Add 9.0 issues data

This commit is contained in:
2026-03-20 16:41:03 -05:00
parent ea9bd911aa
commit c562392486
23 changed files with 8995 additions and 2 deletions
@@ -0,0 +1,437 @@
---
type: Addressed
product: PAN-OS
version: 9.0.11
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-154092
An enhancement was made to provide an option to increase Data Plane Development Kit (DPDK) ring size and DPDK queue number for VM-Series firewalls deployed on ESXi.
## PAN-153983
Fixed an issue where the IPSec encapsulation sequence was not properly synced to the dataplanes on a high availability (HA) active/passive cluster.
## PAN-153813
Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks from the firewall to fail.
## PAN-153673
Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow.
## PAN-153436
Added CLI commands to increase thread limits to reduce task thread exhaustion on a process (configd).
## PAN-153111
Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane.
## PAN-152706
Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake.
## PAN-152285
Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher-than-expected session table usage.
## PAN-152106
Fixed an issue where a process (genindex.sh) caused the management plane CPU usage to remain high for a longer period of time than expected.
## PAN-152027
Fixed an issue with URL Filtering where websites that were previously in the malicious category but have since been cleared remained in the malicious category in the dataplane cache. These websites were moved to the benign category only after you manually cleared the cache.
## PAN-151203
Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets.
## PAN-151057
Fixed an issue where upgrading the capacity license on a VM-Series HA pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall.
## PAN-150750
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other.
## PAN-150748
Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets.
## PAN-150746
Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5.
## PAN-150613
Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**).
## PAN-150243
Fixed an issue where the candidate configuration was not updated to the running configuration after a successful commit when the commit was initiated by an API-privileges-only custom role-based administrator.
## PAN-149912
Fixed an issue where FIB entries were unexpectedly removed due to miscommunication between internal processes.
## PAN-149480
Fixed an issue where a custom report query from Panorama, which includes new fields not supported in prior releases, triggered a restart of a process (reportd) when Panorama was connected to log collectors running an earlier PAN-OS release.
## PAN-149426
Fixed an issue where non-superuser administrators with all rights enabled were unable to **Review Policies** or **Review Apps** for downloaded or installed content versions.
## PAN-149296
Fixed an issue on Panorama where system and configuration logs from dedicated Log Collectors did not display on Panorama appliances in Management Only mode.
## PAN-148564
Fixed an issue where Panorama stopped showing new logs when url_category_list was in the URL payload format of the HTTP(S) server profile used to forward URL logs from the Panorama Log Collector.
## PAN-147741
Fixed an issue where an API call for correlated events did not return any events .
## PAN-147595
Fixed an issue where stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information after a policy commit and session rematch.
## PAN-147285
Fixed an issue where host information profile (HIP) details were not available on Panorama even with a valid and active HIP redistribution configuration.
## PAN-146878
Fixed an issue where TCP traffic dropped due to TCP sequence checking in an HA active/active configuration where traffic was asymmetric.
## PAN-146650
A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)).
## PAN-146531
Fixed an issue where conversion from Panorama mode to logger mode was enabled even when an administrative user named admin did not exist in the configuration, which prevented access to the appliance after conversion.
## PAN-146506
Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall that was acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time.
## PAN-146284
Fixed an issue where Applications and Threats content installation failed on the firewall with the following error message: Error: Threat database handler failed.
## PAN-146117
Fixed an issue on the firewall where memory usage on a process (devsrvr) increased after running the show object dynamic-address-group all CLI command.
## PAN-146115
Fixed an issue where GlobalProtect™ IPSec connections flapped when the peer address to the gateway changed due to NAT.
## PAN-145823
Fixed an issue where BGP-learned routes were incorrectly populated with a VR error as a next hop.
## PAN-145757
Fixed an issue where a firewall process (all_pktproc) restarted while processing Session Traversal Utilities for NAT (STUN) over TCP.
## PAN-145752
Fixed an issue where exporting policies to PDF or CSV files did not include all policies and contained duplicates.
## PAN-145188
Fixed an issue on Panorama in PAN-DB mode where content updates did not successfully install, which caused the cloud state to degrade.
## PAN-145133
A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)).
## PAN-144919
Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity.
## PAN-144448
Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005).
## PAN-143959
Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface.
## PAN-143809
Fixed an issue where Log Collectors had problems ingesting older logs for previous days received at a high rate.
## PAN-143796
Fixed an issue where commits failed on the firewall due to memory allocation failure. You can check configuration memory using the debug dataplane show cfg-memstat statistics CLI command.
## PAN-141980
Fixed an issue where random member ports in a link aggregate group failed to join the aggregate group due to the following error: Link speed mismatch.
## PAN-141923
Fixed an issue where authentication stopped working after a commit and a process (authd) exited, which caused other processes to exit.
## PAN-141793
Fixed an issue where Panorama did not show correct logs filtered with not, leq, and geq.
## PAN-141717
Fixed an issue where an administrative user using custom admin roles and without access to the **Device** tab was unable to expand the detailed views of **Monitor > Logs**.
## PAN-141551
Fixed an issue where SSH service restart management did not take effect in the SSH management server profile.
## PAN-141262
Fixed an issue where the resolution of FQDN for a policy on the web interface did not work as expected if the FQDN contained CAPITAL letters.
## PAN-140900
Fixed an issue where IP address-to-tag mapping entries had negative time-to-live (TTL) values instead of being removed after expiry.
## PAN-140883
Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a process (snmpd), if the above OID was called before other OIDs, there was an approximate 10-second delay in populating the data pulled by each OID.
## PAN-140628
Fixed an issue where a memory leak on a process (useridd) caused multiple processes to restart during device serial number checks.
## PAN-140382
Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even when the DNS response was received before the session expired.
## PAN-140227
```caveat
PA-7000 Series firewalls only
```
Fixed a rare issue where the firewall rebooted due to a path monitoring failure on the Log Processing Card (LPC).
## PAN-140173
Fixed an issue where a large number of groups in group mapping caused a process (useridd) to stop responding.
## PAN-140157
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
## PAN-140121
Fixed an issue where a process (authid) used a large amount of memory due to many incomplete authentication requests, which caused an out-of-memory (OOM) condition.
## PAN-140084
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate was set to 2.
## PAN-139991
Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock.
## PAN-139680
Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption.
## PAN-139233
Fixed an issue where HIP reports failed to display on either the web interface or the CLI.
## PAN-139136
Fixed an issue where a large number of groups in group mappings caused a process (useridd) to stop responding.
## PAN-138938
An enhancement was made to reduce the memory usage of a process (logrcvr) to avoid out-of-memory (OOM) conditions on lower-end platforms.
## PAN-138674
Fixed an issue where custom role-based admins were able to reset the rule hit counter for disabled device groups.
## PAN-138427
Fixed an issue where pushing a configuration from a Panorama management server running PAN-OS 9.0 to a firewall running PAN-OS 8.1 produced a HTTP/2 warning. To leverage this fix, update both Panorama and the firewall to PAN-OS 9.0.11 or a later PAN-OS 9.0 release.
## PAN-137770
Fixed an issue where the dataplane restarted due to a loop in DoS protection source-destination IP address classification.
## PAN-137716
Fixed an issue where, for users with admin roles, logs for only one device group were displayed due to a query string with multiple device groups.
## PAN-137663
Fixed a cosmetic issue where misleading App-ID and rule shadowing warnings populated after a commit.
