Add some reference files

This commit is contained in:
2026-05-18 08:30:46 -05:00
parent e86259ffad
commit bf90a29934
17 changed files with 7430 additions and 0 deletions
@@ -0,0 +1,32 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272413</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry did not generate logs after
upgrading the firewall.
</div>
</td>
</tr>
</tbody>
</table>
+696
View File
@@ -0,0 +1,696 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289102</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
CN-Series firewalls only</tt
>) Fixed a race condition issue related to predict processing, which
resulted in a dataplane restart and traffic loss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when ACE was enabled, traffic from cloud
applications randomly matched an incorrect
<span class="ph uicontrol">cloud-apps</span> policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286475</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the option to sort sequence numbers was missing
from <span class="ph uicontrol">Filters prefix list</span> in the
advanced routing filters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to reboot
unexpectedly, and traffic failures occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where retrieving filenames from OneDrive resulted in a
cache miss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where mTLS decryption bypass did not work when the
decryption profile was configured with the maximum TLS version as TLS
1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the SNMP polled values for
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
high number of errors that did not match the values in the CLI show
interface command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283467</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall unexpectedly rebooted and entered maintenance mode
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
advanced services load testing and a high volume of IoT EAL log
forwarding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes to managed devices failed when
the <span class="ph uicontrol">User ID Master Device</span> was
configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls became unstable and stopped responding,
which resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the popup window did not appear as expected for
Clientless VPN users.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279706</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
Panorama did not update all
<span class="ph systemoutput">panreplay</span> database entries after
performing a commit and full push to all devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the
<span class="ph userinput">request system private-data-reset</span>
CLI command to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where deleting the NTP server address caused a commit
validation error. This occurred when the configuration included both
primary and secondary NTP servers and the secondary server was
removed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the following error
message in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
logs: <span class="ph systemoutput">pan_get_keystr_from_cryptod</span>
</div>
<div class="p">
<span class="ph systemoutput"
>(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod
failed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decrypt SSL traffic
when using forward proxy and HSM with an ECDSA signing certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding with a SIGABRT.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process that occurred when running consecutive commits for multiple
days.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270248</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to forward logs to a SNMP
trap server if the SNMP manager IP address was unable to be resolved.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits to service connection firewalls from
Panorama failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269499</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when receiving a
high number of logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PDF summary and email reports displayed IPv6
addresses instead of IPv4 addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268313</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
header were not reset to 0 when a packet was received from one Layer 3
tagged interface and forwarded to another, which resulted in dropped
packets. To use this fix, run the CLI command
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
reboot the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268017</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the IP address-to-user mapping timeout was
triggered and the Inactivity TTL was refreshed unexpectedly
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you enabled multihop in a BFD
profile, you were unable to disable it via the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264883</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7080 appliances with LPCs only</tt>) Fixed an
issue where syslog forwarding over TCP stopped after upgrading.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264040</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where AAAA DNS queries went out even when
<span class="ph uicontrol">IPv6 firewalling</span> was disabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261429</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show auth radius-require-msg-authentic</span
>
command CLI displayed no output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260132</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where secondary IP addresses with a /32 prefix
configured on Layer 3 interfaces were not reachable in FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257117</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CSV or PDF exports of zones did not contain all
zones.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255914</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255759</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to match HIP data with
the correct anti-malware object for Windows Defender.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when QoS was enabled on aggregate interfaces,
the maximum aggregate interface throughput was capped, which limited
network traffic. This occurred even with default QoS settings and no
configured egress max-bandwidth.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224729</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to create duplicate entries in
Advanced Routing AS path prepend in the BGP filter route map.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224020</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CIE validation checks on the firewall prevented
configuration pushes from Panorama, which resulted in commit failures
during new firewall deployment. This occurred when a template with an
Authentication Profile with the
<span class="ph uicontrol">Authentication Type</span> as
<span class="ph uicontrol">Cloud Authentication Service</span> was
pushed to a newly deployed firewall without internet access or without
a device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222307</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212182</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 connections failed if the server sent a
certificate request after sending its certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-201298</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unknown TCP traffic caused errors and high shared
memory usage.
