diff --git a/reference/PAN-OS/addressed/10.2.7-h1.html b/reference/PAN-OS/addressed/10.2.7-h1.html new file mode 100644 index 0000000..94d1705 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.7-h1.html @@ -0,0 +1,49 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-237871
+ |
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ PAN-236926
+ |
+
+
+ Fixed an issue where Elasticsearch shards failed if they were
+ allocated when tunnels were down, and shards that failed remained
+ unallocated when tunnels went back up.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy
+ nodes.
+
+ |
+
|
+ PAN-261917
+ |
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were
+ decrypted in traffic log when using a Google Chrome browser with PQC
+ enabled
+
+ |
+
|
+ PAN-258996
+ |
+
+
+ Fixed an issue where the firewall displayed the SFP ports as
+ PowerDown when the SFP
+ transceiver was removed and reinserted or the port was shut down and
+ brought back up on the peer device.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall entered maintenance mode after enabling kernel data
+ collection during the silent reboot.
+
+ |
+
|
+ PAN-253546
+ |
+
+
+ Fixed an issue where a TLS client hello was split into multiple
+ packets and arrived out of order, so the packets were dropped and the
+ session terminated.
+
+ |
+
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ PAN-251661
+ |
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header
+ inflation.
+
+ |
+
|
+ PAN-251563
+ |
+
+
+ Added CPLD enhancement to capture external power issues.
+
+ |
+
|
+ PAN-250152
+ |
+
+
+ Fixed an issue related to shared-to-shared optimization. To utilize
+ this fix, contact Palo Alto Networks Tech Support.
+
+ |
+
|
+ PAN-249814
+ |
+
+
+ Fixed an issue where multiple
+ all_task
+ processes stopped responding, which caused the dataplane to fail.
+
+ |
+
|
+ PAN-247257
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-244648
+ |
+
+
+ Fixed an issue where, when FIPS was enabled in maintenance mode, the
+ firewall rebooted and returned to maintenance mode.
+
+ |
+
|
+ PAN-240612
+ |
+
+ Fixed a kernel panic caused by a third-party issue.
+ |
+
|
+ PAN-244013
+ |
+
+
+ Fixed an issue where the web interface did not display newly added
+ Anti-Spyware signatures or Vulnerability Signatures.
+
+ |
+
|
+ PAN-239662
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the NSSA default route from the active firewall was not
+ generated to advertise even though the backbone area default route was
+ advertised during a graceful restart.
+
+ |
+
|
+ PAN-238625
+ |
+
+
+ Fixed an issue where, when the physical interface went down, the
+ SD-WAN ethernet connection state still showed
+ UP/path-monitor due to the Active
+ URL SaaS monitor connection state remaining UP/path-monitor.
+
+ |
+
|
+ PAN-233191
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the Data Processing Card (DPC) restarted due to path monitor failure
+ after QSFP28 disconnected from the Network Processing Card (NPC).
+
+ |
+
|
+ PAN-226768
+ |
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on iOS
+ endpoints and the gateway was configured to accept cookies, the app
+ remained in the Connecting stage
+ after authentication, and the GlobalProtect log displayed the error
+ message
+ User is not in allow list. This
+ occurred when the app was restarted or when the app attempted to
+ reconnect after disconnection.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-264871
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when viewing IP addresses on dynamic
+ address groups with a large number of IP addresses.
+
+ |
+
|
+ PAN-262340
+ |
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and
+ all FQDN traffic was denied by the interzone-default policy rule.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused
+ pan_task
+ processes to stop responding.
+
+ |
+
|
+ PAN-250787
+ |
+
+
+ Fixed an issue where network issues between the firewall and the log
+ collector caused
+ logrcvr
+ process memory exhaustion.
+
+ |
+
|
+ PAN-242910
+ |
+
+
+ Fixed an issue where a custom based non Superuser was unable to push
+ to firewalls.
