you were saving + telemetry settings, OK was disabled + by default and Cancel was enabled by + default. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-279336
+
+
+ Fixed an issue where the CLI did not display a message to commit prior + changes before loading a partial configuration. +
+
+
PAN-279176
+
+
+ Fixed an issue where the configuration audit displayed inaccurate + information after partially loading the configuration via the CLI, + which caused the audit to flag the configuration as deleted or + changed. +
+
+
PAN-274570
+
+
+ Fixed an issue where the + devsrvr + process restarted after a failed commit due to an invalid memory + access. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-262373
+
+
+ Fixed an issue where the error message + Failed to reload config files + displayed in the system logs even when device telemetry was not + enabled. +
+
+
PAN-262372
+
+
+ Fixed an issue where the firewall generated the message + Successfully generating a new set of config files + in the system logs even when device telemetry was not enabled. +
+
+
PAN-261489
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a + firewall outage. +
+
+
PAN-261484
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount + of memory as requested for pre-allocation. +
+
+
PAN-260564
+
+
+ Fixed an issue on firewalls in high availability (HA) configurations + where a network loop was detected by switches after suspending HA on + the active firewall. +
+
+
PAN-259759
+
+
+ A fix was made to address + CVE-2025-0125. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-255859
+
+
+ A fix was made to address + CVE-2025-0128. +
+
+
PAN-254174
+
+
+ A fix was made to address + CVE-2025-0115. +
+
+
PAN-253328
+
+
+ A fix was made to address + CVE-2025-0126. +
+
+
PAN-251895
+
+
+ Fixed an issue where enabling Inline Cloud Analysis features caused a + slow packet buffer leak, which resulted in performance issues and + dropped traffic. +
+
+
PAN-250146
+
+
+ Fixed an issue on the web interface where templates incorrectly showed + that telemetry was enabled when it was not enabled. With this fix, the + telemetry setting is not displayed in the template on the web + interface. +
+
+
PAN-250020
+
+
+ Fixed an issue where MLC2 verdict retrieval failed due to a regression + in loopback data flag handling. +
+
+
PAN-242739
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly + restarted. +
+
+
PAN-236133
+
+
+ Fixed an issue where SSL traffic was impacted when + SSL Command and Control detector for + Incline Cloud Analysis was set to + reset-both, + reset-client, + reset-server, or + drop. +
+
+
PAN-230823
+
+
+ (PA-800 Series firewalls and PA-220 firewalls only) Fixed an issue where executing the CLI command + show running resource-monitor ingress-backlogs + displayed the following error message: + Server error: Failed to interpret the DP response. +
+
+
PAN-225690
+
+
+ A fix was made to address + CVE-2025-0127. +
+
+
PAN-216941
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where Panorama stopped processing and saving logs. +
+
+
PAN-215223
+
+
+ A fix was made to address + CVE-2025-4231. +
+
+
PAN-213275
+
+
+ Fixed an issue where new Panorama template stacks did not inherit the + existing telemetry settings on Panorama. +
+
+
PAN-185286
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + on Panorama where device health resources did not populate. +
+
diff --git a/reference/PAN-OS/addressed/10.2.7.html b/reference/PAN-OS/addressed/10.2.7.html new file mode 100644 index 0000000..67f610f --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7.html @@ -0,0 +1,348 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-236605
+
+
+ Fixed an issue where the + configd + process stopped responding due to a deadlock related to + rule-hit-count. +
+
+
PAN-232800
+
+
+ Fixed an issue where critical disk usage for + /opt/pancfg increased + continuously and the system logs displayed the following message: + Disk usage for /opt/pancfg exceeds limit, <value> percent in + use. +
+
+
PAN-232132
+
+
+ Fixed an issue where DNS response packets were malformed when an + Anti-Spyware Security Profile was enabled. +
+
+
PAN-232059
+
+
+ Fixed an issue with memory management when processing large + certificates using TLSv1.3. +
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-231043
+
+
+ Fixed an issue where websites were not able to be opened via + GlobalProtect with SSL-VPN when software cut through was enabled. +
+
+
PAN-229691
+
+
+ Fixed an issue on Panorama where configuration lock timeout errors + were observed during normal operational commands by increasing thread + stack size on Panorama. +