</div>
</td>
</tr>
</tbody>
</table>
+740
View File
@@ -0,0 +1,740 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 46.728971962616825%" />
<col style="width: 53.27102803738318%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
integrated with Gateway Load Balancer (GWLB), the firewall did not
preserve the GENEVE source port for internet traffic, resulting in
increased latency. The fix ensures the firewall preserves the outer
UDP source port of GENEVE encapsulation when sending traffic back to
GWLB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a stream receiving a reconnect signal with an
associated error in
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>Wifclient</a
>
caused the entire pool to close, which resulted in a complete
disconnection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296478</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
JavaScript links, resulting in an authorization error. This occurred
because the firewall was incorrectly injecting text into URLs when
JavaScript buttons or dropdown menus were clicked within the
Clientless VPN portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled custom reports generated through
Panorama were blank (<span class="ph uicontrol"
>Monitor &gt; Reports</span
>) due to a malformed JSON response from the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295342</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding due to insufficient time allocated to read
file descriptors when processing long messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293879</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the VM monitor source remained in
the <span class="ph uicontrol">Getting All</span> status, which
prevented dynamic address groups from updating IP addresses for new
EC2 instances. This issue occurred due to a race condition where two
threads that simultaneously retrieved IP address tag information from
AWS VM monitoring sources became stuck while reading the XML file.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
did not work when connected through GlobalProtect due to the firewall
blocking 200 OK responses. This occurred because of incorrect NAT
translations for the 200 OK message from the server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP walks returned a value of 0 for the CPS
(Connections Per Second) per vsys on firewalls after upgrading to
PAN-OS 11.1.6-h3, even when active connections were present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls</tt>) only Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287842</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding due to missing heartbeats, which resulted
in a system alert and HA communication loss on slot1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation</span>
<span class="ph systemoutput">_restore_timeout</span> not initiating
when the accumulation<span class="ph systemoutput">session_init</span>
failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when an application stopped responding, a large
file was created in the /opt/panlogs directory, which caused the
partition to fill up.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
when searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>set system setting loopback-workaround enable</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client displayed an error
message when you clicked
<span class="ph uicontrol">Check Now</span> and
<span class="ph uicontrol">Preferred Releases</span> and
<span class="ph uicontrol">Base Releases</span> were unchecked (<span
class="ph menucascade"
><span class="ph uicontrol">Device &gt; Software</span></span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unexpected path monitor failures caused the
firewall to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads or uploads failed or
remained in an incomplete state when using DLP HTTP2 mirror mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the default version of IKE gateway
was not set to IKEv2 only mode, which caused VPN establishment issues
if the firewall recognized a new configuration as IKEv1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259741</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped GRE keepalive packets that
were encapsulated under another GRE tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259076</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed an OCSP/CRL check failure
when accessing websites.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255860</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding when the firewall was under a heavy traffic
load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where file downloads from websites failed
when decrypting HTTP/2 traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253485 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where dataplane packet capture filter configuration
failed on the active firewall with the error
<span class="ph systemoutput"
>op command for client dagger timed out as client is not
available</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where templates incorrectly showed
that telemetry was enabled when it was not enabled. With this fix, the
telemetry setting is not displayed in the template on the web
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput"
>import of failed. Please check the validity of the key pair and try
again</span
>
for unmatched keys for EC certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245064</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where commits failed on the firewall after selecting
<span class="ph uicontrol">Export or push device config bundle</span>
on Panorama and a force push was required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
download throughput when passing through a Prisma IPSec tunnel and the
firewall and the SMB-V3 session owner dataplane was the same as the
IPSec-ESP tunnel on the multi-dataplane firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where admin users with the Custom Panorama
Admin role were unable to add, edit, or delete route filters under
<span class="ph menucascade"
><span class="ph uicontrol">Routing Profiles</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-220293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall management plane could not display
BGP peer details when using the CLI command
<span class="ph systemoutput"
>show advanced-routing bgp peer detail logical-router</span
>. This was due to the
<span class="ph systemoutput">bgp_frr.py</span> script failing to
parse the IPv6 address family section of the
<span class="ph systemoutput">show ip bgp neighbors json</span>
output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
</tbody>
</table>
+909
View File
@@ -0,0 +1,909 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to adjust the local pool cache size of the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>detector_threat</a
>
process to address an issue where the local-reuse memory pool borrowed
from the global pool, which impacted performance during session
deletion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299228</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a session process consumed excessive CPU
resources, even when Data Loss Prevention (DLP) was not enabled. This
occurred due to the active threat list being iterated twice when
active threats were present in the session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
integrated with Gateway Load Balancer (GWLB), the firewall did not
preserve the GENEVE source port for internet traffic, resulting in
increased latency. The fix ensures the firewall preserves the outer
UDP source port of GENEVE encapsulation when sending traffic back to
GWLB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're using
a multivsys environment, you must upgrade your firewalls to a fixed
PAN-OS version. The best practice is to upgrade both the firewalls and
Panorama to a fixed PAN-OS version.
