Add remaining PAN-OS 11.1 addressed issues

This commit is contained in:
2026-03-16 16:16:41 -05:00
parent f7373bd7a1
commit d1a554d974
39 changed files with 5527 additions and 0 deletions
@@ -0,0 +1,43 @@
---
type: Addressed
product: PAN-OS
version: 11.1.0-h2
---
## PAN-238792
Fixed the following device certificate issues:
- The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly
with the error message OTP is not
valid.
- Firewalls disconnected from Strata Logging Service
after renewing the device certificate.
- The device certificate was not correctly generated on the
log forwarding card (LFC).
- WildFire cloud logs did not log thermite certificate usage
status.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-215576
Fixed an issue where the userID-Agent
and TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.1.0-h3
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.0-h4
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.1.1-h1
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.1-h2
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,116 @@
---
type: Addressed
product: PAN-OS
version: 11.1.1
---
## PAN-239241
Extended the root certificate for WildFire appliances to December 31,
2032.
## PAN-238792
Fixed the following device certificate issues:
- The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly
with the error message OTP is not
valid.
- Firewalls disconnected from Strata Logging Service
after renewing the device certificate.
- The device certificate was not correctly generated on the
log forwarding card (LFC).
- WildFire cloud logs did not log thermite certificate usage
status.
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates
which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-236605
Fixed an issue where the configd process stopped
responding due to a deadlock related to rule-hit-count.
## PAN-235385
Enhanced wifclient cloud connectivity redundancy.
## PAN-234929
Fixed an issue where tabs in the ACC such as
Network Activity
Threat Activity and Blocked
Activity did not display data when you applied a
Time filter of Last 15
Minutes, Last Hour,
Last 6 Hours, or Last 12
Hours, and the data that was displayed with the
Last 24 Hours filter was not accurate.
Reports that were run against summary logs also did not display
accurate results.
## PAN-233957
```caveat
PA-5450 firewalls only
```
Fixed an issue where the NAT
private pool was not used properly when enabling slot 6 DPC.
## PAN-233191
```caveat
PA-5450 firewalls only
```
Fixed an issue where the Data
Processing Card (DPC) restarted due to path monitor failure after
QSFP28 disconnected from the Network Processing Card (NPC).
## PAN-232358
```caveat
PA-5450 firewalls only
```
Fixed an issue where the interface
on QSFP28 ports did not go down when the Tx cable was removed from
the QSFP28 module.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
## PAN-231658
Fixed an issue where DNS resolution failed when interfaces were
configured as DHCP and a DNS server was provided via DHCP while also
statically configured with DNS servers.
## PAN-231194
Fixed an issue where the firewall was unable to clear hints from the
disk.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-215576
Fixed an issue where the userID-Agent and
TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
@@ -0,0 +1,76 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h12
---
## PAN-264421
Fixed an issue on Panorama where Push Scope
did not populate automatically after changing the device group
configuration.
## PAN-263226
Fixed an issue where decryption based traffic failed on Explicit
Proxy nodes.
## PAN-262831
```caveat
PA-5450 firewalls only
```
Fixed an intermittent issue where
the all_task process stopped responding, which caused
the firewall to restart.
## PAN-262593
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
## PAN-261991
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
## PAN-261917
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
## PAN-259769
Fixed an issue where the GlobalProtect portal was not accessible via
a web browser and displayed the error
ERR_EMPTY_RESPONSE.
## PAN-258736
Fixed an issue where policy rule configurations pushed from Panorama
were not reflected on the firewall if the rule had 63
characters.
## PAN-253213
Fixed an issue where the firewall sent HIP notifications every time
it received a HIP report instead of every two hours.
## PAN-252300
Fixed an issue where you were unable to select device groups in the
push scope for user accounts.
## PAN-245690
Fixed an issue where the Managed Collectors
health status on Panorama displayed as empty.
## PAN-209574
Fixed an issue with HTTP/2 traffic where downloading large files did
not work when decryption was enabled.
@@ -0,0 +1,70 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h14
---
## PAN-262287
Fixed an issue where dereferencing a NULL pointer that occurred
caused pan_task processes to stop responding.
## PAN-261673
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where, when Accelerated Networking was enabled,
traffic was dropped because of the
flow_parse_ip_hdr counter related to an Nvidia
driver issue.