+
+
PAN-228998
+
+
+ Fixed an issue where multiple license status checks caused an internal + process to stop responding. +
+
+
PAN-228877
+
+
+ (PA-7050 firewalls only) Fixed an issue with + OOM conditions that caused slot restarts due to + pan_cmd consuming more than 300 + MB. +
+
+
PAN-227539
+
+
+ Fixed an issue where excess WIF process memory use caused processes to + restart due to OOM conditions. +
+
+
PAN-227368
+
+
+ Fixed an issue where the GlobalProtect app was unable to connect to a + portal or gateway and GlobalProtect Clientless VPN users were unable + to access applications if authentication took more than 20 seconds. +
+
+
PAN-225337
+
+
+ Fixed an issue on Panorama related to Shared configuration objects + where configuration pushes to multi-vsys firewalls when authentication + took longer than 20 seconds. +
+
+
PAN-224145
+
+
+ Fixed an issue in multi-vsys environments where, when Panorama was on + a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release, + commits failed on the firewall when inbound inspection mode was + configured in the decryption policy rule. +
+
+
PAN-223488
+
+
+ Fixed an issue where closed ElasticSearch shards were not deleted, + which resulted in shard purging not working as expected. +
+
+
PAN-221973
+
+
+ Fixed an issue where the same user connected to multiple SSL VPN + connections and one of the sessions stopped working. +
+
+
PAN-221190
+
+
+ (PA-800 Series firewalls only) Fixed an issue + where the firewall rebooted due to I2C errors when unsupported optics + were inserted in ports 5-8. +
+
+
PAN-221126
+
+
+ Fixed an issue where Email server profiles (Device > Server Profiles > Email and Panorama > Server + Profiles > Email) to forward logs as email notifications were not forwarded in a + readable format. +
+
+
PAN-221015
+
+ (M-600 Appliances only) Fixed an issue where + ElasticSearch processes did not restart when the appliance was rebooted, + which caused the Managed Collector ES health status to be downgraded. +
+
PAN-218521
+
+
+ (M-600 Appliances in Log Collector mode only) + Fixed an issue where Panorama continuously rebooted and became + unresponsive, which consumed excessive logging disk space and + prevented new log ingestion. +
+
+
PAN-215268
+
+
+ Fixed an issue where selective push did not work for firewalls on + PAN-OS 9.1 or an earlier release. +
+
+
PAN-214186
+
+
+ Fixed an issue where category length was incorrect, which caused the + dataplane to restart. +
+
+
PAN-212761
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the dataplane to go down and + caused HA failover. +
+
+
PAN-193004
+
+
+ Fixed an issue where + /opt/pancfg partition utilization + reached 100%, which caused access to the Panorama web interface to + fail. +
+
diff --git a/reference/PAN-OS/addressed/12.1.7-h3.html b/reference/PAN-OS/addressed/12.1.7-h3.html new file mode 100644 index 0000000..55b4887 --- /dev/null +++ b/reference/PAN-OS/addressed/12.1.7-h3.html @@ -0,0 +1,99 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-329834
+
+
+ Fixed an issue where a memory leak associated with some display CLI + commands caused instability. +
+
PAN-327460
+
+ Fixed an issue where a + Commit and Push operation on + Panorama did not successfully push configuration changes to Prisma + Access endpoints. This occurred when the system reported that not all + commit jobs were triggered. With this fix, + Commit and Push operations now + correctly apply configurations to Prisma Access. +
+
PAN-326677
+
+ Fixed an issue where a selective push from Panorama to the firewall + was successful even when applying rename operation failed in selective + push, which resulted in configurations on the firewall being deleted. + With this fix, the selective push will fail when applying rename + operation fails. +
+
PAN-325890
+
+ Fixed an issue where licenses were not installed after bootstrapping a + VM-Series firewall in an air-gapped environment. +
+
PAN-323485
+
+ Fixed an issue where multicast radio RTP based traffic was dropped + after an upgrade when the firewall performed Cloud Inline inspection, + which led to an exceeded session queue for Cloud Threat Detection. +
+
PAN-307618
+
+ Added a debug CLI command to address where remote networks for Prisma + Access tenants randomly dropped monitoring packets from peer devices, + which caused tunnels to be marked as down. This occurred when a CPU + core suddenly experienced high utilization. +
+
+ To utilize this fix, run + debug dataplane set ssl-decrypt use-new-peek-window yes. +
+