</div>
<div class="p">
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message
<span class="ph systemoutput"
>vsys name should end with a number vsys is invalid</span
>
after you
<span class="ph uicontrol">Export or push device config bundle</span>
from 11.1.1 Panorama.
</div>
<div class="p">
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an
<span class="ph uicontrol">Export or Push device config bundle</span>
from Panorama to the firewall to fail. The workaround for PAN-214177
is to first push only the template configuration and then push the
device group configurations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a stream receiving a reconnect signal with an
associated error in
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>Wifclient</a
>
caused the entire pool to close, which resulted in a complete
disconnection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296478</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
JavaScript links, resulting in an authorization error. This occurred
because the firewall was incorrectly injecting text into URLs when
JavaScript buttons or dropdown menus were clicked within the
Clientless VPN portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled custom reports generated through
Panorama were blank (<span class="ph uicontrol"
>Monitor &gt; Reports</span
>) due to a malformed JSON response from the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295342</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding due to insufficient time allocated to read
file descriptors when processing long messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293879</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the VM monitor source remained in
the <span class="ph uicontrol">Getting All</span> status, which
prevented dynamic address groups from updating IP addresses for new
EC2 instances. This issue occurred due to a race condition where two
threads that simultaneously retrieved IP address tag information from
AWS VM monitoring sources became stuck while reading the XML file.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
did not work when connected through GlobalProtect due to the firewall
blocking 200 OK responses. This occurred because of incorrect NAT
translations for the 200 OK message from the server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to gather path
monitoring failure information when troubleshooting high dataplane CPU
utilization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291009</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a web server returned a 401 or 403 error,
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
rejected all subsequent streams from the client.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP walks returned a value of 0 for the CPS
(Connections Per Second) per vsys on firewalls after upgrading to
PAN-OS 11.1.6-h3, even when active connections were present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls</tt>) only Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287842</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding due to missing heartbeats, which resulted
in a system alert and HA communication loss on slot1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation</span>
<span class="ph systemoutput">_restore_timeout</span> not initiating
when the accumulation<span class="ph systemoutput">session_init</span>
failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when an application stopped responding, a large
file was created in the /opt/panlogs directory, which caused the
partition to fill up.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
when searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a GlobalProtect gateway stopped responding when
handling HTTP/1.1 traffic with web inspection enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>set system setting loopback-workaround enable</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client displayed an error
message when you clicked
<span class="ph uicontrol">Check Now</span> and
<span class="ph uicontrol">Preferred Releases</span> and
<span class="ph uicontrol">Base Releases</span> were unchecked (<span
class="ph menucascade"
><span class="ph uicontrol">Device &gt; Software</span></span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268168</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where uploading files that were 5GB or larger to Google
Drive or YouTube failed when a decryption policy rule for http2 was
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads or uploads failed or
remained in an incomplete state when using DLP HTTP2 mirror mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unexpected path monitor failures caused the
firewall to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the default version of IKE gateway
was not set to IKEv2 only mode, which caused VPN establishment issues
if the firewall recognized a new configuration as IKEv1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259741</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped GRE keepalive packets that
were encapsulated under another GRE tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259076</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed an OCSP/CRL check failure
when accessing websites.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255860</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding when the firewall was under a heavy traffic
load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where file downloads from websites failed
when decrypting HTTP/2 traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253485 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where dataplane packet capture filter configuration
failed on the active firewall with the error
<span class="ph systemoutput"
>op command for client dagger timed out as client is not
available</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where templates incorrectly showed
that telemetry was enabled when it was not enabled. With this fix, the
telemetry setting is not displayed in the template on the web
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput"
>import of failed. Please check the validity of the key pair and try
again</span
>