+
+ |
+
|
+ PAN-231823
+ |
+
+
+ Fixed an issue where server profile details in the
+ configd
+ process log were incorrectly displayed in plaintext
+
+ |
+
|
+ PAN-230755
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process intermittently restarted when processing traffic with a Cloud
+ App ID.
+
+ |
+
|
+ PAN-226361
+ |
+
+
+ Fixed an issue where sessions bypassed L7 inspection or ended
+ unexpectedly with the error
+ resources unavailable when the
+ firewall incorrectly interpreted the Content and Threat Detection
+ (CTD) global packet queue as being full.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused
+ pan_task
+
+ processes to stop responding.
+
+ |
+
|
+ PAN-255653
+ |
+
+
+ Fixed a high availability (HA) failover issue where, when Management
+ Processing Card (MPC) or Base Card (BC) failures occurred, the HA link
+ went down, which caused fpp-down events on one firewall.
+
+ |
+
|
+ PAN-240450
+ |
+
+
+ Fixed an issue where commits failed when pushing a configuration to a
+ large number of device groups (vsys) on a firewall.
+
+ |
+
|
+ PAN-234560
+ |
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses
+ instead of IPv4 addresses.
+
+ |
+
|
+ PAN-226361
+ |
+
+
+ Fixed an issue where sessions bypassed L7 inspection or ended
+ unexpectedly with the error
+ resources unavailable when the
+ firewall incorrectly interpreted the Content and Threat Detection
+ (CTD) global packet queue as being full.
+
+ |
+
|
+ PAN-219805
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding due to a race condition.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273730
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where the web interface became unresponsive after upgrading to PAN-OS
+ 10.2.7-h8.
+
+ |
+
|
+ PAN-268727
+ |
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy
+ was enabled and header insertion modified packets.
+
+ |
+
|
+ PAN-260131
+ |
+
+
+ Fixed an issue where the firewall consumed a large amount of memory
+ when forwarding raw logs.
+
+ |
+
|
+ PAN-248752
+ |
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-850 firewalls only) Fixed an issue where the firewall did not have enough Linux memory
+ on the dataplane, which caused the firewall to restart.
+
+ |
+
|
+ PAN-246772
+ |
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a
+ path monitor failure caused by an out-of-memory (OOM) condition
+ related to the
+ pan_task
+ process.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-268823
+ |
+
+
+ Fixed an issue where
+ Monitor > Log Display did not
+ display all logs when you applied a filter.
+
+ |
+
|
+ PAN-268260
+ |
+
+
+ Fixed an issue on hardware firewalls where, when SSL decryption was
+ enabled and Client Hello messages spanned multiple TCP segments, some
+ SSL decrypted sessions failed.
+
+ |
+
|
+ PAN-264249
+ |
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using
+ SNMP.
+
+ |
+
|
+ PAN-261332
+ |
+
+
+ A fix was made to address
+ CVE-2024-2552.
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ (PA-5440 firewalls only) Fixed an issue where a
+ failover event occurred unexpectedly on the firewall.
+
+ |
+
|
+ PAN-244950
+ |
+
+
+ A fix was made to address
+ CVE-2024-2550.
+
+ |
+
|
+ PAN-243244
+ |
+
+
+ Fixed an issue where decryption failed for TLSv1.3 with the error
+ message early close notify.
+
+ |
+
|
+ PAN-240596
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding due to an invalid memory address
+
+ |
+
|
+ PAN-225090
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push was greyed out when
+ making changes to a template or device group.
+
+ |
+
|
+ PAN-222188
+ |
+
+
+ A CLI command was introduced to address an issue where SNMP monitoring
+ performance was slower than expected, which resulted in
+ snmpwalk timeouts.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-276822
+ |
+
+
+ Fixed an issue where the packet buffer size increased significantly
+ when WildFire File Forwarding was continued after a threat detection
+ and then canceled.
+
+ |
+
|
+ PAN-273994
+ |
+
+
+ A fix was made to address
+ CVE-2025-0111.
+
+ |
+
|
+ PAN-273971
+ |
+
+
+ A fix was made to address
+ CVE-2025-0108.