## PAN-136791
Fixed an intermittent issue where the first response to a SIP INVITE message created incorrect appinfo2ip entries and caused Via header translation failure.
## PAN-136716
```caveat
Panorama virtual appliances only
```
Fixed an issue where SNMP monitoring of ifSpeed reported the interface speed as 0 for interfaces other than eth0.
## PAN-136650
Fixed an issue where a Log Collector remained in an out-of-sync state after configuring an IP address (local or public) on an additional Ethernet interface.
## PAN-135887
Fixed an issue where the inner GTP-U flows were installed using incorrect zones, which led to traffic issues when the firewall was in line for the S1-U interface.
## PAN-135071
Fixed an issue in Panorama where the template stack drop-down was missing templates when using access domain.
This issue is fixed only for existing template stacks.
## PAN-134907
Fixed an issue where IP tags were not evaluated in the filter evaluation criteria when Dynamic Address Groups were configured.
## PAN-134745
Fixed an issue where Panorama commits failed due to a process (useridd) exceeding the maximum number of file descriptors while a large number of firewalls were connecting to Panorama for User-ID redistribution.
## PAN-134226
Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported.
## PAN-134029
Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped.
## PAN-133934
Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls.
## PAN-133388
Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall.
## PAN-133179
Fixed a rare issue where the show ntp CLI command showed the status as rejected even when the NTP was synced with at least one NTP server.
## PAN-132285
Fixed an intermittent issue where a Security policy with **Send ICMP Unreachable** enabled for certain drop or reset sessions caused a process (all-pktproc) to restart.
## PAN-132053
Added an enhancement to improve handling for firewall management web interface sessions that timeout so that the message Your session has expired does not display. Now, the web interface will present a timeout page that presents a button to redirect back to the login page.
## PAN-131750
Fixed an issue where a configuration push from Panorama to the firewall showed the **Commit All** status as complete even though the job was still in process.
## PAN-130955
Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node.
## PAN-130357
Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0.
## PAN-129376
```caveat
PA-800 Series firewalls only
```
Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so.
## PAN-128172
Fixed an issue on Panorama where the show system logdb-quota CLI command took more time than expected, which caused the configuration lock to time out.
## PAN-128048
Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors.
## PAN-125218
A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)).
## PAN-124819
Fixed an issue where only the current day's logs were visible on Panorama.
## PAN-124331
Fixed an issue where the LDAP query took longer than expected to populate in the web interface.
## PAN-122672
Fixed an issue where the firewall returned incorrect information about the logging service status when the information was requested through the web interface.
## PAN-122115
Fixed an issue with the session browser search where using more than 32 characters caused an error.
## PAN-121944
Fixed an issue where the **Device Connectivity** status was grey on the firewall web interface even when the SSL session with the logging service was successful.
## PAN-121035
Added support for high powered module PAN-QSFP28-100GBASE-ER4.
## PAN-120245
Fixed an issue on Panorama where WildFire® cloud content download failed for content deployment to the WF-500 appliance.
## PAN-119982
Fixed an issue where template variable view failed to display some template variables when the **Device Priority** type variable was configured.
## PAN-119329
Fixed an issue where a process (devsrvr) stopped responding when the firewall received corrupted data from the PAN-DB cloud.
## PAN-118667
Fixed an issue where firewall policy configurations displayed **[object Object]** instead of the object names.
## PAN-115896
Fixed an issue where the static route path monitoring status was not viewable from the CLI or web interface and failed with the following error message: failed to execute op command.
## PAN-115541
Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface.
## PAN-112449
Fixed an issue that caused a process (snmpd) to stop responding when sending a Simple Network Management Protocol (SNMP) GET request for LcLogUsageTable on a Panorama appliance in Management Only mode.
## PAN-110511
Fixed an issue where a passive Panorama appliance reported that device groups were out of sync despite a successful HA sync from the active Panorama appliance. This issue occurred when the address objects defined in the device group were in use under the corresponding template.
@@ -0,0 +1,35 @@
---
type: Addressed
product: PAN-OS
version: 9.0.14-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-176661
Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)).
## PAN-176655
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-158334
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-176653
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)).
## PAN-176618
A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)).
## PAN-171203
Fixed an issue in a high availability (HA) configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
## PAN-160708
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
@@ -0,0 +1,123 @@
---
type: Addressed
product: PAN-OS
version: 9.0.15
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-184592
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
## PAN-183767
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
## PAN-179581
Fixed an issue on firewalls in high availability (HA) configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
## PAN-174055
Fixed an issue where SNMP readings reported as 0 for dataplane interface packet statistics for Amazon Web Services (AWS) m5n.4xlarge instance types. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
## PAN-173978
Fixed an issue where the Elasticsearch process continuously restarted if zero-length files were present.
## PAN-172783
Fixed an issue on an HA active/passive configuration where old (GPRS tunneling protocol) GTP-U tunnel sessions did not sync to the passive firewall during some upgrades, such as upgrading from a PAN-OS 8.1 release version to a 9.0 release version or upgrading from a 9.0 release version to a 9.1 release version.
## PAN-172490
Fixed an issue on firewalls in HA configuration where HA-2 links continuously flapped on HSCI interfaces after upgrading to PAN-OS 8.1.19.
## PAN-172243
Fixed an issue where NetFlow traffic triggered a packet buffer leak.
## PAN-171203
Fixed an issue in an HA configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
## PAN-170825
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
## PAN-170595
Fixed an issue with Content and Threat Detection where traffic patterns created a bus error, which caused the all_pktproc process to stop responding and the dataplane to restart.
## PAN-166299
```caveat
PA-3000 Series firewalls only
```
Fixed an issue where Server Message Block (SMB) sessions failed due to resource unavailability.
## PAN-166180
Fixed an issue where SNMPV3 traps were not processed by the snmptrap receiver after a firewall reboot.
## PAN-161496
Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to pan_in_cksm32_diff overflowed the 32-bit integer.
## PAN-160708
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
## PAN-160238
Fixed an issue where intermittent VXLAN packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
## PAN-158280
Fixed an issue where SMB session were discarded with the following error message: ctd out of resource.
## PAN-157730
Fixed an issue where, after a firewall reboot, a commit or auto-commit operation failed with the following error message: ID population failed. This issue occurred because the Phase1 ID assignment failure did not trigger an idmgr reset.
## PAN-157725
Fixed an issue on firewalls where URL category responses were not processed by the dataplane in a timely fashion, which adversely affected web-browsing traffic.
## PAN-157632
Fixed an intermittent issue where the firewall dropped GTP-U traffic with the message TEID=0x00000000.
## PAN-154526
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
## PAN-154433
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
## PAN-150097
Fixed an issue where hourly URL summary log generation failed.
## PAN-147256
```caveat
Firewalls in HA configurations only
```
Fixed an issue where connections to the SafeNet hardware security module (HSM) were lost after upgrading to a new major PAN-OS release.
## PAN-141454
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
## PAN-128634
A debug command was added to provide more verbose output when troubleshooting packet processing on the firewall.
## PAN-113093
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,71 @@
---
type: Addressed
product: PAN-OS
version: 9.0.16
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-179581
Fixed an issue on firewalls in high availability (HA) configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
## PAN-177551
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
## PAN-176703
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
## PAN-175716
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
## PAN-175211
Fixed a memory leak issue in the mgmtsrvr process.