## PAN-259151
Fixed an issue where unused objects were pushed to the firewall,
which caused configuration pushes to fail with the error
Number of address groups exceed platform
capacity.
## PAN-259002
Fixed an issue where frequent external dynamic list updates caused
the configd process to restart.
## PAN-257601
```caveat
PA-5450 firewalls only
```
Fixed an issue where Networking
Cards (NC) experienced an internal link fault which caused path
monitoring failure on the Dataplane Processing Card (DPC).
## PAN-257327
Fixed an issue where a failover event occurred unexpectedly on the
firewall.
## PAN-253626
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently
fail.
## PAN-236191
Fixed an issue where the web interface performance was slower than
expected.
## PAN-222542
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Log
Forward Cards (LFC) were incorrectly identified as distribution
policies, which caused packet loss due to traffic, BFD, and other
control packets being forwarded to the LFC.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h15
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,84 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h16
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
## PAN-269000
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
## PAN-265785
Fixed an issue where the firewall rebooted due to a sysd
variable being modified before it was created.
## PAN-265179
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
## PAN-263973
Fixed an issue where log collectors had a low incoming log rate.
## PAN-263208
```caveat
PA-5440 and PA-5445 firewalls only
```
Fixed an issue where
interrupts were generated at a certain packet rate, and dataplane
processes missed heartbeats, which caused the dataplane to go
down.
## PAN-259881
Fixed an issue on Panorama where traffic log details were not
displayed under detailed log view.
## PAN-259351
A fix was made to address CVE-2024-3393.
## PAN-256223
Fixed an issue where device telemetry log collection filled the root
partition.
## PAN-255747
Fixed an issue on the firewall where CLI commands returned
Server error: op command for client dagger timed
out as client is not available.
## PAN-253485
```caveat
Firewalls in active/passive HA configurations only
```
Fixed
an issue where dataplane packet capture filter configuration failed
on the active firewall with the error op command for
client dagger timed out as client is not
available.
## PAN-249300
Fixed an issue where, when CUID was enabled, the CUID firewall pub
node was slower than expected when processing incoming traffic and
User-ID mapping redistribution between PAN-OS nodes was
impacted.
## PAN-219805
Fixed an issue where the reportd process stopped
responding due to a race condition.
@@ -0,0 +1,38 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h18
---
## PAN-279604
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of
the report content.
## PAN-273085
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
## PAN-272006
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device)
sent a Non-Maskable Interrupt (NMI) to the CPU.
## PAN-271926
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
## PAN-270549
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
## PAN-268727
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h1
---
## PAN-242879
Fixed an issue where the dataplane restarted when advanced features
such as Advanced Threat Protection, Advanced WildFire, and Advanced
URL Filtering hit max latency under inline mode.
## PAN-242634
```caveat
PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls only
```
Fixed an issue where a large packet burst from the
dataplane to the management plane caused the DPDK kernel network
interface to become unresponsive.
## PAN-240166
Fixed an issue where, when explicit proxy was configured on the
firewall, websites loaded more slowly than expected or did not load
due to DNS using TCP.
## PAN-239279
Fixed an issue where the proxy did not accept new connections.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h3
---
## PAN-252214
A fix was made to address CVE-2024-3400.
## PAN-246949
Fixed an issue where custom admin users were not able to click
OK in the push scope selection window
when device group or template were disabled under commit in the
admin roles.
## PAN-244013
Fixed an issue on the Panorama web interface where, when a new
content package was installed, new Anti-Spyware
Signatures and new Vulnerability
Signatures were not visible in their respective
profiles.
## PAN-243951
Fixed an issue on Panorama appliances in active/passive HA
configurations where managed devices displayed as out-of-sync on the
passive appliance when peer configuration changes were made to the
SD-WAN configuration on the active peer.
@@ -0,0 +1,151 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h4
---
## PAN-252214
A fix was made to address CVE-2024-3400.
## PAN-251013
Fixed an issue on the web interface where the Virtual
Router and Virtual System
configurations for the template incorrectly showed as
none.
## PAN-250686
Fixed an issue where selective push operations did not work when more
than one admin user simultaneously performed changes and partial
commits on Panorama.
## PAN-249931
Fixed an issue where configuration pushes from Panorama on PAN-OS
11.1.1 to a firewall on a PAN-OS 10.2 release failed.
## PAN-249808
Fixed an issue where the configd process stopped
responding when performing multi-device group pushes via XML
API.