+
+ |
+
|
+ PAN-273964
+ |
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after
+ upgrading to a PAN-OS 10.2 release.
+
+ |
+
|
+ PAN-273278
+ |
+
+
+ A fix was made to address
+ CVE-2025-0109.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-268951
+ |
+
+
+ Fixed a CPS counter query issue that caused SNMP polling timeouts on
+ the firewall.
+
+ |
+
|
+ PAN-268260
+ |
+
+
+ Fixed an issue on hardware firewalls where, when SSL decryption was
+ enabled and Client Hello messages spanned multiple TCP segments, some
+ SSL decrypted sessions failed.
+
+ |
+
|
+ PAN-267704
+ |
+
+
+ Fixed an issue where the firewall did not send an ICMP error packet to
+ Envoy when the MSS was exceeded.
+
+ |
+
|
+ PAN-264249
+ |
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using
+ SNMP.
+
+ |
+
|
+ PAN-259055
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving
+ SNMPv3 traps.
+
+ |
+
|
+ PAN-257390
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ the
+ logrcvr
+ process stopped responding due to a segmentation fault.
+
+ |
+
|
+ PAN-244907
+ |
+
+
+ A fix was made to address
+ CVE-2024-9468.
+
+ |
+
|
+ PAN-243244
+ |
+
+
+ Fixed an issue where decryption failed for TLSv1.3 with the error
+ message early close notify.
+
+ |
+
|
+ PAN-240397
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process memory usage increased with each MDM reconnected attempt.
+
+ |
+
|
+ PAN-232550
+ |
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512
+ Auth protocol.
+
+ |
+
|
+ PAN-231395
+ |
+
+
+ Fixed an intermittent issue where the OCSP query failed.
+
+ |
+
|
+ PAN-224938
+ |
+
+
+ Fixed an issue where the CLI command settings for
+ set system setting logging max-log-rate
+ did not persist after a
+ mgmtsrvr process restart.
+
+ |
+
|
+ PAN-222484
+ |
+
+
+ A fix was made to address
+ CVE-2024-5920.
+
+ |
+
|
+ PAN-222193
+ |
+
+
+ Fixed an issue where the length of the TCP timestamp option was not
+ considered when the proxy sent out data, which caused oversized
+ packets to be sent out and fragmented or dropped.
+
+ |
+
|
+ PAN-213956
+ |
+
+
+ Fixed an issue where the firewall interface did not go down even after
+ the peer link/switch port went down.
+
+ |
+
|
+ PAN-207003
+ |
+
+
+ Fixed an issue where the
+ logrcvr process netflow buffer was
+ not reset which resulted in duplicate netflow records.
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push or
+ Push to Devices operations failed
+ when an external dynamic list was configured to check for updates
+ every 5 minutes due to the commit and external dynamic fetch processes
+ overlapping.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-240197
+ |
+
+
+ Fixed an issue where configuration changes made in Panorama and pushed
+ to the firewall were not reflected on the firewall.
+
+ |
+
|
+ PAN-239144
+ |
+
+
+ Fixed an issue where the web interface was slower than expected when
+ logging in, committing, and pushing changes after upgrading to PAN-OS
+ 10.2.7.
+
+ |
+
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237935
+ |
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which
+ were previously set to expire on September 2, 2024.
+
+ |
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-234929
+ |
+
+
+ Fixed an issue where tabs in the
+ ACC such as
+ Network Activity
+ Threat Activity and
+ Blocked Activity did not display
+ data when you applied a Time filter
+ of Last 15 Minutes,
+ Last Hour,
+ Last 6 Hours, or
+ Last 12 Hours, and the data that was
+ displayed with the
+ Last 24 Hours filter was not
+ accurate. Reports that were run against summary logs also did not
+ display accurate results.
+
+ |
+
|
+ PAN-234279
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process crashed due to an IKEv1 timing issue, which caused commits to
+ fail with the following error message:
+ Client ikemgr requesting last config in the middle of a
+ commit/validate, aborting current commit.