for unmatched keys for EC certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245064</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where commits failed on the firewall after selecting
<span class="ph uicontrol">Export or push device config bundle</span>
on Panorama and a force push was required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
download throughput when passing through a Prisma IPSec tunnel and the
firewall and the SMB-V3 session owner dataplane was the same as the
IPSec-ESP tunnel on the multi-dataplane firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where admin users with the Custom Panorama
Admin role were unable to add, edit, or delete route filters under
<span class="ph menucascade"
><span class="ph uicontrol">Routing Profiles</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-220293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall management plane could not display
BGP peer details when using the CLI command
<span class="ph systemoutput"
>show advanced-routing bgp peer detail logical-router</span
>. This was due to the
<span class="ph systemoutput">bgp_frr.py</span> script failing to
parse the IPv6 address family section of the
<span class="ph systemoutput">show ip bgp neighbors json</span>
output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3393"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3393</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+153
View File
@@ -0,0 +1,153 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="panos-addressed-issues-10.2.13-h18_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269254</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high CPU utilization caused GlobalProtect VPN
tunnels to flap, users to be disconnected, and the CLI to become
unresponsive. This occurred when a large number of GlobalProtect users
were actively processing application traffic.
</div>
</td>
</tr>
</tbody>
</table>
+479
View File
@@ -0,0 +1,479 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted after a failed commit due to an invalid memory
access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273994</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0111"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0111</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273971</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0108"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0108</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273278</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0109"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0109</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 25G port links did not come up due to a change in
the handling of 25G DAC modules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-269899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
getting restarted continuously.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269624</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients failed to connect with the
error message
<span class="ph systemoutput"
>The device or feature requires a GlobalProtect subscription
license</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IP address tags were removed from firewalls after
a management server or
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restart. This occurred when a Panorama serial-number based
configuration was used for User-ID redistribution.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Receive Time</span> and
<span class="ph uicontrol">Time Generated</span> were not visible as
attributes in the <span class="ph uicontrol">Filter Builder</span> for
system logs and URL filtering logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268260</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on hardware firewalls where, when SSL decryption was
enabled and Client Hello messages spanned multiple TCP segments, some
SSL decrypted sessions failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267781</b></div>
</td>
<td class="entry relcol">
Fixed an issue where Panorama did not display the Source Dynamic Address
Group.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restarting with an OOM condition due to a memory leak on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267001</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multicast streams were unstable with ECMP and
dropped every 30 seconds.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266312</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BFD sessions took longer than expected to
establish after an HA failover due to BGP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261739</b></div>
</td>
<td class="entry relcol">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall displayed 0 for the physical port
counters read from MAC.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where frequent external dynamic list updates caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where enabling flow basic caused the
firewall to stop responding due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>masterd</a
>
process restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the <span class="ph uicontrol">Policy</span> page
on the Panorama web interface was slower than expected when a device
group had a large number of managed devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom admin users were not able to click
<span class="ph uicontrol">OK</span> in the push scope selection
window when device group or template were disabled under commit in the
admin roles.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240739</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ECMP FIB update on the dataplane didn't clear
the pending change flag, which caused the next non-ECMP FIB update to
miss the latest generation ID and age out after 5 minutes
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Push All Changes</span> displayed changes
that were already committed in the push scope for another device group
after performing a selective commit and selective push to the first
device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215038</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the output of the
<span class="ph systemoutput"
>request logging-service-forwarding status</span
>
CLI command did not display the correct information after successfully
onboarding a firewall to Cloud Delivered Licensing (CDL).