## PAN-247403
```caveat
VM-Series firewalls only
```
Fixed an issue where the push
scope CLI command took longer than expected, which caused the web
interface to be slow.
## PAN-246960
Fixed an issue where firewalls failed to fetch content updates from
the Wildfire Private Cloud due to an Unsupported
protocol error.
## PAN-244894
Fixed an issue where turning off mprelay logging caused
*mprelay* heartbeat failure.
## PAN-244622
Fixed an issue where FIB re-push did not work with Advanced Routing
enabled.
## PAN-244227
Fixed an issue where inconsistent FIB entries across the dataplane
were not detected.
## PAN-242309
Fixed an issue where a higher byte count (s2c) was observed for
DNS-Base application.
## PAN-242027
Fixed an issue where the all-task process repeatedly
restarted during memory allocation failures.
## PAN-241141
Fixed an issue where creating more than one address object in the
same XML API request resulted in a commit error.
## PAN-240477
Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to
not be able to link up on PA-3400 and PA-1400 Series firewalls.
## PAN-240308
Fixed an issue where ElasticSearch did not work as expected when
raid-mounts were not fully ready after a reboot.
## PAN-239367
Fixed an issue on the firewall where a memory leak associated with
the logrcvr process occurred.
## PAN-239354
Fixed an issue where DNS resolution was delayed when an Antispyware
policy rule was applied to both client to firewall and firewall to
internal DNS server legs of a connection.
## PAN-238643
Fixed an issue where a memory leak caused multiple processes to stop
responding when VM Information Sources was configured
## PAN-237537
Fixed an issue where, when deleting CTD entries, the
all_pktproc process stopped responding which
resulted in dataplane failure.
## PAN-237208
Fixed an issue where the reportd process stopped and the
firewall rebooted.
## PAN-233789
Fixed an issue with push and commit and push operations where the
user was not correctly bound to the scope, which caused all device
groups to be selected for a selective push.
## PAN-233692
Fixed an issue on Panorama where the configd process
stopped, which caused performance issues.
## PAN-233684
Fixed an issue on Panorama where Push to
Devices or Commit and Push
operations took longer than expected on the web interface.
## PAN-231148
Fixed an issue where no DHCP option list was defined when using
GlobalProtect.
## PAN-230746
Fixed an issue on the web interface where device groups with a large
number of managed firewalls displayed the
Policy page more slowly than
expected.
## PAN-205482
Fixed an issue related to the configd process where
Panorama displayed the error Server not
responding when editing policies.
@@ -0,0 +1,116 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2-h9
---
## PAN-258225
Fixed an issue on the Panorama web interface where Security policy
rules loaded more slowly than expected.
## PAN-257615
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
## PAN-256725
Fixed an issue on the Panorama interface where
Traffic and
Unified event details loaded more slowly
than expected.
## PAN-255868
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the
firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
## PAN-255266
Fixed an issue where you were unable to clone a template stack with
the Pre-Shared Key variable.
## PAN-254411
Fixed an issue where the configd process stopped
responding, which caused
RR_CONNECTION_REFUSED error messages to
be displayed in admin sessions.
## PAN-253546
Fixed an issue where a TLS client hello was split into multiple
packets and arrived out of order, so the packets were dropped and
the session terminated.
## PAN-251563
Added CPLD enhancement to capture external power issues.
## PAN-247099
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
## PAN-246772
Fixed an issue on the firewall where the dataplane went down due to a
path monitor failure caused by an OOM condition related to the
pan_task process.
## PAN-246059
Fixed an issue where forwarded logs were not visible on Panorama due
to the Elasticsearch service not starting when it encountered old
and unsupported indices.
## PAN-245428
Fixed an issue where FIB entries aged out and were incorrectly
removed after an HA failover event.
## PAN-244548
Fixed an issue where ECMP sessions changed destination MAC addresses
mid-session, which caused connections to be reset.
## PAN-243098
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
## PAN-240739
Fixed an issue where the ECMP FIB update on the dataplane didn't
clear the pending change flag, which caused the next non-ECMP FIB
update to miss the latest generation ID and age out after 5
minutes.
## PAN-240612
Fixed a kernel panic caused by a third-party issue.
## PAN-240596
Fixed an issue where the all_task process stopped
responding due to an invalid memory address.