+
+ |
+
|
+ PAN-232377
+ |
+
+
+ Fixed an issue where the
+ AddrObjRefresh job failed when
+ the
+ useridd
+ process restarted.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-231169
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where an
+ unused plugin incorrectly used memory.
+
+ |
+
|
+ PAN-228273
+ |
+
+
+ (Panorama appliances in FIPS-CC mode only)
+ Fixed an issue where the Elasticsearch cluster did not come up, and
+ the
+ show log-collector-es-cluster health
+ CLI command displayed the status as red. This caused log ingestion
+ issues for Panorama appliances in Panorama mode or Log Collector mode.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-224954
+ |
+
+
+ Fixed an issue where, after upgrading and rebooting a Panorama
+ appliance in Panorama or Log Collector mode, managed firewalls
+ continuously disconnected.
+
+ |
+
|
+ PAN-224067
+ |
+
+
+ Fixed an issue where cookie authentication did not work for
+ GlobalProtect when an authentication override domain was configured in
+ the SAML authentication profile.
+
+ |
+
|
+ PAN-224060
+ |
+
+
+ (PA-220 Series firewalls only) Fixed an issue
+ where multiple dataplane processes stopped responding after an
+ upgrade.
+
+ |
+
|
+ PAN-223652
+ |
+
+
+ Fixed an issue where data was not thread safe and led to concurrent
+ read/write issues that caused GPSVC to stop working unexpectedly.
+
+ |
+
|
+ PAN-223270
+ |
+
+
+ Fixed an issue with Virtual Wire links on firewalls in active/active
+ HA configurations where the forwarding path was not preserved in
+ HTTP/2 cleartext traffic with asymmetric routing.
+
+ |
+
|
+ PAN-222002
+ |
+
+
+ Fixed an issue where content updates failed with the error message
+ Unable to get key pancontent-8.0.pass from cryptod. Error -9.
+
+ |
+
|
+ PAN-218988
+ |
+
+
+ Fixed an issue in FIPS mode where, when importing a certificate with a
+ new private key, and the certificate used the name of an existing
+ certificate on the Panorama, the following error message was
+ displayed:
+ Mismatched public and private keys.
+
+ |
+
|
+ PAN-218057
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where internal path monitoring failed due to a heartbeat miss.
+
+ |
+
|
+ PAN-217289
+ |
+
+
+ Fixed an intermittent issue where HTTP/2 traffic caused buffer
+ depletion.
+
+ |
+
|
+ PAN-216214
+ |
+
+
+ (Panorama managed firewalls in active/active HA configurations
+ only) Fixed an issue where the HA (high availability) status displayed as
+ Out of Sync (Panorama > Managed Devices > Health) if local firewall configurations were made on one of the HA peers.
+ This caused the next HA configuration sync to overwrite the local
+ firewall configuration made on the HA peer.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ PAN-208395
+ |
+
+
+ Fixed an issue where user authentication failed in multi-vsys
+ environments with the error message
+ User is not in allowlist when an
+ authentication profile was created in a shared configuration space.
+
+ |
+
|
+ PAN-202361
+ |
+
+
+ Fixed an issue where packets queued to the
+ pan_task
+ process were still transmitted when the process was not responding.
+
+ |
+
|
+ PAN-189769
+ |
+ + Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) + deployments with overlay routing enabled where, when a single firewall + was the backend of multiple GWLBs, packets were re-encapsulated with an + incorrect source IP address. + | +
|
+ PAN-181706
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding after upgrading to PAN-OS 10.1.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-246431
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8.
+
+ |
+
+
+ Fixed an issue where a
+ Push to Device operation remained at
+ the state None when performing a
+ selective push to device groups and templates that included both
+ connected and disconnected firewalls.
+
+ |
+
|
+ PAN-242910
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8.
+
+ |
+
+
+ Fixed an issue where a custom based non Superuser was unable to push
+ to firewalls.
+
+ |
+
|
+ PAN-242627
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8.