## PAN-174998
```caveat
M-200 and M-500 appliances only
```
Fixed a capacity issue that was caused by high operational activity and large configurations. This fix increases the virtual memory limit on the configd process to 32GB.
## PAN-174709
Fixed an out-of-memory (OOM) condition that occurred due to multiple parallel jobs being created by the scheduled log export feature.
## PAN-170997
Fixed an issue where FQDN service routes were not installed after a system reboot.
## PAN-170952
Fixed an issue where the dataplane failed due to path monitor failure.
## PAN-163245
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
## PAN-161940
Fixed an issue where the firewall did not honor the peer RX interval timeout in a Bidirectional Forwarding Detection (BFD) INIT state.
## PAN-161297
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
## PAN-159936
Fixed an issue where BGP routing stopped advertising a redistributed route when a similar new redistributed route was configured.
## PAN-155532
Fixed an issue where the mgmtsrv process restarted due to a missing protective check around access to potentially NULL pointers.
## PAN-149911
Fixed an issue where URL filtering logs for credential phishing displayed a slash character ( / ) in the URL field.
@@ -0,0 +1,79 @@
---
type: Addressed
product: PAN-OS
version: 9.0.17-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-221224
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-227523
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-218663
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-216216
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-224964
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-221352
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-220267
```caveat
and PAN-216858
```
A fix was made to address customer and internal bugs.
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 9.0.2-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-119745
A security-related fix was made to address the Netflix Linux kernel TCP SACK vulnerability ([PAN-SA-2019-0013](https://securityadvisories.paloaltonetworks.com/Home/Detail/151) / CVE-2019-11477,CVE-2019-11478,CVE-2019-11479, and CVE-2019-5599).
## PAN-118869
A security-related fix was made to address an issue where the php-debug log incorrectly displayed non-sanitized data ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
## PAN-107239
A security-related fix was made to address cleartext passwords and keys that were visible in the logs for XML API calls ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
@@ -0,0 +1,193 @@
---
type: Addressed
product: PAN-OS
version: 9.0.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5023
Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data.
## WF500-5022
Fixed an issue where a non-functioning CLI command was removed from WF-500 appliances.
## WF500-4974
Fixed an issue on a WF-500 appliance where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface.
## WF500-4844
Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail.
## WF500-4838
Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout.
## WF500-4784
Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: FATAL: module nbd not found.
## WF500-4743
Fixed an intermittent issue on a WF-500 appliance where the CLI command debug wildfire reset global-database fix became unresponsive.
## PAN-118065
```caveat
M-Series Panorama™ management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the show interface all command in the CLI after you commit.
**Workaround:**Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116919
```caveat
Microsoft Azure only
```
Fixed an issue where the firewall dropped packets passing through IPSec tunnels if you enabled jumbo frames (**Device** > **Setup** > **Session** > **Session Settings**).
## PAN-116658
Fixed a rare issue where the firewall sent HTTP/2 DATA frames with incorrect padding byte lengths, which caused software buffer corruption and a process (all_pktproc) to stop responding.
## PAN-116316
Fixed an issue where RTP and RTCP predict sessions failed, which caused the firewall to stop processing RTSP-based video streaming.
## PAN-116084
Fixed an issue where a VM-Series firewall on Microsoft Azure deployed using MMAP dropped traffic when the firewall was experiencing heavy traffic.
## PAN-115592
Fixed an issue where the firewall rebooted due to a plugin memory leak.
## PAN-115591
Fixed an issue where the snmpd process was leaking memory when polling for global counters.
## PAN-114984
Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details.
## PAN-114893
Fixed an issue where a context switch from Panorama to a firewall did not respond as expected when a web browser was used.
## PAN-114804
Fixed an issue where a configuration change resets to "default" when you conducted a search in the Categories (**Objects** > **URL Filtering** > **Categories**) web interface.
## PAN-114601
Fixed an issue where the Allow List (**Device** > **Setup** > **Authentication Setting** > **<authentication profile - name>** > **Authentication**) did not update after you added new users to a group in the Active Directory.
## PAN-114255
Fixed an issue where Bidirectional Forwarding Detection (BFD) went down temporarily during a commit or EDL refresh if you configured a large value for the BFD Hold Time.
## PAN-114003
Fixed an issue on a Panorama management server running PAN-OS 9.0 where a context switch to firewalls did not respond.
## PAN-113829
Fixed an issue where, after you upgraded the firewall to PAN-OS® 9.0, a firewall configured from "none" to "allow" in the custom URL category reverted to "none" after a commit.
## PAN-113692
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions.
## PAN-113608
Fixed an issue on a firewall with packet capture (pcap) enabled where the log receiver stopped responding when larger than expected packets were received.
## PAN-113414
Fixed an issue where the User-ID™ (useridd) process stopped responding.
## PAN-112815
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **<group mapping-name>** > **User and Group Attributes**) on the passive firewall during a restart.
## PAN-112814
Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic.
## PAN-112729
Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Sessions**) did not display as expected for VM-Series firewalls.
## PAN-112699
```caveat
VM-Series firewall on AWS running on a C5 or M5 instance only
```
Fixed an issue where you were unable use the mgmt-interface-swap command to [swap the interfaces](https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/about-the-vm-series-firewall-on-aws/management-interface-mapping-for-use-with-amazon-elb.html) for deploying a VM-Series firewall behind a web load balancer (such as AWS ALB or Classic ELB).
## PAN-112626
Fixed an issue where a new DNS Security subscription was not available on your VM-Series firewall after you upgraded to a PAN-OS 9.0® release with a PAYG Bundle 2 license.
## PAN-112445
Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap.
## PAN-112340
Fixed an issue with performance, including high CPU usage, that occurred when you enabled URL Filtering without enabling Threat Prevention in an environment that processes a large number (thousands) of URL look-ups per second per dataplane.
## PAN-112194
Fixed an issue where packet buffers did not release GlobalProtect™ clientless VPN packets, which caused the firewall to stop responding.
## PAN-111679
Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit.
## PAN-111553
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will **Include Device and Network Templates** by default.
## PAN-111540
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
## PAN-111251
Fixed an issue where administrators were unable to use the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule (they were able to execute the command but the firewall did not implement the change).
## PAN-110390
Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall.
## PAN-110273
Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted.
## PAN-109672
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) is enabled.
## PAN-109344
Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names.
## PAN-108374
Fixed an issue on GlobalProtect where you were unable to authenticate when the domain name included the ampersand ( "&" ) character.
## PAN-106518
Fixed an issue on Panorama M-Series and virtual appliances where predefined DHCP options did not accept template variables when you configured a DHCP server for a template.
## PAN-101341
Fixed an issue where administrators configured with Device Group and Template Admin type were unable to perform a global search and returned the following message: Unauthorized request.
@@ -0,0 +1,23 @@
---
type: Addressed
product: PAN-OS
version: 9.0.3-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-123700
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS® software ([PAN-SA-2019-0023](https://securityadvisories.paloaltonetworks.com/Home/Detail/161) / CVE-2019-1582).
## PAN-123603
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS software ([PAN-SA-2019-0021](https://securityadvisories.paloaltonetworks.com/Home/Detail/159) / CVE-2019-1580).
## PAN-123564
Fixed CVE-2019-1581, see [PAN-SA-2019-0022](https://securityadvisories.paloaltonetworks.com/Home/Detail/160) for details.
## PAN-121814
Fixed an issue where the threat log incorrectly displayed informational severity-level threats with high severity level.
