Add reference files

This commit is contained in:
2026-07-29 10:06:27 -05:00
parent 6626ba86cb
commit 3c7abc1cbc
13 changed files with 3076 additions and 0 deletions
+49
View File
@@ -0,0 +1,49 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.316455696202528%" />
<col style="width: 74.68354430379746%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237871</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>WF-500 appliances and PAN-DB private cloud deployments only</tt
>) Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Elasticsearch shards failed if they were
allocated when tunnels were down, and shards that failed remained
unallocated when tunnels went back up.
</div>
</td>
</tr>
</tbody>
</table>
+277
View File
@@ -0,0 +1,277 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption based traffic failed on Explicit Proxy
nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261917</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the SFP ports as
<span class="ph systemoutput">PowerDown</span> when the SFP
transceiver was removed and reinserted or the port was shut down and
brought back up on the peer device.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255868</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a TLS client hello was split into multiple
packets and arrived out of order, so the packets were dropped and the
session terminated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory overwrite occurred during HTTP/2 header
inflation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added CPLD enhancement to capture external power issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250152</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to shared-to-shared optimization. To utilize
this fix, contact Palo Alto Networks Tech Support.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249814</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
processes stopped responding, which caused the dataplane to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247257</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-244648</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when FIPS was enabled in maintenance mode, the
firewall rebooted and returned to maintenance mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240612</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed a kernel panic caused by a third-party issue.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-244013</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display newly added
Anti-Spyware signatures or Vulnerability Signatures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the NSSA default route from the active firewall was not
generated to advertise even though the backbone area default route was
advertised during a graceful restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238625</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the physical interface went down, the
SD-WAN ethernet connection state still showed
<span class="ph uicontrol">UP/path-monitor</span> due to the Active
URL SaaS monitor connection state remaining UP/path-monitor.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233191</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the Data Processing Card (DPC) restarted due to path monitor failure
after QSFP28 disconnected from the Network Processing Card (NPC).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-226768</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on iOS
endpoints and the gateway was configured to accept cookies, the app
remained in the <span class="ph uicontrol">Connecting</span> stage
after authentication, and the GlobalProtect log displayed the error
message
<span class="ph systemoutput">User is not in allow list</span>. This
occurred when the app was restarted or when the app attempted to
reconnect after disconnection.
</div>
</td>
</tr>
</tbody>
</table>
+172
View File
@@ -0,0 +1,172 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264871</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when viewing IP addresses on dynamic
address groups with a large number of IP addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FQDN resolution failed for address objects, and
all FQDN traffic was denied by the interzone-default policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
processes to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where network issues between the firewall and the log
collector caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process memory exhaustion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom based non Superuser was unable to push
to firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231823</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where server profile details in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process log were incorrectly displayed in plaintext
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-230755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process intermittently restarted when processing traffic with a Cloud
App ID.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-226361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions bypassed L7 inspection or ended
unexpectedly with the error
<span class="ph systemoutput">resources unavailable</span> when the
firewall incorrectly interpreted the Content and Threat Detection
(CTD) global packet queue as being full.
</div>
</td>
</tr>
</tbody>
</table>
+157
View File
@@ -0,0 +1,157 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task
</a>
processes to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a high availability (HA) failover issue where, when Management
Processing Card (MPC) or Base Card (BC) failures occurred, the HA link
went down, which caused fpp-down events on one firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed when pushing a configuration to a
large number of device groups (vsys) on a firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the daily summary report displayed IPv6 addresses
instead of IPv4 addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-226361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions bypassed L7 inspection or ended
unexpectedly with the error
<span class="ph systemoutput">resources unavailable</span> when the
firewall incorrectly interpreted the Content and Threat Detection
(CTD) global packet queue as being full.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-219805</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding due to a race condition.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,95 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273730</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where the web interface became unresponsive after upgrading to PAN-OS
10.2.7-h8.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260131</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall consumed a large amount of memory
when forwarding raw logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248752</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3200 Series, PA-5200 Series, and PA-850 firewalls only</tt
>) Fixed an issue where the firewall did not have enough Linux memory
on the dataplane, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane went down due to a
path monitor failure caused by an out-of-memory (OOM) condition
related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process.
</div>
</td>
</tr>
</tbody>
</table>
+207
View File
@@ -0,0 +1,207 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted after a failed commit due to an invalid memory
access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268823</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Monitor &gt; Log Display</span> did not
display all logs when you applied a filter.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268260</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on hardware firewalls where, when SSL decryption was
enabled and Client Hello messages spanned multiple TCP segments, some
SSL decrypted sessions failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261332</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-2552"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-2552</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 firewalls only</tt>) Fixed an issue where a
failover event occurred unexpectedly on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-244950</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-2550"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-2550</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-243244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption failed for TLSv1.3 with the error
message <span class="ph systemoutput">early close notify</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240596</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding due to an invalid memory address
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Commit and Push</span> was greyed out when
making changes to a template or device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222188</b></div>
</td>
<td class="entry relcol">
<div class="p">
A CLI command was introduced to address an issue where SNMP monitoring
performance was slower than expected, which resulted in
<span class="ph systemoutput">snmpwalk</span> timeouts.