</div>
</td>
</tr>
</tbody>
</table>
+272
View File
@@ -0,0 +1,272 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276822</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the packet buffer size increased significantly
when WildFire File Forwarding was continued after a threat detection
and then canceled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274592</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the firewall did not fail over when the active firewall
experienced data plane issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273277</b></div>
</td>
<td class="entry relcol">
Fixed an issue where GlobalProtect clients on macOS devices were
prompted to enter their username and password for Kerberos SSO
authentication.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273153</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected due to excessive polling of the
<span class="ph systemoutput">MonitorDirect.getTasks</span> API by the
Task Manager.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device) sent
a Non-Maskable Interrupt (NMI) to the CPU.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271301</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments with
GWLB integrated only</tt
>) Fixed an issue where DNS queries timed out when overlay routing was
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268489</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed a Threat log PCAP ID overwrapping issue.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send an ICMP error packet to
Envoy when the MSS was exceeded
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267660</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where UserID stopped working when the
<span class="ph systemoutput">show object registered user</span> CLI
command was used with start-point and limit options.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265399</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS queries for uppercase internal domain (SRV
record) timed out when DNS Security was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264762</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall showed the status of SFP+ interfaces
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
connected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to a memory leak and buffer overrun.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261074</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall delayed video file transfers over
SMB when <span class="ph uicontrol">Exclude Video Traffic</span> from
the Tunnel feature was enabled and no applications were added to the
list.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260827</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall consumed excessive CPU while
processing traffic for a workload running on a GKE cluster, which
caused reduced throughput.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253921</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the following error
message:
<span class="ph systemoutput"
>critical userid register 0 fail to integrate the update of
registered ip addresses since 2 seconds ago; critical system log
alerts observed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent HIP notifications every time it
received a HIP report instead of every two hours.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246304</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits failed due to a timeout in
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
process during decryption.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,80 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SMTP packets were not sent out when the Client
Hello arrived at the firewall in multiple out-of-order segments and
the traffic was not subject to SSL decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall to reboot due to the
<span class="ph systemoutput">wifclient</span> exiting multiple times
when using IoT Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268800</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where the firewall failed to process FTP
traffic after upgrading to PAN-OS 10.1.14.
</div>
</td>
</tr>
</tbody>
</table>
+801
View File
@@ -0,0 +1,801 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a slow
buffer resource leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283813</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface performance was
slower than usual when retrieving read-only configurations from
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall was only able to display a maximum of
14 permitted IP addresses from a Panorama Template Variable.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282236</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large IPv6 packets were reassembled incorrectly
on the firewall when the packets arrived fragmented over an IPv4
tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processes stopped responding when HTTPS Forward
traffic was run.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279400</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when
<span class="ph uicontrol">Restrict Certificate Extension</span>s was
enabled on decryption profiles, the basic constraints extension was
overwritten incorrectly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278150</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the Authentication Key
Identifier (AKID) from the certificate during SSL decryption, which
caused Python 3.13 to fail with a certificate verification error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an memory leak issue related to TLS inbound decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277234</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a device group import resulted in a Security
policy rule being created with
<span class="ph uicontrol">Application</span> set to
<span class="ph uicontrol">none</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277147</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where daily scheduled reports were not generated and
emailed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became unresponsive while performing a
dynamic address update without a lock.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security intermittently logs malicious domain
URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a DPC on slot 3 failed intermittently due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pktlog_forwarding</a
>
process restarting, which resulted in an unexpected HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Wildfire signature generation was enabled on all
nodes in a cluster instead of only the active node.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP scans to a firewall timed out after
upgrading to a PAN-OS 10.2 release.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where restarting the firewall did not initiate an
autocommit job, which caused the firewall to stop responding and the
HA interface to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated BGP update packets larger
than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
were enabled globally.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272395</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where informational logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process log file to be frequently overwritten.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271425</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue with SSL inbound decryption on firewalls on a vwire
setup with asymmetric routing.