@@ -0,0 +1,521 @@
---
type: Addressed
product: PAN-OS
version: 9.0.3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4995
Fixed an issue on Panorama™ M-Series and WF-500 appliances where administrators were unable to run the debugsoftware disk-usage aggressive-cleaning enable CLI command and resulted in the following error message: Server error:Failed to execute op command.
## PAN-118949
Fixed an issue where after you changed the filter configuration in the user.src notin 'cns\proxy full profile, the firewall displayed the following error message: Unknown user group cns\Proxy Full.
## PAN-118640
Fixed an issue where the GTP-U session did not match the correct policy, which caused the IMSI and IMEI not to display in the inner session traffic and threat logs.
## PAN-118525
```caveat
PA-5250, PA-5260, PA-5280, and PA-7000 Series firewalls only
```
Fixed an issue where the QSFP28 port did not come up with the TR-FC13L-N00 version of the PAN-QSFP28-100GBASE-LR4 optical transceiver on firewalls running a PAN-OS 9.0 release.
## PAN-118008
```caveat
PA-3000 Series firewalls only
```
Fixed an intermittent issue where a low memory condition prevented decoders from loading, which led to traffic inspection issues related to the impacted decoder(s).
## PAN-117424
[Cortex Data Lake without Panorama](https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/management-features/cortex-data-lake-without-panorama.html)—where we removed Panorama as a requirement to send logs to Cortex Data Lake—was introduced in PAN-OS® 9.0.2, and was not initially supported for PA-220 and PA-800 Series firewalls. This issue details a change we've made in PAN-OS 9.0.3 to support this feature across all firewall platforms. [Heres](https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/management-features/cortex-data-lake-without-panorama.html) how you can get started with Cortex Data Lake now.
## PAN-117359
```caveat
Firewalls with an AutoFocus license only
```
Fixed an issue where AutoFocus™ threat intelligence did not display when hovering over source and destination addresses in the logs when you configure a service route or proxy.
## PAN-117249
Fixed an issue where end users who don't have REST API authentication roles were able to list and edit configuration rules.
## PAN-117149
Fixed an issue on firewalls configured with authentication policies where sessions matching an authentication policy did not generate traffic logs as defined in the security policy when sessions were redirected or denied.
## PAN-116969
Fixed an issue where authentication failed when you configured a User Principal Name (UPN) and included a group in the profile.
## PAN-116848
Fixed an issue where multiple device group administrators simultaneously enabled configuration locks caused a race condition.
## PAN-116828
Fixed an issue on Panorama M-Series and virtual appliances where the management server and a process (configd) used higher than expected CPU and memory.
## PAN-116069
```caveat
PA-200 firewalls only
```
Fixed a rare out-of-memory (OOM) condition.
## PAN-116579
Fixed an issue where the firewall sent truncated URLs to the Captive Portal Redirect message when HTTPS traffic sent through a proxy server was subjected to decryption.
## PAN-116188
Fixed an issue where communication between tunnel interfaces did not respond when you configured a generic routing encapsulation (GRE) tunnel.
## PAN-116022
Fixed an issue where the NSX Manager passed a blank string to Panorama, which added a null entry into the configuration and caused commits to fail.
## PAN-115930
Fixed an intermittent issue where after a configuration change, a commit caused the dataplane to stop responding.
## PAN-115526
Fixed an issue where a dataplane process (all_pktproc) stopped responding due to a packet buffer protection feature.
## PAN-115494
Fixed an issue where the /opt/pancfg/ partition became full due to a configuration preview operation not responding.
## PAN-115415
Fixed an issue where a session created from a predict session went into DISCARD state.
## PAN-115379
Fixed an issue where you were unable to create a custom log forwarding profile when you configured a filter with the "in" and "not in" configurations (**Objects** > **Log Forwarding** > **Add** > **Add** > **Filter** > **Filter Builder**) and resulted in the following error message: Invalid filter policy-logging-cf-ent -> match-list -> ITS_url_logs -> filteris invalid.
## PAN-115339
Fixed a rare issue where a commit caused the firewall to stop responding when you enabled flow debug and configured a NAT policy.
## PAN-115035
Fixed a rare issue where **Traffic** logs, **Threat** logs and **URL filtering** logs stopped generating.
## PAN-115012
Fixed an issue where a process (appweb) stopped responding, which caused the web interface to stop responding.
## PAN-114867
Fixed an issue where GlobalProtect™ gateway client configuration generation failed when a matching rule existed.
## PAN-114743
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall to PAN-OS 8.1, commits failed when Panorama was configured to manage shared gateway objects for managed firewalls.
## PAN-114695
Fixed an issue where a daemon (authd) stopped responding when you configured a GlobalProtect portal and gateway with Security Assertion Markup Language (SAML) authentication.
## PAN-114642
Fixed an issue where firewall logs incorrectly included the end-user IP address in GTP message logs when you configured PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
## PAN-114607
Fixed an issue where all the log collectors did not get queued when you configured more than 32 collector groups.
## PAN-114593
Fixed an issue where the setsystem setting layer4-checksum disable CLI command did not disable the Layer 4 checksum check as expected.
## PAN-114577
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to authenticate when the authentication profile contained a server profile that used the FQDN of the server.
## PAN-114437
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall from PAN-OS 8.0.8 to PAN-OS 8.1.4, commits took longer than expected when you configured the Device Group with large group hierarchies.
## PAN-114435
Fixed an issue where multiple dataplanes stopped responding and caused traffic outages after you enabled IPSec tunnels.
## PAN-114434
Fixed an issue where the firewall created incorrect predict sessions, which caused flow sessions to fail for applications.
## PAN-114403
Fixed an issue on Panorama M-Series and virtual appliances where serial numbers for deployed firewalls did not display in the web interface with the exception of GlobalProtect cloud service firewalls.
## PAN-114395
Fixed an issue on a VM-Series firewall where a process (all_task) stopped responding, which caused the firewall to reboot.
## PAN-114275
Fixed an issue where the firewall dropped GTPv1 DELETE PDP response packets that had a termination endpoint ID (TEID) value of 0.
## PAN-114181
Fixed an issue where the firewall incorrectly triggered Reverse Path Forwarding (RPF), which caused packet leaks.
## PAN-113795
Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (all_pkts) stopped responding, which caused the dataplane to restart.
## PAN-113775
Fixed an issue where the firewall dropped UpdatePDPContext reponse packets and displayed the following GTP log event: 122113.
## PAN-113631
A security-related fix was made to address a use-after-free (UAF) vulnerability in the Linux kernel ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2019-8912)
## PAN-113614
Fixed an issue with a memory leak on Panorama appliances associated with commits that eventually caused an unexpected restart of the configuration (configd) process.
## PAN-113340
```caveat
PA-200 firewalls only
```
Fixed an issue where the management plane (MP) memory was lower than expected, which caused the MP to restart.
## PAN-113189
A security-related fix was made to correct log file string-conversion errors that caused parsing issues, which caused the User-ID™ (useridd) process to stop running.
## PAN-113117
Fixed an issue on Panorama VM-Series firewalls where you were logged out of the web interface and had to log back in to push a device group and template configuration from a newly launched bootstrapped firewall.
## PAN-113046
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where a process (brdagent) stopped responding, which caused the management plane to stop responding.
## PAN-112674
Fixed an issue where an escape ( “\” ) character was added to HTTP log s when a log contained a comma.