## PAN-236133
Fixed an issue where SSL traffic was impacted when SSL
Command and Control detector for Incline Cloud
Analysis was set to reset-both,
reset-client,
reset-server, or
drop.
## PAN-234560
Fixed an issue where the daily summary report displayed IPv6
addresses instead of IPv4 addresses.
@@ -0,0 +1,92 @@
---
type: Addressed
product: PAN-OS
version: 11.1.2
---
## PAN-242627
Fixed an issue where selective push did not work.
## PAN-242561
Fixed an issue where GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.
## PAN-242519
Fixed an issue where scheduled email reports failed if the @ symbol before the mail client was missing.
## PAN-241504
Fixed an issue on the web interface where filtering logs under the Monitor tab was slower than expected.
## PAN-239769
Fixed an issue where object references in a rule were renamed, and a selective revert of the changes with Commit changes by me caused a reference error.
## PAN-238769
```caveat
VM-Series firewalls in FIPS-CC mode only
```
Fixed an issue where upgrading Panorama caused all locally created Security policy rule actions to Deny.
## PAN-238586
Fixed an issue where DNS resolution failure from the LFC resulted in WildFire public cloud connectivity failure.
## PAN-236120
Fixed an issue where the /opt/panlogs partition reached capacity due to the logdb-quota for the User-ID log folder not being matched.
## PAN-235840
Fixed an issue where, after a configuration push from Panorama to managed firewalls, the status displayed as None and the push took longer than expected.
## PAN-235585
Fixed an issue where, when custom signatures and predefined signatures shared the same literal pattern part, the custom signature caused an incorrect calculation for the length of the predefined signature, which resulted in App-ID not detecting correctly.
## PAN-234279
Fixed an issue where the ikemgr process crashed due to an IKEv1 timing issue, which caused commits to fail with the following error message: Client ikemgr requesting last config in the middle of a commit/validate, aborting current commit.
## PAN-230106
Fixed an issue where the firewall was unable to retrieve the most current external dynamic list information from the server due to hostname resolution failure.
## PAN-227397
Fixed an issue where selective pushes on Panorama removed a previously pushed configuration from the firewalls.
## PAN-226785
Fixed an issue where accessing websites with HTTP to HTTPS redirect
failed via explicit proxy.
## PAN-225337
Fixed an issue on Panorama related to Shared configuration objects
where configuration pushes to multi-vsys firewalls failed.
## PAN-225203
Fixed an issue where the Log Forwarding Card (LFC) did not honor the negotiated MSS on the logging connection.
## PAN-224954
Fixed an issue where, after upgrading and rebooting a Panorama appliance in Panorama or Log Collector mode, managed firewalls continuously disconnected.
## PAN-223259
Fixed an issue where selective pushes failed with the error message Failed to generate selective push configuration. Unable to retrieve last in-sync configuration for the device, either a push was never done or version is too old. Please try a full push.
## PAN-216941
```caveat
Panorama appliances in Log Collector mode only
```
Fixed an
issue where Panorama stopped processing and saving logs.
@@ -0,0 +1,127 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h10
---
## PAN-265336
```caveat
PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-5450 firewalls only
```
Fixed an issue where the copper ports
flapped when generating a technical support file or executing
telemetry.
## PAN-265287
Fixed an issue where the firewall experienced a packet buffer leak in
the dataplane of the network processing card (NPC) when processing
certain net messages.
## PAN-265287
Fixed an issue where the firewall experienced a packet buffer leak in
the dataplane of the NPC when processing certain net messages.
## PAN-263973
Fixed an issue where log collectors had a low incoming log rate.
## PAN-262287
Fixed an issue where dereferencing a NULL pointer that occurred
caused pan_task processes to stop responding.
## PAN-261485
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
## PAN-259733
Fixed an issue where a custom report was not deleted on Panorama when
expected.
## PAN-259151
Fixed an issue where unused objects were pushed to the firewall,
which caused configuration pushes to fail with the error
Number of address groups exceed platform
capacity.
## PAN-257912
Fixed an issue where the firewall stopped responding when it received
RADIUS traffic and user equipment (UE) traffic at the same time on
an NPC.
## PAN-257615
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
## PAN-257601
```caveat
PA-5450 firewalls only
```
Fixed an issue where Networking
Cards (NC) experienced an internal link fault which caused path
monitoring failure on the Dataplane Processing Card (DPC).
## PAN-257327
```caveat
PA-5440 firewalls only
```
Fixed an issue where a failover
event occurred unexpectedly on the firewall.