</div>
<div class="p">
To use this fix, enter the CLI command
<span class="ph systemoutput"
>set system setting ssl-decrypt ha-vwire-mac-learn global ye</span
>s on both firewalls in an HA pair.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271184</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Device Telemetry failed due to an issue with the
encoding of characters in the log file path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269677</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not check for a NULL pointer when
querying logs, which caused logs to not display on the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269291</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the scheduled report generation script did not
return debug information.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the wifclient stopped responding during server
certificate verification for MICA gRPC connections and caused the
dataplane to restart when using a cloud-based ML detection engine
(MICA). On certain platforms, this caused the firewall to reboot
periodically.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was blocked by a URL filtering profile
even though the Security policy rule did not have a URL filtering
profile configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to external dynamic lists that caused commit
times on the firewall to be higher than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268951</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a CPS counter query issue that caused SNMP polling timeouts on
the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268118</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/passive HA configurations where,
after a failover, irrelevant routing FIB entries were seen in the
routing table on the newly active firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267707</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BFD sessions did not come up even when BGP
peering was established.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the replay database size increased significantly
due to local and special configurations not being purged after
commits.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266900</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where you were unable to
click <span class="ph uicontrol">OK</span> after selecting an install
package type and file from the dropdown and selecting a firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265791</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the dataplane to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265646</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the config lock icon was not visible for a custom
role-based admin when a Superuser admin had acquired the config lock.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push was blocked when a configuration
load was done.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Preview Changes</span> did not display
configuration changes in
<span class="ph uicontrol">Commit and push &gt; Push Scope</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264169</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where the firewall sent correlated event logs to the syslog server
using the management interface instead of the log interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple DNS responses with different CNAME
values caused evasion false positive alerts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding and the firewall
unexpectedly rebooted due to multiple process restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262729</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process experienced continuous high CPU utilization and repeatedly
restarted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262540</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where application traffic transactions that reused TCP
ports did not work with decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decompress the HTTP2
header, which caused the session to be classified as unknown-tcp
instead of web-browsing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260300</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only</tt
>) Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process where DPC slot 3 stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260131</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Wildfire content installation failed for WF-500B
clusters when deployed from Panorama using the deployment schedule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane restarted due to
insufficient allocation of memory buffers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254577</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a core file was created on the Log Forwarding
Card due to a third-party software issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249011</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive when committing
a configuration change with a large number of uncommitted changes in
the replay database.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when TLSv1.3 was used, an incorrect error
message <span class="ph systemoutput">invalid padding</span> was
displayed instead of the expected error message
<span class="ph systemoutput">Invalid server certificate</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the client IP address was incorrect in the
authentication logs for Captive Portal authentication events when the
client used IPv6.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238594</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted when a QSFP28 cable was
removed from the port while the port was passing traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237010</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where local commits took longer than
expected after an upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233868</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall took an incorrect action for
overlapping custom and edl-url-categories in a policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/active HA configurations where
SYN+ACK packets of asymmetric TCP sessions were dropped because of a
session synchronization issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224833</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped DHCPv6 relay packets if
there were duplicate link-local addresses on different sub-interfaces.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212735</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions that were previously in sw-cut-through
mode (software fast forwarding) and persisted after an HA failover
were no longer subject to software fast forwarding, which led to
increased dataplane CPU load after HA failover.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+255
View File
@@ -0,0 +1,255 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 46.728971962616825%" />
<col style="width: 53.27102803738318%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP walks returned a value of 0 for the CPS
(Connections Per Second) per vsys on firewalls after upgrading to
PAN-OS 11.1.6-h3, even when active connections were present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290803</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where firewall failed to bootstrap with a custom
image, and VM-Series plugin information was not displayed in the
system information.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289763</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400f firewalls only</tt>) Fixed an issue where
SD-WAN SaaS monitoring did not work with URL monitoring.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">preferred_wnd</span> value provided by
CTD (Content Threat Detection) was disregarded due to TCP bandwidth
estimation, which prevented the window from closing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288363</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation</span>
<span class="ph systemoutput">_restore_timeout</span> not initiating
when the accumulation<span class="ph systemoutput">session_init</span>
failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits took longer than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287056</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP export policy rules with next-hop matching
failed to block the advertisement of static routes, and the firewall
incorrectly matched the egress interface IP address instead of the
original next-hop IP address of the static route, which caused the
deny rule to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when an application stopped responding, a large
file was created in the /opt/panlogs directory, which caused the
partition to fill up.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the logrcvr process
to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287002</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0133"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0133</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when getting transceiver information from ESCC
for SFP 25G modules, the transceiver code was incorrectly updated with
<span class="ph systemoutput">Unknown</span> instead of
<span class="ph systemoutput">25GBase-SR</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284744</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4229"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4229</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to log in to Panorama and the
following error message was displayed:
<span class="ph systemoutput">
Timed out while getting config lock. Please try again</span
>. This occurred when pushing configurations to a large number of
devices.