## PAN-112577
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the HA1 port flapped and caused a split-brain condition.
## PAN-112446
Fixed an issue where a predefined report (blocked credential post) generated reports using the incorrect query builder (flags has credential-builder), which caused the report to incorrectly display logs for alerts.
## PAN-112293
Fixed an issue where the connection between the firewall and Log Collector flapped.
## PAN-112167
Fixed an issue where IPv4 BGP routes were missing from the routing table and FIB after a failover event.
## PAN-112106
Fixed an issue where the firewall was unable to add IPv6 loopback IP address ::1 to the external dynamic list and displayed the following error message: Invalid ips: ::1.
## PAN-111976
Fixed an issue where you were unable to generate user activity reports when the username included a colon ( : ), ampersand ( & ), single parenthesis ( ' ) character.
## PAN-111872
A security-related fix was made to address a command injection vulnerability ([PAN-SA-2019-0018](https://securityadvisories.paloaltonetworks.com/Home/Detail/156) / CVE-2019-1576).
## PAN-111708
```caveat
PA-3200 Series firewalls only
```
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command.
## PAN-111380
```caveat
PA-5200, PA-3200, and PA-7000 Series firewalls with 100Gbps cards only
```
Fixed an issue where the show qos interface ae1 throughput 0 CLI command incorrectly displayed the active data stream only and QoS was not working as expected on the first subinterface.
## PAN-111286
Fixed an issue where you were unable to generate a custom report (**Monitor** > **Manage Custom Report** > **<device-name>** > **Report Setting**).
## PAN-110996
Fixed an issue where the dataplane stopped responding due to an incorrectly calculated offset when you configured **Exclude video traffic from the tunnel** (**Network** > **GlobalProtect** > **Gateways** > **<gateway-name>** > **Agent** > **Video Traffic**).
## PAN-110962
Fixed an issue where a process (all_pktproc) stopped responding when SSH decryption was enabled, which caused the dataplane to restart.
## PAN-110883
Fixed an issue on a VM-Series firewall where all jobs did not execute and returned the following error message: Error- time out sending/receiving message.
## PAN-110873
Fixed an issue where member interfaces of the aggregate interface did not display on web interface (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Interfaces**).
## PAN-110758
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure the firewall to disable the portal log in page.
## PAN-110638
Fixed an issue where you were unable to establish a GlobalProtect connection on IPv6 and displayed the following error message: Packet too big due to the firewall MTU value set lower than normal on the neighboring firewall.
## PAN-110548
Fixed an intermittent issue where heartbeats failed on the management plane (MP), which caused the dataplane to stop responding and displayed the following error message: Dataplaneis down: controlplane exit failure.
## PAN-110526
Fixed an issue where Captive Portal authentication required two log-in attempts when the authentication sequence was configured as an authentication profile.
## PAN-110293
Fixed an issue where GTP-U traffic dropped when the GTP tunnel endpoint ID (TEID) was not updated correctly during a GTP-C update.
## PAN-109966
Fixed an issue where the content update threshold downloaded and installed an older content version after you manually installed a newer content version.
## PAN-109954
Fixed an issue where a commit failed with an error message: cluster is missing 'encryption' when HA Traffic Encryption (**Panorama** > **Managed WildFire Clusters** > **<appliance-name>** > **Communication**) was not configured and after upgrading from PAN-OS 8.0.12 to PAN-OS 8.1.4.
## PAN-109944
Fixed an intermittent issue where a process (configd) restarted due to a race condition when generating custom reports.
## PAN-109663
Fixed an intermittent issue where the firewall dropped packets when the policy rule was set to allow but denied the packets during a commit or high availability (HA) sync.
## PAN-109837
Fixed an issue where a race condition occurred when a configuration push and NetFlow update occurred simultaneously, which caused the dataplane to restart.
## PAN-109575
Fixed an issue where you were unable to configure more than one device certificate (**Device** > **Certificate Management** > **Certificates** > **<device certificate-name>**) with **Trusted Root CA**.
## PAN-109336
```caveat
PA-500 and PA-800 Series firewalls only
```
Fixed an issue where commits failed after you imported a device state from Panorama the template configuration referenced Bidirectional Forwarding Detection (BFD).
## PAN-109186
Fixed an issue where the dataplane stopped responding and caused a failover event.
## PAN-109101
Fixed an issue where you were unable to override IKE Gateway configurations (**Network** > **IKE Gateways** > **<template-name>**) in the template stack. However, with this fix, you still cannot override template stacks when you configure any value with **none**. Additionally, to override the Local Identification, select **Authentication** in the pop-up dialogue.
## PAN-109024
Fixed an issue where, after you upgrade the firewall from PAN-OS 8.0 to PAN-OS 8.1, firewalls configured with the User-ID agent and group mapping incorrectly mapped users to groups.
## PAN-108990
Fixed an intermittent issue on a firewall where configuring **Force Template Values** (**Network** > **Interfaces** > **Commit** > **Push to Devices** > **Templates**) deleted the zone assigned to an interface.
## PAN-108878
Fixed an issue where host traffic ICMP packets larger than 9,180 bytes dropped when you configured a jumbo frame with a maximum MTU value of 9,216 bytes and with the DF option enabled.
## PAN-108846
Fixed an issue where a higher than expected rate of tunnel resolution packets occurred due to an internal loop, which caused a spike in dataplane CPU usage for firewalls that support distributed tunnel ownership.
## PAN-108785
Fixed an intermittent issue on a firewall in an HA active/passive configuration where a ping test stopped responding on Ethernet 1/1, 1/2, and 1/4 due to input errors on the corresponding switch port after a HA failover.
## PAN-108715
Fixed an issue where the firewall did not update the dataplane DNS cache after the management plane (MP) DNS entries expired, which caused evasion signatures to erroneously trigger a Suspicious TLS/HTTP(S)Evasion Found event.
## PAN-108164
Fixed an issue where a process (tund) caused the dataplane to restart during a commit.
## PAN-107989
Fixed an issue where the Strict IP Address Check incorrectly triggered when you enabled ECMP (**Network** > **Virtual Routers** > **Add** > **Router settings** > **ECMP**).
## PAN-107662
Fixed an issue on a firewall in an HA active/active configuration where client-bound DHCPv6 packets dropped when you configured the firewall as a DHCPv6 relay agent.
## PAN-107370
Fixed an issue where IPv6 traffic throughput reduced more than expected after you updated a static ND entry (**Network** > **Interfaces** > **<interface-name>** > **Advanced** > **ND Entries**) by moving the interface to a different virtual router.
## PAN-107126
Fixed an issue where an SSL inbound session cache corruption caused a process (all_pktproc) to stop responding.
## PAN-106861
Fixed an issue where stale route entries remained in the FIB after the routes were removed from the routing table when you used a redistribution rule without a profile.
## PAN-106857
Fixed an issue where the dataplane restarted due to an internal path monitoring failure Caused by large SSL decrypted file transfer sessions.
## PAN-106543
Fixed an issue on a firewall in an HA active/active configuration where the show vpn ipsec-sa CLI command incorrectly returned an error message: Server error: An error occurred. See dagger.log for information when you ran the command on the active secondary firewall.
## PAN-106344
Fixed an issue where the log collector within a collector group retained varying numbers of detailed firewall logs when you enabled log redundancy.