## PAN-256725
Fixed an issue on the Panorama interface where
Traffic and
Unified event details loaded more slowly
than expected.
## PAN-254794
Fixed an issue where the Panorama management server stopped
responding.
## PAN-253626
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently
fail.
## PAN-250394
Fixed an issue where a large amount of group data caused
serialization errors and prevented synchronization.
## PAN-246708
Fixed an issue where the firewall stopped responding when the
all_pktproc repeatedly restarted.
## PAN-243098
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
## PAN-222542
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Log
Forward Cards (LFC) were incorrectly identified as distribution
policies, which caused packet loss due to traffic, BFD, and other
control packets being forwarded to the LFC.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h11
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,76 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h13
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
## PAN-269000
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
## PAN-265785
Fixed an issue where the firewall rebooted due to a sysd
variable being modified before it was created.
## PAN-263208
```caveat
PA-5440 and PA-5445 firewalls only
```
Fixed an issue where
interrupts were generated at a certain packet rate, and dataplane
processes missed heartbeats, which caused the dataplane to go
down.
## PAN-260604
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
## PAN-259881
Fixed an issue on Panorama where traffic log details were not
displayed under detailed log view.
## PAN-259351
A fix was made to address CVE-2024-3393.
## PAN-258799
Fixed an issue where, when updating a Security Policy
Policy Optimizer, the web interface
stopped responding.
## PAN-256223
Fixed an issue where device telemetry log collection filled the root
partition.
## PAN-255915
Fixed an issue where a memory leak in the sslmgr process
caused the firewall to restart.
## PAN-254826
Fixed an issue where the firewall stopped responding when processing
traffic.
## PAN-254794
Fixed an issue where the Panorama management server stopped
responding.
## PAN-254577
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
@@ -0,0 +1,20 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h1
---
## PAN-256765
Fixed an issue where you were unable to push variables from Panorama
in service routes for non-cluster templates.
## PAN-255868
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the
firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
@@ -0,0 +1,41 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h2
---
## PAN-259733
Fixed an issue where a custom report was not deleted on Panorama when
expected.
## PAN-259473
```caveat
PA-5450 firewalls only
```
Fixed an issue where the chassis
shut down when FAN1 was removed.
## PAN-254411
Fixed an issue where the configd process stopped
responding, which caused ERR_CONNECTION_REFUSED error
messages to be displayed in admin sessions.
## PAN-253546
Fixed an issue where a TLS client hello was split into multiple
packets and arrived out of order, so the packets were dropped and
the session terminated.
## PAN-249814
Fixed an issue where multiple all_task processes stopped
responding, which caused the dataplane to fail.
## PAN-247099
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
@@ -0,0 +1,66 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h4
---
## PAN-259480
Fixed an issue where the varrcvr process stopped
responding after running out of memory due to how the process queued
and dequeued files for WildFire file forwarding when a WildFire
Analysis Security profile was enabled.
## PAN-257925
```caveat
CN-Series firewalls only
```
Fixed an issue where the CLI
command show system setting ctd state
did not work as expected.
## PAN-257615
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
## PAN-257462
Fixed an issue related to the varrcvr process where the
management plane CPU was higher than expected during WildFire
updates.
## PAN-256385
```caveat
CN-Series firewalls only
```
Fixed an issue where
communication was broken between the management plane and the
dataplane when anti-spyware profiles were configured in a Security
policy rule.
## PAN-254373
Fixed an issue where the firewall did not handle error code 500
responses from the WildFire cloud correctly.
## PAN-251639
Fixed an issue where an out-of-memory condition occurred due to a
memory leak related to the varrvcr process when a
WildFire Analysis security profile was enabled.
## PAN-248148
Jumbo frame feature support is enabled.
## PAN-225213
Fixed an issue where Push All Changes
displayed changes that were already committed in the push scope for
another device group after performing a selective commit and
selective push to the first device group.
@@ -0,0 +1,54 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3-h6
---
## PAN-263226
Fixed an issue where decryption based traffic failed on Explicit
Proxy nodes.
## PAN-262593
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
## PAN-261991
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
## PAN-261917
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
## PAN-259769
Fixed an issue where the GlobalProtect portal was not accessible via
a web browser and displayed the error
ERR_EMPTY_RESPONSE.