</div>
</td>
</tr>
</tbody>
</table>
+404
View File
@@ -0,0 +1,404 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 46.728971962616825%" />
<col style="width: 53.27102803738318%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297349</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295342</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding due to insufficient time allocated to read
file descriptors when processing long messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294770</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
Fixed an issue on firewalls where, after failover, certain subnets
were missing from the Link State Database, which prevented OSPF routes
from being immediately learned due to a Type-7 to Type-5 LSA
translation conflict in the ABR when the same LSA was advertised by
two peers in the NSSA area.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287842</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding due to missing heartbeats, which resulted
in a system alert and HA communication loss on slot1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287838</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
the web interface where resetting the rule hit counter for multiple
policy rules failed with the error message
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an OOM condition on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process caused interface flapping, and the interface unexpectedly went
down and then recovered without intervention.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls that were connected to the same Cloud
Identity Engine displayed inconsistent group membership information,
with some firewalls showing only a subset of users belonging to a
group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276484 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (<span class="ph uicontrol"
>Device Deployment &gt; Licenses</span
>) due to the inability to perform batch-license refreshes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277034</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire reports were not fully displayed and
were not downloadable due to static resources not being found.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected due to high CPU utilization on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mongodb</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-220293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall management plane could not display
BGP peer details when using the CLI command
<span class="ph systemoutput"
>show advanced-routing bgp peer detail logical-router
&lt;LR&gt;</span
>. This was due to the
<span class="ph systemoutput">bgp_frr.py</span> script failing to
parse the IPv6 address family section of the
<span class="ph systemoutput">show ip bgp neighbors json</span>
output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-191026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">debug log receiver statistics</span> CLI
command did not display entries for hipmatch logs.
</div>
</td>
</tr>
</tbody>
</table>
+450
View File
@@ -0,0 +1,450 @@
<table class="table colsep rowsep">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 46.728971962616825%" />
<col style="width: 53.27102803738318%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're using
a multivsys environment, you must upgrade your firewalls to a fixed
PAN-OS version. The best practice is to upgrade both the firewalls and
Panorama to a fixed PAN-OS version.
</div>
<div class="p">
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message
<span class="ph systemoutput"
>vsys name should end with a number vsys is invalid</span
>
after you
<span class="ph uicontrol">Export or push device config bundle</span>
from Panorama.
</div>
<div class="p">
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an
<span class="ph uicontrol">Export or Push device config bundle </span
>from Panorama to the firewall to fail. The workaround for PAN-214177
is to first push only the template configuration and then push the
device group configurations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297349</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294770</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
Fixed an issue on firewalls where, after failover, certain subnets
were missing from the Link State Database, which prevented OSPF routes
from being immediately learned due to a Type-7 to Type-5 LSA
translation conflict in the ABR when the same LSA was advertised by
two peers in the NSSA area.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where during a commit, the firewall experienced an
out-of-memory (OOM) condition due to a memory leak and displayed an
error message. This issue caused the device to stop responding and
reboot unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291288 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restart related to page allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a cumulative memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process that occurred whenever the CLI command
<span class="ph systemoutput"
>show running application statistics</span
>
was issued. This memory leak would gradually consume system memory and
produce an OOM condition, causing the firewall to reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls that were connected to the same Cloud
Identity Engine displayed inconsistent group membership information,
with some firewalls showing only a subset of users belonging to a
group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276484 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (<span class="ph uicontrol"
>Device Deployment &gt; Licenses</span
>) due to the inability to perform batch-license refreshes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected due to high CPU utilization on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mongodb</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-191026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">debug log receiver statistics</span> CLI
command did not display entries for hipmatch logs.
</div>
</td>
</tr>
</tbody>
</table>
+394
View File
@@ -0,0 +1,394 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">Fixes were made to address the following CVEs:</div>
<ul id="pan-os-10-2-10-h31-addressed-issues_ul-snk_4r1_gjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0265"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0265</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0264"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0264</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0262"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0262</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0261"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0261</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0258"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0258</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0256"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0256</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0259"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0259</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0300"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0300</a
>
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward traffic due to
memory issues on a forwarding component.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Strata Logging Service (SLS) even when duplicate
logging and enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305415</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits caused high dataplane CPU utilization and
briefly increased Packet Descriptors, which disrupted traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive after an upgrade
due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>fsck</a
>
command scanning drive partitions in parallel with the root partition,
which caused the process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297295</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295470</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process continuously increased its memory consumption, which resulted
in an OOM condition that caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286094</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward logs to SLS when
using a proxy server configuration due to an OCSP validation failure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242952</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high SSL traffic depleted flex memory, which
prevented the firewall from revalidating SSLVPN client CAs during
configuration pushes.