+
+ |
+
+ Fixed an issue where selective push did not work.
+ |
+
|
+ PAN-242561
+ |
+
+
+ Fixed an issue where GlobalProtect tunnels disconnected shortly after
+ being established when SSL was used as the transfer protocol.
+
+ |
+
|
+ PAN-242027
+ |
+
+
+ Fixed an issue where the
+ all-task
+ process repeatedly restarted during memory allocation failures.
+
+ |
+
|
+ PAN-239367
+ |
+
+
+ Fixed an issue on the firewall where a memory leak associated with the
+ logrcvr
+ process occurred.
+
+ |
+
|
+ PAN-238643
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8.
+
+ |
+
+
+ Fixed an issue where a memory leak caused multiple processes to stop
+ responding when VM Information Sources was configured.
+
+ |
+
|
+ PAN-237208
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped and the firewall rebooted.
+
+ |
+
|
+
+ PAN-235840
+
+ |
+
+
+ Fixed an issue where, after a configuration push from Panorama to
+ managed firewalls, the status displayed as
+ None and the push took longer than
+ expected.
+
+ |
+
|
+
+ PAN-233789
+
+ |
+
+
+ Fixed an issue with commit and push and push operations where the user
+ was not correctly bound to the scope, which caused all device groups
+ to be selected for a selective push.
+
+ |
+
|
+
+ PAN-231148
+
+ |
+
+
+ Fixed an issue where no DHCP option list was defined when using
+ GlobalProtect.
+
+ |
+
|
+
+ PAN-229090
+
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding during memory allocation failures.
+
+ |
+
|
+ PAN-228515
+
+ This issue is resolved in this hotfix but not in PAN-OS 10.2.8.
+
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed
+ as yellow or red due to Elasticsearch SSH tunnel flaps.
+
+ |
+
|
+
+ PAN-223259
+
+ |
+
+
+ Fixed an issue where selective pushes failed with the error message
+ Failed to generate selective push configuration. Unable to retrieve
+ last in-sync configuration for the device, either a push was never
+ done or version is too old. Please try a full push.
+
+ |
+
|
+
+ PAN-217293
+
+ |
+
+
+ Fixed a rare issue where URLs were not accessible when the header
+ length was greater than 16,000 over HTTP/2.
+
+ |
+
|
+
+ PAN-199070
+
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-292393
+ |
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in
+ active/active HA pairs when the TFTP control channel was processed by
+ one firewall and the data channel was processed by the other. This
+ occurred because the firewall receiving the data channel failed to
+ match the predicted session due to asynchronous processing of HA
+ messages.
+
+ |
+
|
+ PAN-285756
+ |
+
+
+ Fixed an issue on the web interface where, when you were saving
+ telemetry settings, OK was disabled
+ by default and Cancel was enabled by
+ default.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-262373
+ |
+
+
+ Fixed an issue where the error message
+ Failed to reload config files
+ displayed in the system logs even when device telemetry was not
+ enabled.
+
+ |
+
|
+ PAN-262372
+ |
+
+
+ Fixed an issue where the firewall generated the message
+ Successfully generating a new set of config files
+ in the system logs even when device telemetry was not enabled.
+
+ |
+
|
+ PAN-261489
+ |
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a
+ firewall outage.
+
+ |
+
|
+ PAN-261484
+ |
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount
+ of memory as requested for pre-allocation.
+
+ |
+
|
+ PAN-260564
+ |
+
+
+ Fixed an issue on firewalls in high availability (HA) configurations
+ where a network loop was detected by switches after suspending HA on
+ the active firewall.
+
+ |
+
|
+ PAN-259759
+ |
+
+
+ A fix was made to address
+ CVE-2025-0125.
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-255859
+ |
+
+
+ A fix was made to address
+ CVE-2025-0128.
+
+ |
+
|
+ PAN-254174
+ |
+
+
+ A fix was made to address
+ CVE-2025-0115.