## PAN-257957
```caveat
Firewalls and Panorama appliances in FIPS-CC mode only
```
Fixed an issue where the authd process restarted if
RADIUS PAP/CHAP authentication was used.
## PAN-242331
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
## PAN-232214
Fixed an issue where GlobalProtect clients remained in the connecting
state during portal pre-login when Kerberos single sign-on (SSO) was
enabled.
@@ -0,0 +1,866 @@
---
type: Addressed
product: PAN-OS
version: 11.1.3
---
## PAN-251013
Fixed an issue on the web interface where the Virtual
Router and Virtual System
configurations for the template incorrectly showed as
none.
## PAN-250686
Fixed an issue where selective push operations did not work when more
than one admin user simultaneously performed changes and partial
commits on Panorama.
## PAN-249808
Fixed an issue where the configd process stopped
responding when performing multi-device group pushes via XML
API.
## PAN-249597
Fixed an issue where the Policy page on the
Panorama web interface was slower than expected when a device group
had a large number of managed devices.
## PAN-249019
Fixed an issue where the all_pktproc process stopped
responding, which caused the firewall to become unresponsive.
## PAN-248748
Fixed an issue that caused the dataplane to stop responding when
running a packet diagnostic with Jumbo frames enabled.
## PAN-248105
Fixed an issue where the GlobalProtect SSL VPN tunnel immediately
disconnected due to a keep-alive timeout.
## PAN-247403
```caveat
Panorama virtual appliances only
```
Fixed an issue where the
push scope CLI command took longer than expected, which caused the
web interface to be slow.
## PAN-246707
Fixed an issue where failover was not triggered when multiple
processes stopped responding.
## PAN-246420
```caveat
PA-5450 Series firewalls only
```
Fixed an issue where the
firewall rebooted unexpectedly during an upgrade.
## PAN-246215
Fixed an issue where the sleep time for a suspended
pan_task process caused configuration and policy
updates to be blocked.
## PAN-245701
Fixed an issue where the returned values to SNMP requests for data
port statistics were incorrect.
## PAN-245690
Fixed an issue where the Managed Collectors health status on Panorama
displayed as empty.
## PAN-245428
Fixed an issue where FIB entries aged out and were incorrectly
removed after an HA failover event.
## PAN-245387
Fixed an issue where selective push failed intermittently due to
schema validation or bad encryption errors.
## PAN-245041
Fixed an issue where the WF-500 appliance returned an error verdict
for every sample in FIPS mode.
## PAN-244907
```caveat
PA-3400, PA-5400, and PA-1400 Series firewalls only
```
Fixed
an issue where virtual wire ports did not go down when moving from
an active state to a suspended state.
## PAN-244894
Fixed an issue where turning off mprelay logging caused
mprelay heartbeat failure.
## PAN-244836
A knob was introduced to toggle the default behavior of BGP in the
Advanced Routing stack to not suppress duplicate updates. By
default, the prefix updates are suppressed for optimization.
## PAN-244648
Fixed an issue where, when FIPS was enabled in maintenance mode, the
firewall rebooted and returned to maintenance mode.
## PAN-244625
```caveat
VM-Series firewalls only
```
Fixed an issue where incorrect
virtual MAC addresses were used in interfaces.
## PAN-244622
Fixed an issue where FIB re-push did not work with Advanced Routing
enabled.
## PAN-244548
Fixed an issue where ECMP sessions changed destination MAC addresses
mid-session, which caused connections to be reset.
## PAN-244493
Fixed a memory limitation with mapping subinterfaces to VPCE
endpoints for GCP IPS, Amazon Web Services (AWS) integration with
GWLB, and NSX service chain mapping.
## PAN-244227
Fixed an issue where inconsistent FIB entries across the dataplane
were not detected.
## PAN-244013
Fixed an issue where the web interface did not display newly added
Anti-Spyware signatures or Vulnerability Signatures.
## PAN-243463
Fixed an issue where high Enhanced Application Log traffic used
excess system resources and caused processes to not work.
## PAN-242027
Fixed an issue where the all-task process repeatedly
restarted during memory allocation failures.
## PAN-241548
Fixed an issue where the firewall stopped responding when switching
from endpoint authentication bypass to endpoint Kerberos
authentication with SWG-proxy traffic.
## PAN-241230
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
## PAN-241164
```caveat
PA-410 firewalls only
```
Fixed an issue where system and
configuration logs sent from the firewall to Panorama contained the
serial number field instead of the firewall device name.