</div>
</td>
</tr>
</tbody>
</table>
+495
View File
@@ -0,0 +1,495 @@
<table class="table colsep rowsep">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289102</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
CN-Series firewalls only</tt
>) Fixed a race condition issue related to predict processing, which
resulted in a dataplane restart and traffic loss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287611</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading, the firewall incorrectly
calculated the UDP checksum for RTP traffic after NAT and Security
policy application, which led to dropped packets and silent calls in
applications.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286897</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding when the firewall attempted to forward
files to the WildFire public cloud, which caused the dataplane to
experience heartbeat failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286475</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the option to sort sequence numbers was missing
from <span class="ph uicontrol">Filters prefix list</span> in the
advanced routing filters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285941</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high memory consumption occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to reboot
unexpectedly, and traffic failures occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285590</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
only</tt
>) Fixed an issue where the firewall CPU usage reached 100% after
upgrading to PAN-OS 11.1.6-h1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where retrieving filenames from OneDrive resulted in a
cache miss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284840</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
custom reports were delayed when sent via email instead of being sent
at the scheduled time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the total number of logout
records in the HIP database incorrectly displayed as zero.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the SNMP polled values for
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
high number of errors that did not match the values in the CLI show
interface command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a slow NAT leak occurred when persistent NAT was
enabled. This occurred when ICMP sessions matched the persistent
Dynamic IP and Port (DIPP) rule and no predict sessions were involved
in that rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283428</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 Firewalls only</tt>) Fixed an issue where,
after an upgrade, the dataplane CPU reached 100% due to packet buffer
exhaustion, which resulted in general packet processing issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls became unstable and stopped responding,
which resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the popup window did not appear as expected for
Clientless VPN users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279706</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>)) Fixed an issue where
Panorama did not update all
<span class="ph systemoutput">panreplay</span> database entries after
performing a commit and full push to all devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where deleting the NTP server address caused a commit
validation error. This occurred when the configuration included both
primary and secondary NTP servers and the secondary server was
removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall skipped the DNS policy rule of a
domain external dynamic list (EDL) during an EDL refresh.
</div>
<div class="p">
To use this fix, run the following CLI command and commit:
<span class="ph systemoutput"
>set deviceconfig setting ctd custom-edl-domains-continuous-reload
yes/no</span
>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where socket files created in the /tmp directory were
not cleared.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268313</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
header were not reset to 0 when a packet was received from one Layer 3
tagged interface and forwarded to another, which resulted in dropped
packets.
</div>
<div class="p">
To use this fix, run the CLI command
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
reboot the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267707</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BFD sessions did not come up even when BGP
peering was established.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you enabled multihop in a BFD
profile, you were unable to disable it via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260132</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where secondary IP addresses with a /32 prefix
configured on Layer 3 interfaces were not reachable in FRR mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane restarted due to
insufficient allocation of memory buffers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when QoS was enabled on aggregate interfaces,
the maximum aggregate interface throughput was capped, which limited
network traffic. This occurred even with default QoS settings and no
configured egress max-bandwidth.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240606</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where licenses expired a day before the expiry date.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224729</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to create duplicate entries in
Advanced Routing AS path prepend in the BGP filter route map.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224020</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CIE validation checks on the firewall prevented
configuration pushes from Panorama, which resulted in commit failures
during new firewall deployment. This occurred when a template with an
Authentication Profile with the
<span class="ph uicontrol">Authentication Type</span> as
<span class="ph uicontrol">Cloud Authentication Service</span> was
pushed to a newly deployed firewall without internet access or without
a device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220435</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the GlobalProtect client failed to install on the firewall.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0257"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0257</a
>.
</div>
</td>
</tr>
</tbody>
</table>