## PAN-106274
Fixed an issue on a firewall where a Layer 2 interface that contained a VLAN sub-interface in conjunction with policy based forwarding (PBF) caused the firewall to forward the return traffic to the incorrect web interface.
## PAN-106259
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall reported a higher number of GlobalProtect user accounts than the active firewall.
## PAN-105925
Fixed an issue where the GlobalProtect Gateway web interface did not display the list of previous users.
## PAN-105412
Fixed an issue where forward error correction (FEC) was disabled by default for AOC modules, which caused QSFP ports to flap or remain in the DOWN state. With this fix, FEC is enabled by default for AOC modules.
## PAN-105397
Fixed an issue where a firewall incorrectly processed path monitoring, which originated from a NAT firewall on the same network segment.
## PAN-105091
Fixed an issue on a firewall where stateful inspection failed, which caused the firewall to drop GTPv2-C Modify Bearer Request packets.
## PAN-104568
Fixed an issue where the firewall did not send emails when you configured the email gateway with an FQDN.
## PAN-104274
Addressed an issue where in a slow network environment the firewall displayed an error message: error online 1 at column 1: document is empty when you used an API call to fetch a license even when the auth code was successfully applied. Extremely slow networks may still see this issue.
## PAN-103285
Fixed an issue where an API call (show system disk details), responded with the following error message: An error occurred. See dagger.log for information.
## PAN-103225
Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager did not display progress after you pushed a configuration to a firewall.
## PAN-102979
Fixed an issue where Dynamic Updates did not display expired threat prevention licenses when you tried to install an application from Panorama.
## PAN-102745
Fixed an intermittent issue on a firewall where a commit and FQDN refresh took longer than expected.
## PAN-101970
Fixed an issue where the decode filter was unable to detect the end characters of a file name, which caused the firewall to bypass the file blocking profile.
## PAN-101764
Fixed an issue where a process (slmgr) stopped responding during an auto-commit.
## PAN-101379
Fixed an issue where an invalid Captive Portal authentication policy was successfully pushed to managed firewalls, which caused auto-commits to fail.
## PAN-101052
Fixed an issue on Panorama M-Series and virtual appliances where Panorama unnecessarily checked and updated licenses for VM-Series firewalls on AWS after every commit, which resulted in new log entries. With this fix, Panorama no longer checks licenses after every commit.
## PAN-100773
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) port on a 20GQ NPC card took longer than expected to respond.
## PAN-100742
Fixed an issue Panorama M-Series and virtual appliances where scheduled reports generated more than one DNS lookups, which caused inconsistent name resolutions for DNS deployments.
## PAN-100693
Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character.
## PAN-99483
```caveat
PA-5250, PA-5260, and PA-5280
```
Fixed an issue where, when you deployed the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems were limited to using a translated IP address-and-port pair for only one connection.
See [Limitations](/content/techdocs/en_US/pan-os/9-0/pan-os-release-notes/pan-os-9-0-release-information/limitations.html#id1787F0E08SZ) for PA-7000 Series firewalls that do not use second-generation PA-7050-SMC-B or PA-7080-SMC-B Switch Management Cards.
## PAN-99354
Fixed an issue where the firewall incorrectly denied URL access when the URL filtering profile was configured to alert.
## PAN-99134
Fixed an issue where temporary files generated during preview changes did not get cleared, which caused disk space issues.
## PAN-98746
Fixed an issue where GlobalProtect clientless VPN did not get redirected to the application URL when you used Internet Explorer as a web browser.
## PAN-97288
Fixed an issue on GlobalProtect Clientless VPN where the URL gets truncated when you exclude the domain from the Rewrite Exclude Domain List (**Network** > **GlobalProtect** > **Portals** > **<portal-name>** > **Clientless VPN** > **Advanced Settings**).
## PAN-92872
Fixed an intermittent issue where the firewall sent packets incorrectly to an outgoing interface.
## PAN-89820
Fixed an intermittent issue where the Data Filtering (**Monitor** > **Data Filtering**) and Threat Log (**Monitor** > **Threat**) did not display file names when you transferred multiple files into a single session.
## PAN-81778
Fixed an issue where scheduled reports did not generate as expected due to a race condition.
@@ -0,0 +1,555 @@
---
type: Addressed
product: PAN-OS
version: 9.0.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5137
Fixed an issue where the show wildfire global last-device-registration all CLI command incorrectly returned an error message: Failed, even when you registered the firewall correctly.
## PAN-128561
Fixed an issue where a process (all_pktproc) stopped responding after you upgraded the firewall to PAN-OS® 9.0.4.
## PAN-128324
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where internal path monitoring failures occurred due to either a buffer leak or buffer corruption.
## PAN-127932
Fixed an issue where the REST API reference did not display the web browser documentation, which resulted in an error when running a PAN-OS 9.0.4 release.
## PAN-127807
Fixed an issue on Panorama™ M-Series and virtual appliances where a process (configd) stopped responding when you performed a commit to a large number of firewalls.
## PAN-127189
Fixed an issue where images displayed through the Clientless VPN were corrupted.
## PAN-126921
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where internal path monitoring failed when the firewall processed corrupt packets.
## PAN-126697
Fixed an HTTPD issue with PHP where it leaked memory.
## PAN-126547
Fixed an issue where a process (configd) stopped responding when an XML API call with type=config&action=get triggered during a commit.
## PAN-126534
```caveat
PAN-OS 8.1.10 and later releases only
```
Fixed an issue where the data from Security policies did not export as expected.
## PAN-126354
Fixed an issue where log in and commits took longer than expected when you used XML API calls to create new address objects.
## PAN-125933
Fixed an issue where the receiving firewall deleted the host information profile (HIP) report due to the report containing the same IPv4 address in the IP and IP2 fields and caused a process (useridd) to stop responding.
## PAN-125833
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a daemon (routed) did not receive the updated interface status after an HA failover, which caused routes to remain in the routing and FIB tables.
## PAN-125775
Fixed an issue where Panorama management servers deployed using the C5 or M5 instance types on Amazon Web Services (AWS) caused the Panorama instance to stop responding in regions that supported these instance types.
## PAN-125517
An enhancement was made to improve firewall performance for stream control transmission protocol (SCTP) flows. To enable this enhancement, run the set sctp fast-sack yes CLI command.
## PAN-125515
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
## PAN-125478
Fixed an issue on a firewall in an HA active/passive configuration where the route to the passive firewall dropped during a failover.
## PAN-125452
Fixed an issue where the firewall did not list registered addresses from the Dynamic Address Group when the same IP-tag information was received from two sources, which caused the traffic flow to stop responding as expected.
## PAN-125346
An enhancement was made to enable you to configure IPv6 in the web interface and through a CLI command when you added IPv6 virtual addresses to a firewall in an HA active/active configuration.
## PAN-125121
```caveat
VM-Series firewalls only
```
Fixed an issue where custom images did not function as expected for PAN-OS 9.0.
## PAN-125069
An enhancement was made to enable you to delete the GTP-C tunnel with all GTP-U tunnel sessions after the firewall received a Delete Bearer Response message where default bearer ID=5. To enable this enhancement, run the set gtp ebi5-del-gtpc [yes/no] CLI command.
## PAN-124996
Fixed an issue where a GlobalProtect™ daemon (rasmgr) stopped responding when you connected with an overlapping IPv6 address, which caused subsequent GlobalProtect connections to fail.