+
+ |
+
|
+ PAN-253328
+ |
+
+
+ A fix was made to address
+ CVE-2025-0126.
+
+ |
+
|
+ PAN-251895
+ |
+
+
+ Fixed an issue where enabling Inline Cloud Analysis features caused a
+ slow packet buffer leak, which resulted in performance issues and
+ dropped traffic.
+
+ |
+
|
+ PAN-250146
+ |
+
+
+ Fixed an issue on the web interface where templates incorrectly showed
+ that telemetry was enabled when it was not enabled. With this fix, the
+ telemetry setting is not displayed in the template on the web
+ interface.
+
+ |
+
|
+ PAN-250020
+ |
+
+
+ Fixed an issue where MLC2 verdict retrieval failed due to a regression
+ in loopback data flag handling.
+
+ |
+
|
+ PAN-242739
+ |
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly
+ restarted.
+
+ |
+
|
+ PAN-236133
+ |
+
+
+ Fixed an issue where SSL traffic was impacted when
+ SSL Command and Control detector for
+ Incline Cloud Analysis was set to
+ reset-both,
+ reset-client,
+ reset-server, or
+ drop.
+
+ |
+
|
+ PAN-230823
+ |
+
+
+ (PA-800 Series firewalls and PA-220 firewalls only) Fixed an issue where executing the CLI command
+ show running resource-monitor ingress-backlogs
+ displayed the following error message:
+ Server error: Failed to interpret the DP response.
+
+ |
+
|
+ PAN-225690
+ |
+
+
+ A fix was made to address
+ CVE-2025-0127.
+
+ |
+
|
+ PAN-216941
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where Panorama stopped processing and saving logs.
+
+ |
+
|
+ PAN-215223
+ |
+
+
+ A fix was made to address
+ CVE-2025-4231.
+
+ |
+
|
+ PAN-213275
+ |
+
+
+ Fixed an issue where new Panorama template stacks did not inherit the
+ existing telemetry settings on Panorama.
+
+ |
+
|
+ PAN-185286
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ on Panorama where device health resources did not populate.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-236605
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding due to a deadlock related to
+ rule-hit-count.
+
+ |
+
|
+ PAN-232800
+ |
+
+
+ Fixed an issue where critical disk usage for
+ /opt/pancfg increased
+ continuously and the system logs displayed the following message:
+ Disk usage for /opt/pancfg exceeds limit, <value> percent in
+ use.
+
+ |
+
|
+ PAN-232132
+ |
+
+
+ Fixed an issue where DNS response packets were malformed when an
+ Anti-Spyware Security Profile was enabled.
+
+ |
+
|
+ PAN-232059
+ |
+
+
+ Fixed an issue with memory management when processing large
+ certificates using TLSv1.3.
+
+ |
+
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-231043
+ |
+
+
+ Fixed an issue where websites were not able to be opened via
+ GlobalProtect with SSL-VPN when software cut through was enabled.
+
+ |
+
|
+ PAN-229691
+ |
+
+
+ Fixed an issue on Panorama where configuration lock timeout errors
+ were observed during normal operational commands by increasing thread
+ stack size on Panorama.
+
+ |
+
|
+ PAN-228998
+ |
+
+
+ Fixed an issue where multiple license status checks caused an internal
+ process to stop responding.
+
+ |
+
|
+ PAN-228877
+ |
+
+
+ (PA-7050 firewalls only) Fixed an issue with
+ OOM conditions that caused slot restarts due to
+ pan_cmd consuming more than 300
+ MB.
+
+ |
+
|
+ PAN-227539
+ |
+
+
+ Fixed an issue where excess WIF process memory use caused processes to
+ restart due to OOM conditions.
+
+ |
+
|
+ PAN-227368
+ |
+
+
+ Fixed an issue where the GlobalProtect app was unable to connect to a
+ portal or gateway and GlobalProtect Clientless VPN users were unable
+ to access applications if authentication took more than 20 seconds.