</div>
</td>
</tr>
</tbody>
</table>
+399
View File
@@ -0,0 +1,399 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276822</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the packet buffer size increased significantly
when WildFire File Forwarding was continued after a threat detection
and then canceled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273994</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0111"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0111</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273971</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0108"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0108</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP scans to a firewall timed out after
upgrading to a PAN-OS 10.2 release.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273278</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0109"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0109</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268951</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a CPS counter query issue that caused SNMP polling timeouts on
the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268260</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on hardware firewalls where, when SSL decryption was
enabled and Client Hello messages spanned multiple TCP segments, some
SSL decrypted sessions failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send an ICMP error packet to
Envoy when the MSS was exceeded.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259055</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when receiving
SNMPv3 traps.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257390</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-244907</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9468"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9468</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-243244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption failed for TLSv1.3 with the error
message <span class="ph systemoutput">early close notify</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240397</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process memory usage increased with each MDM reconnected attempt.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232550</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMPv3 authentication failed when using SHA-512
Auth protocol.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231395</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where the OCSP query failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command settings for
<span class="ph systemoutput"
>set system setting logging max-log-rate</span
>
did not persist after a
<span class="ph uicontrol">mgmtsrvr</span> process restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222484</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5920"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5920</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the length of the TCP timestamp option was not
considered when the proxy sent out data, which caused oversized
packets to be sent out and fragmented or dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-213956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall interface did not go down even after
the peer link/switch port went down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-207003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">logrcvr</span> process netflow buffer was
not reset which resulted in duplicate netflow records.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-164885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Commit and Push</span> or
<span class="ph uicontrol">Push to Devices</span> operations failed
when an external dynamic list was configured to check for updates
every 5 minutes due to the commit and external dynamic fetch processes
overlapping.
</div>
</td>
</tr>
</tbody>
</table>
+453
View File
@@ -0,0 +1,453 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration changes made in Panorama and pushed
to the firewall were not reflected on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239144</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface was slower than expected when
logging in, committing, and pushing changes after upgrading to PAN-OS
10.2.7.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237935</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the offline PAN-DB, Panorama, and WildFire certificates which
were previously set to expire on September 2, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tabs in the
<span class="ph uicontrol">ACC</span> such as
<span class="ph uicontrol">Network Activity</span>
<span class="ph uicontrol">Threat Activity</span> and
<span class="ph uicontrol">Blocked Activity</span> did not display
data when you applied a <span class="ph uicontrol">Time</span> filter
of <span class="ph uicontrol">Last 15 Minutes</span>,
<span class="ph uicontrol">Last Hour</span>,
<span class="ph uicontrol">Last 6 Hours</span>, or
<span class="ph uicontrol">Last 12 Hours</span>, and the data that was
displayed with the
<span class="ph uicontrol">Last 24 Hours</span> filter was not
accurate. Reports that were run against summary logs also did not
display accurate results.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process crashed due to an IKEv1 timing issue, which caused commits to
fail with the following error message:
<span class="ph systemoutput"
>Client ikemgr requesting last config in the middle of a
commit/validate, aborting current commit</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232377</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">AddrObjRefresh</span> job failed when
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restarted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231169</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where an
unused plugin incorrectly used memory.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-228273</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
Fixed an issue where the Elasticsearch cluster did not come up, and
the
<span class="ph systemoutput"
>show log-collector-es-cluster health</span
>
CLI command displayed the status as red. This caused log ingestion
issues for Panorama appliances in Panorama mode or Log Collector mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading and rebooting a Panorama
appliance in Panorama or Log Collector mode, managed firewalls
continuously disconnected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where cookie authentication did not work for
GlobalProtect when an authentication override domain was configured in
the SAML authentication profile.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224060</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 Series firewalls only</tt>) Fixed an issue
where multiple dataplane processes stopped responding after an
upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-223652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where data was not thread safe and led to concurrent
read/write issues that caused GPSVC to stop working unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-223270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Virtual Wire links on firewalls in active/active
HA configurations where the forwarding path was not preserved in
HTTP/2 cleartext traffic with asymmetric routing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content updates failed with the error message
<span class="ph systemoutput"
>Unable to get key pancontent-8.0.pass from cryptod. Error -9</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218988</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in FIPS mode where, when importing a certificate with a
new private key, and the certificate used the name of an existing
certificate on the Panorama, the following error message was
displayed:
<span class="ph systemoutput">Mismatched public and private keys</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218057</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where internal path monitoring failed due to a heartbeat miss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-217289</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where HTTP/2 traffic caused buffer
depletion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216214</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in active/active HA configurations
only</tt
>) Fixed an issue where the HA (high availability) status displayed as
<span class="ph uicontrol">Out of Sync</span> (<span
class="ph uicontrol"
>Panorama &gt; Managed Devices &gt; Health</span
>) if local firewall configurations were made on one of the HA peers.