## PAN-124890
Fixed a configuration lock issue where you were unable to log in after you upgraded from PAN-OS 8.1.6 to PAN-OS 8.1.9.
## PAN-124630
Fixed an issue where new logs were not ingested due to a buffer exhaustion condition caused by invalid messages incorrectly handled by elastic search.
## PAN-124481
Fixed an issue where the dataplane stopped responding when SMTP sessions were used.
## PAN-124299
Fixed an issue on VM-Series firewalls in an HA active/passive configuration where the active firewall leaked packet buffers when links were disconnected from the hypervisor.
## PAN-123850
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an issue where conflicting GTP sessions were installed in short interval, which caused the firewall to queue GTP packets and deplete packet buffers.
## PAN-123600
Fixed an issue where the firewall was unable to establish a connection to the DNS Security feature domain (dns.service.paloaltonetworks.com) when the firewall could not connect with the primary DNS server but could connect with the secondary DNS server.
## PAN-123446
Fixed an issue where an administrator with a Superuser role could not reset administrator credentials.
## PAN-123362
Fixed an issue where the firewall used more than expected virtual memory when you decreased the maximum elastic search heap size.
## PAN-123190
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) restarted multiple times and caused the firewall to reboot.
## PAN-123030
Fixed an issue with a memory leak associated with a process (mgmtsrvr) when you pushed a commit.
## PAN-122662
```caveat
PA-5260 firewalls only
```
Fixed an issue where a process (mpreplay) stopped responding after a commit when you configured the firewall with more than 200 virtual systems (vsys) running on PAN-OS 8.1.9.
## PAN-122601
Fixed a memory leak issue with a process (configd) when you performed device group related operations.
## PAN-122550
Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver.
## PAN-121945
Fixed an issue on Panorama M-Series and virtual appliances where after you deployed the firewall in Google Cloud the Panorama serial console stopped responding.
## PAN-121911
Fixed an issue where a process (logrcvr) restarted during commits.
## PAN-121667
Fixed an issue where traffic incorrectly matched Security policies when configured static address groups and FQDN IP addresses on Security policies overlapped.
## PAN-121523
Fixed an issue where an API call triggered memory errors, which caused a process (configd) to stop responding and triggered SIGABRT logs.
## PAN-121447
Fixed an issue where the BGP did not remove the IPv6 default route from the forwarding table after the route was withdrawn.
## PAN-121133
Fixed an issue on Panorama M-Series and virtual appliances where a validation job triggered a memory leak in a process (configd), which caused context switching between Panorama and the web interface to respond slower than expected.
## PAN-121001
Fixed an issue where the firewall only reported a maximum of two logs when you configured more than two hardware security modules (HSM).
## PAN-120901
Fixed an issue on Panorama M-Series and virtual appliances where partial commits did not apply configuration changes as expected.
## PAN-120361
Fixed an issue on Panorama M-Series and virtual appliances where objects were not compressed, which caused higher than expected CPU and memory usage.
## PAN-120287
Fixed a JavaScript error due to an incorrect HTTP response, which prevented GlobalProtect Clientless VPN applications to load.
## PAN-120151
Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count is 0. With this fix, the DNS packet parser aborts further processing when QD != 1.
## PAN-119765
Fixed an intermittent issue where the firewall dropped sessions that used a large number of predict sessions.
## PAN-119680
Fixed a rare issue where the show running CLI commands for policy addresses caused file descriptor leaks.
## PAN-119289
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to query Cortex™ Data Lake by the serial number filter.
## PAN-119225
Fixed an issue where an inaccurate sequence number check for an RST packet caused the packet to drop.
## PAN-119185
Fixed an issue where a process (panio) caused more than expected CPU consumption.
## PAN-119172
Fixed an issue where the firewall incorrectly enforced URL category policies and erroneously triggered alert instead of block.
## PAN-118985
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) experienced high memory utilization and a memory leak condition, which caused slower than expected performance.
## PAN-118881
Fixed an issue where the user domain information was missing from the user IP mapping entry when you configured **Allow Authentication with User Credentials or Client Certificate** to **Yes** while using a client certificate for GlobalProtect authentication.
## PAN-118783
Fixed an intermittent issue where a daemon (dnsproxy) stopped responding when you configured an HTTP proxy on the firewall.
## PAN-118762
Fixed an issue where the GlobalProtect portal used an outdated jQuery library.
## PAN-118720
Fixed an issue on a firewall in an HA active/active configuration where Oracle traffic SYN packets dropped intermittently with the flow_fpp_owner_err_no_predict counter.
## PAN-118628
Fixed an issue where after you deployed Panorama in Azure, you were unable to log in to Panorama with the username and password that was provided during the deployment process.
## PAN-118583
Fixed a memory allocation issue that prevented URL filtering logs from displaying the full URL.
## PAN-118430
Fixed an issue where pushed template configurations were overridden when you made a configuration change in the Master Key **Lifetime** (**Device** > **Master Key and Diagnostic** > **Edit**) field.
## PAN-118370
Fixed an issue where the firewall displayed incorrect application dependency warnings during commits when a Security policy used a wildcard address.
## PAN-118277
Fixed an issue where the firewall stopped responding due to a race condition.
## PAN-118256
Fixed an issue where a DNS Security signature response from a cloud service caused a daemon (dnsproxyd) to stop responding.
## PAN-118183
Fixed an issue where a process (dnsproxyd) stopped responding due to higher than expected CPU usage.
## PAN-118180
Fixed an issue on firewalls configured with authentication policies where UDP and ICMP packets matching an authentication policy did not generate traffic logs as defined in the Security policy when sessions were redirected or denied.
## PAN-118057
Fixed an issue on a firewall in an HA active/passive configuration where a process (all_pktproc) stopped responding and the dataplane restarted, which caused an internal path monitoring failure and an HA failover event.
## PAN-118055
Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles.
## PAN-117959
Fixed an issue where LDAP authentication failed when you configured the authentication server with an FQDN.
## PAN-117907
Fixed an issue where the date and time provided for a request license information output did not match the show clock output provided by the NTP server.
## PAN-117900
Fixed an issue where commits failed when you moved an object referenced in a policy to a shared group.
## PAN-117888
Fixed an issue where the firewall was unable to detect the hardware security module (HSM), which caused the firewall to drop SSL traffic.
## PAN-117878
Fixed an issue where you were unable to add a service definition to the NSX manager and the following error message displayed: Failed to create object service-definition. Ret code is 400.
## PAN-117835
Fixed an intermittent issue where a process (all_pktproc) stopped responding, which caused a heartbeat failure and the firewall to drop LACP and OSPF connections.
## PAN-117738
```caveat
PA-3050 and PA-3060 firewalls only
```
Fixed an issue where a higher than expected number of flow_fpga_flow_update messages occurred when you configured QoS.
## PAN-117727
Fixed an issue where job threads were deadlocked, which prevented log in attempts and displayed the following error message: CONFIG_LOCK: write lock TIMEDOUT for cmd.
## PAN-117384
Fixed an issue on Panorama M-Series and virtual appliances where the connection between Panorama and managed firewalls timed out when you upgraded PAN-OS 9.0.0 to PAN-OS 9.0.1 and displayed the following error message: Error - time out sending/receiving message.
## PAN-117303
Fixed an issue where the BGP aggregate prefix, which is advertised to multiple BGP peers was removed from RIB OUT when you disabled one of the BGP peers.