+
+ |
+
|
+ PAN-225337
+ |
+
+
+ Fixed an issue on Panorama related to Shared configuration objects
+ where configuration pushes to multi-vsys firewalls when authentication
+ took longer than 20 seconds.
+
+ |
+
|
+ PAN-224145
+ |
+
+
+ Fixed an issue in multi-vsys environments where, when Panorama was on
+ a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release,
+ commits failed on the firewall when inbound inspection mode was
+ configured in the decryption policy rule.
+
+ |
+
|
+ PAN-223488
+ |
+
+
+ Fixed an issue where closed ElasticSearch shards were not deleted,
+ which resulted in shard purging not working as expected.
+
+ |
+
|
+ PAN-221973
+ |
+
+
+ Fixed an issue where the same user connected to multiple SSL VPN
+ connections and one of the sessions stopped working.
+
+ |
+
|
+ PAN-221190
+ |
+
+
+ (PA-800 Series firewalls only) Fixed an issue
+ where the firewall rebooted due to I2C errors when unsupported optics
+ were inserted in ports 5-8.
+
+ |
+
|
+ PAN-221126
+ |
+
+
+ Fixed an issue where Email server profiles (Device > Server Profiles > Email and Panorama > Server
+ Profiles > Email) to forward logs as email notifications were not forwarded in a
+ readable format.
+
+ |
+
|
+ PAN-221015
+ |
+ + (M-600 Appliances only) Fixed an issue where + ElasticSearch processes did not restart when the appliance was rebooted, + which caused the Managed Collector ES health status to be downgraded. + | +
|
+ PAN-218521
+ |
+
+
+ (M-600 Appliances in Log Collector mode only)
+ Fixed an issue where Panorama continuously rebooted and became
+ unresponsive, which consumed excessive logging disk space and
+ prevented new log ingestion.
+
+ |
+
|
+ PAN-215268
+ |
+
+
+ Fixed an issue where selective push did not work for firewalls on
+ PAN-OS 9.1 or an earlier release.
+
+ |
+
|
+ PAN-214186
+ |
+
+
+ Fixed an issue where category length was incorrect, which caused the
+ dataplane to restart.
+
+ |
+
|
+ PAN-212761
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the dataplane to go down and
+ caused HA failover.
+
+ |
+
|
+ PAN-193004
+ |
+
+
+ Fixed an issue where
+ /opt/pancfg partition utilization
+ reached 100%, which caused access to the Panorama web interface to
+ fail.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-329834
+ |
+
+
+ Fixed an issue where a memory leak associated with some display CLI
+ commands caused instability.
+
+ |
+
PAN-327460 |
+
+
+ Fixed an issue where a
+ Commit and Push operation on
+ Panorama did not successfully push configuration changes to Prisma
+ Access endpoints. This occurred when the system reported that not all
+ commit jobs were triggered. With this fix,
+ Commit and Push operations now
+ correctly apply configurations to Prisma Access.
+
+ |
+
PAN-326677 |
+
+
+ Fixed an issue where a selective push from Panorama to the firewall
+ was successful even when applying rename operation failed in selective
+ push, which resulted in configurations on the firewall being deleted.
+ With this fix, the selective push will fail when applying rename
+ operation fails.
+
+ |
+
PAN-325890 |
+
+
+ Fixed an issue where licenses were not installed after bootstrapping a
+ VM-Series firewall in an air-gapped environment.
+
+ |
+
PAN-323485 |
+
+
+ Fixed an issue where multicast radio RTP based traffic was dropped
+ after an upgrade when the firewall performed Cloud Inline inspection,
+ which led to an exceeded session queue for Cloud Threat Detection.
+
+ |
+
PAN-307618 |
+
+
+ Added a debug CLI command to address where remote networks for Prisma
+ Access tenants randomly dropped monitoring packets from peer devices,
+ which caused tunnels to be marked as down. This occurred when a CPU
+ core suddenly experienced high utilization.
+
+
+ To utilize this fix, run
+ debug dataplane set ssl-decrypt use-new-peek-window yes.
+
+ |
+