This caused the next HA configuration sync to overwrite the local
firewall configuration made on the HA peer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-208395</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where user authentication failed in multi-vsys
environments with the error message
<span class="ph systemoutput">User is not in allowlist</span> when an
authentication profile was created in a shared configuration space.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packets queued to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process were still transmitted when the process was not responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-189769</b></div>
</td>
<td class="entry relcol">
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB)
deployments with overlay routing enabled where, when a single firewall
was the backend of multiple GWLBs, packets were re-encapsulated with an
incorrect source IP address.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-181706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding after upgrading to PAN-OS 10.1.
</div>
</td>
</tr>
</tbody>
</table>
+319
View File
@@ -0,0 +1,319 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.316455696202528%" />
<col style="width: 74.68354430379746%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246431</b></div>
<div class="p">
<tt class="ph tt"
>This issue is resolved in this hotfix but not in PAN-OS 10.2.8.</tt
>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<span class="ph uicontrol">Push to Device</span> operation remained at
the state <span class="ph uicontrol">None</span> when performing a
selective push to device groups and templates that included both
connected and disconnected firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242910</b></div>
<div class="p">
<tt class="ph tt"
>This issue is resolved in this hotfix but not in PAN-OS 10.2.8.</tt
>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom based non Superuser was unable to push
to firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242627</b></div>
<div class="p">
<tt class="ph tt"
>This issue is resolved in this hotfix but not in PAN-OS 10.2.8.</tt
>
</div>
</td>
<td class="entry relcol">
<div class="p">Fixed an issue where selective push did not work.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242561</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect tunnels disconnected shortly after
being established when SSL was used as the transfer protocol.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all-task</a
>
process repeatedly restarted during memory allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239367</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where a memory leak associated with the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238643</b></div>
<div class="p">
<tt class="ph tt"
>This issue is resolved in this hotfix but not in PAN-OS 10.2.8.</tt
>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak caused multiple processes to stop
responding when VM Information Sources was configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped and the firewall rebooted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-235840</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a configuration push from Panorama to
managed firewalls, the status displayed as
<span class="ph uicontrol">None</span> and the push took longer than
expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-233789</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with commit and push and push operations where the user
was not correctly bound to the scope, which caused all device groups
to be selected for a selective push.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231148</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where no DHCP option list was defined when using
GlobalProtect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-229090</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding during memory allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-228515</b></div>
<div class="p">
<tt class="ph tt"
>This issue is resolved in this hotfix but not in PAN-OS 10.2.8.</tt
>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch cluster health status displayed
as yellow or red due to Elasticsearch SSH tunnel flaps.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-223259</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Unable to retrieve
last in-sync configuration for the device, either a push was never
done or version is too old. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-217293</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a rare issue where URLs were not accessible when the header
length was greater than 16,000 over HTTP/2.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-199070</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
and
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
processes stopped responding, which impacted traffic.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+460
View File
@@ -0,0 +1,460 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active/active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when you were saving
telemetry settings, <span class="ph uicontrol">OK</span> was disabled
by default and <span class="ph uicontrol">Cancel</span> was enabled by
default.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted after a failed commit due to an invalid memory
access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log collectors had a low incoming log rate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262373</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput">Failed to reload config files</span>
displayed in the system logs even when device telemetry was not
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the message
<span class="ph systemoutput"
>Successfully generating a new set of config files</span
>
in the system logs even when device telemetry was not enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261489</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out-of-memory (OOM) condition caused a
firewall outage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where DPDK allocated twice the amount
of memory as requested for pre-allocation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in high availability (HA) configurations
where a network loop was detected by switches after suspending HA on
the active firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259759</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0125"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0125</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255859</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0128"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0128</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254174</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0115"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0115</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253328</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0126"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0126</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251895</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling Inline Cloud Analysis features caused a
slow packet buffer leak, which resulted in performance issues and
dropped traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where templates incorrectly showed
that telemetry was enabled when it was not enabled. With this fix, the
telemetry setting is not displayed in the template on the web
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250020</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where MLC2 verdict retrieval failed due to a regression
in loopback data flag handling.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242739</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane repeatedly
restarted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic was impacted when
<span class="ph uicontrol">SSL Command and Control detector</span> for
Incline Cloud Analysis was set to
<span class="ph uicontrol">reset-both</span>,
<span class="ph uicontrol">reset-client</span>,
<span class="ph uicontrol">reset-server</span>, or
<span class="ph uicontrol">drop</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-230823</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-800 Series firewalls and PA-220 firewalls only</tt
>) Fixed an issue where executing the CLI command
<span class="ph userinput"
>show running resource-monitor ingress-backlogs</span
>
displayed the following error message:
<span class="ph systemoutput"
>Server error: Failed to interpret the DP response</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225690</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0127"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0127</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216941</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
>) Fixed an issue where Panorama stopped processing and saving logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215223</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4231"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4231</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-213275</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where new Panorama template stacks did not inherit the
existing telemetry settings on Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-185286</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
on Panorama where device health resources did not populate.