## PAN-117120
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) restarted due to virtual memory issues.
## PAN-117086
Fixed an issue where community attributes to BGP routes had a character limit of 31 characters, which caused expressions to take longer than expected to process.
## PAN-117068
Fixed an issue on Panorama M-Series and virtual appliances where memory utilization increased more than expected when you deleted several rules with an XML API delete command.
## PAN-116977
Fixed an issue on VM-Series firewalls where you could not upgrade to PAN-OS 9.0.1 or a later release with a pre-licensed firewall.
## PAN-116949
Fixed a memory leak issue with a process (mprelay), which caused the dataplane to restart.
## PAN-116903
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure **Enable X-Auth Support** (**Network** > **GlobalProtect** > **Gateways** > **Template** > **<Template-stack>** > **Agent** > **Tunnel Settings**) at the Template-stack level.
## PAN-116772
Fixed an issue where the firewall sent empty attributes in the LDAP query when you did not configure **Alternate Username 1 - 3** (**Device** > **User Identification** > **Group Mapping Settings** > **<group-name>** > **User and Group Attributes**) in the User Attributes web interface.
## PAN-116708
Fixed an issue where administrators were unable to export policies and objects in PDF format.
## PAN-116611
Fixed an issue where an API call for correlated events did not return any events.
## PAN-116473
Fixed an issue where the firewall logged URL categories configured for Allow in the URL filtering logs.
## PAN-116334
Fixed an issue where a process (mgmtsrvr) leaked memory caused by SNMP traps.
## PAN-116286
Fixed an issue where commits failed after you upgraded from PAN-OS 8.0.16 to PAN-OS 8.1.6 due to an invalid encryption state for a host information profile (HIP) object.
## PAN-116274
Fixed an issue where the firewall was unable to authenticate when you pushed a public key from Panorama.
## PAN-116189
Fixed an issue where Session Initiation Protocol (SIP) calls failed and displayed the following error message: end-reason: resources-unavailable.
## PAN-115990
Fixed an issue where the FQDN address object (**Policy** > **Security** > **<address-object>** > **Value**) displayed the following unrelated error: <FQDN-name> Not used.
## PAN-115959
Fixed an issue where DNS names with more than 63 characters did not resolve FQDN address objects during an FQDN refresh.
## PAN-115890
Fixed an issue where the show system info CLI command incorrectly displayed VMware ESXi as VMWare ESXi.
## PAN-115879
Fixed an issue on a firewall where a bypass switch sent heartbeat messages to the firewall, which triggered non-stop link status change interrupts through a Marvell switch.
## PAN-115697
Fixed CVE-2019-17437, see [PAN-SA-2019-0038](https://securityadvisories.paloaltonetworks.com/Home/Detail/201) for details.
## PAN-115549
Fixed an issue where predict sessions were incorrectly created with a captive-portal zone, which caused the firewall to drop RTP traffic.
## PAN-115349
Fixed an issue where an incorrect predict session was created when a policy-based forwarding (PBF) policy was used without a NAT in the parent session, which caused the firewall to drop RTP and RTCP packets.
## PAN-115344
Fixed an issue where the Username Modifier%USERDOMAIN%\%USERINPUT% enabled you to log in to a locked out user account.
## PAN-115340
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall experienced higher than expected dataplane CPU usage caused by HA IPSec messages bouncing between dataplanes.
## PAN-115282
Fixed an issue where temporary download files were deleted before a download job was completed, which caused the progress bar to remain at 0% and prevented a timeout when downloads fail.
## PAN-115281
Fixed an issue where the firewall did not resolve an external dynamic list server address when the DNS proxy configured it as a static entry.
## PAN-115110
An enhancement was made to enable you to configure syslog parameters through the CLI debug command. To view the available parameters and change the configurations, run the debug syslogng-params settings CLI command and perform a commit force to apply the edits.
## PAN-115108
Fixed an issue on Panorama M-Series and virtual appliances where scheduled uploading and installation of WildFire® content meta files to WF-500 appliances failed and displayed the following error message: device not supported.
## PAN-114880
Fixed an issue where the debug management-server summary-logs flush-options max-keys CLI command did not persist through a system reboot.
## PAN-114856
A change was made to limit debug log visibility to superusers only.
## PAN-114771
Fixed an issue on Panorama M-Series and virtual appliances where **Decrypt Mirror** (**Objects** > **Decryption** > **Decryption Profile** > **<Device Group-name>**) did not appear in the **Interface** drop-down menu when you tried to configure a Decryption Profile.
## PAN-114667
Fixed an issue on a firewall in an HA active/passive configuration where a split-brain condition occurred after you upgraded from PAN-OS 8.1.3 to PAN-OS 8.1.6.
## PAN-114628
Fixed an issue where Panorama was unable to query logs forwarded from the firewall to the log collector.
## PAN-114540
Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change.
## PAN-114456
Fixed an issue where extended packet capture (pcap) for threat logs caused a process (mgmtsrvr) to stop responding.
## PAN-114270
Fixed an issue where the firewall dropped TCP trace route traffic after you upgraded to PAN-OS 8.1.5. To leverage this fix, run the set session tcp-reject-diff-syn no CLI command.
## PAN-114247
Fixed an issue where a larger than expected number of Could not find entry for interface ethernet1/<interface>.<subinterface> in CPS table filled the snmpd.log, which caused the log file to rotate more frequently than expected.
## PAN-113610
Fixed an issue where Panorama incorrectly deleted valid device group directories and was unable to generate reports.
## PAN-113606
Fixed an issue where the Throughput column (**Panorama** > **Managed Devices** > **Health**) was incorrectly labeled.
## PAN-113261
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the total entries for the URL filtering allow list, block list, and custom categories were incorrectly set to an entry limit value other than 100,000.
## PAN-113162
Fixed an issue where you were unable to create shared URL filtering profiles from the Panorama web interface.
## PAN-112661
Fixed an issue where you were unable to access a firewall due to a defective small form-factor pluggable (SFP)/SFP+ module inserted into the firewall.
## PAN-111544
Fixed an issue on Panorama M-Series and virtual appliances configured as log collectors where SSH did not respond after you enabled SSH on ethernet1/1.
## PAN-110685
Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch.
## PAN-110098
Fixed an issue on a firewall in an HA active/passive configuration where you were unable to synchronize configurations or dynamic updates between HA pairs.
## PAN-109874
Fixed a memory leak issue on a firewall during a commit, which prevented the firewall from generating GlobalProtect client configurations.
## PAN-108876
Fixed an issue where the firewall dropped Session Initiation Protocol (SIP) registration packets, which caused SIP sessions to fail.
## PAN-108373
Fixed an issue where an application dependency warning incorrectly displayed when you configured negate-source yes on a security rule to deny an application.
## PAN-108012
Fixed an issue on Panorama M-Series and virtual appliances where you could not add and generate a certificate as expected.
## PAN-106434
Fixed an issue where a process (keymgr) stopped responding due to missed heartbeats, which caused IPSec tunnels to stop responding.
## PAN-102195
Fixed an issue where the firewall did not detect all threat sessions while the App and Threat content installation was processed.
## PAN-100977
```caveat
VM-Series NSX edition firewalls only
```
Fixed an issue where the existing logs for dynamic address updates had insufficient information to debug the root cause of an issue and where the dynamic address update logs were larger than expected, which caused the file to roll over every five minutes and did not provide a sufficient log history to debug issues.