</div>
</td>
</tr>
</tbody>
</table>
+348
View File
@@ -0,0 +1,348 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236605</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding due to a deadlock related to
rule-hit-count.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232800</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where critical disk usage for
<span class="ph systemoutput">/opt/pancfg</span> increased
continuously and the system logs displayed the following message:
<span class="ph systemoutput"
>Disk usage for /opt/pancfg exceeds limit, &lt;value&gt; percent in
use</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232132</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS response packets were malformed when an
Anti-Spyware Security Profile was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with memory management when processing large
certificates using TLSv1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites were not able to be opened via
GlobalProtect with SSL-VPN when software cut through was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-229691</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where configuration lock timeout errors
were observed during normal operational commands by increasing thread
stack size on Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-228998</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple license status checks caused an internal
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-228877</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls only</tt>) Fixed an issue with
OOM conditions that caused slot restarts due to
<span class="ph systemoutput">pan_cmd</span> consuming more than 300
MB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227539</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where excess WIF process memory use caused processes to
restart due to OOM conditions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227368</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was unable to connect to a
portal or gateway and GlobalProtect Clientless VPN users were unable
to access applications if authentication took more than 20 seconds.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama related to Shared configuration objects
where configuration pushes to multi-vsys firewalls when authentication
took longer than 20 seconds.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224145</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in multi-vsys environments where, when Panorama was on
a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release,
commits failed on the firewall when inbound inspection mode was
configured in the decryption policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223488</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where closed ElasticSearch shards were not deleted,
which resulted in shard purging not working as expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the same user connected to multiple SSL VPN
connections and one of the sessions stopped working.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221190</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-800 Series firewalls only</tt>) Fixed an issue
where the firewall rebooted due to I2C errors when unsupported optics
were inserted in ports 5-8.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Email server profiles (<span class="ph uicontrol"
>Device &gt; Server Profiles &gt; Email and Panorama &gt; Server
Profiles &gt; Email</span
>) to forward logs as email notifications were not forwarded in a
readable format.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221015</b></div>
</td>
<td class="entry relcol">
(<tt class="ph tt">M-600 Appliances only</tt>) Fixed an issue where
ElasticSearch processes did not restart when the appliance was rebooted,
which caused the Managed Collector ES health status to be downgraded.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218521</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 Appliances in Log Collector mode only</tt>)
Fixed an issue where Panorama continuously rebooted and became
unresponsive, which consumed excessive logging disk space and
prevented new log ingestion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215268</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective push did not work for firewalls on
PAN-OS 9.1 or an earlier release.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-214186</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where category length was incorrect, which caused the
dataplane to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212761</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused the dataplane to go down and
caused HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-193004</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput">/opt/pancfg</span> partition utilization
reached 100%, which caused access to the Panorama web interface to
fail.
</div>
</td>
</tr>
</tbody>
</table>
+99
View File
@@ -0,0 +1,99 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-329834</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak associated with some display CLI
commands caused instability.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-327460</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<span class="ph uicontrol">Commit and Push</span> operation on
Panorama did not successfully push configuration changes to Prisma
Access endpoints. This occurred when the system reported that not all
commit jobs were triggered. With this fix,
<span class="ph uicontrol">Commit and Push</span> operations now
correctly apply configurations to Prisma Access.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-326677</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push from Panorama to the firewall
was successful even when applying rename operation failed in selective
push, which resulted in configurations on the firewall being deleted.
With this fix, the selective push will fail when applying rename
operation fails.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-325890</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where licenses were not installed after bootstrapping a
VM-Series firewall in an air-gapped environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323485</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multicast radio RTP based traffic was dropped
after an upgrade when the firewall performed Cloud Inline inspection,
which led to an exceeded session queue for Cloud Threat Detection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307618</div></td>
<td class="entry relcol">
<div class="p">
Added a debug CLI command to address where remote networks for Prisma
Access tenants randomly dropped monitoring packets from peer devices,
which caused tunnels to be marked as down. This occurred when a CPU
core suddenly experienced high utilization.
</div>
<div class="p">
To utilize this fix, run
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt use-new-peek-window yes</span
>.
</div>
</td>
</tr>
</tbody>
</table>