## PAN-241141
Fixed an issue where creating more than one address object in the
same XML API request resulted in a commit error.
## PAN-241041
Fixed an issue where, after upgrading to 11.1.0, exporting CSV files
for template stack variables or template variables resulted in an
empty file.
## PAN-241018
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed a Dataplane Development Kit (DPDK) issue where interfaces
remained in a link-down stage after an Azure hot plug event.
## PAN-240993
Fixed an issue where you were unable to revert a sort in task manager
in the admin column.
## PAN-240786
Fixed an issue on firewalls in HA configurations where VXLAN sessions
were allocated, but not installed or freed, which resulted in a
constant high session table usage that was not synced between the
firewalls. This resulted in a session count mismatch.
## PAN-240618
Fixed an issue where configuration commits were successful even when
dynamic peer IKE gateways configured on the same interface and IP
address that did not have the same IKE crypto profile.
## PAN-240612
Fixed a kernel panic caused by a third-party issue
## PAN-240596
Fixed an issue where all_task stopped responding due to
an invalid memory address.
## PAN-240477
Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to
not be able to link up on PA-3400 and PA-1400 Series firewalls.
## PAN-240368
Fixed an issue where authentication portal redirection for HTTPS
websites did not work when Enhanced Handling of SSL/TLS
Handshakes for Decrypted Traffic was enabled.
## PAN-240347
Fixed an issue with the web interface where the
Dashboard and a Device
Group policy rule took longer than expected to
load.
## PAN-240308
Fixed an issue where ElasticSearch did not work as expected when
raid-mounts were not fully ready after a reboot.
## PAN-240251
Fixed an issue where the vldmgr process incorrectly
restarted during an Elasticsearch restart.
## PAN-239776
Fixed an issue where Panorama went into maintenance mode due to a
GlobalProtect quota configuration that was under the minimum
required quota.
## PAN-239722
Fixed an issue where SNMP scans to the firewall took longer than
expected and intermittently timed out.
## PAN-239662
Fixed an issue where the NSSA default route from the firewall was not
generated to advertise even though the backbone area default route
was advertised during a graceful restart.
## PAN-239367
Fixed an issue on the firewall where a memory leak associated with
the logrcvr process occurred.
## PAN-239354
Fixed an issue where DNS resolution was delayed when an antispyware
policy rule was applied to both client to firewall and firewall to
internal DNS server legs of a connection.
## PAN-239337
Fixed an issue where the log_index was suspended and corrupted BDX
files flooded the index_log.
## PAN-239256
Fixed an issue where ARP entries were unable to be completed for
subinterfaces with SNAT configured.
## PAN-239255
Fixed an issue where the firewall did not update the ARP cache
timeout value after modifying the
arp-cache-timeout setting.
## PAN-238996
Fixed an issue where commits did not complete and remained in a
pending state due to a race condition. With this fix, the commit
will fail after 60 seconds and not remain in a pending state.
## PAN-238643
Fixed an issue where a memory leak caused multiple processes to stop
responding when VM Information Sources was configured.
## PAN-238625
Fixed an issue where, when the physical interface went down, the
SD-WAN Ethernet connection state still showed
UP/path-monitor due to the Active URL
SaaS monitor connection state remaining UP/path-monitor.
## PAN-238621
Fixed an issue where the HA3 link status remained down when updating
the HA3 interface configuration when the AE interface was up.
## PAN-238562
Fixed an issue where log collectors stopped responding when gathering
reports from Panorama.
## PAN-238508
Fixed an issue where the routed process created
excessive logs in the log file.
## PAN-237678
Fixed an issue with firewalls in active/passive HA configurations
where the passive firewall displayed the error message
Unable to read QSFP Module ID when
the passive link state was set to shutdown.
## PAN-237537
Fixed an issue where, when deleting CTD entries, the
all_pktproc process stopped responding which
resulted in dataplane failure.
## PAN-237478
Fixed an issue where the traffic log displayed 0 bytes for denied
sessions.
## PAN-237454
Fixed an issue where Panorama stopped redistributing IP
address-to-username mappings when packet loss occurred between the
distributor and the client.
## PAN-237369
```caveat
PA-1420 firewalls only
```
Fixed an issue where the
all_task process stopped responding, which caused
the firewall to become unresponsive.
## PAN-237246
Fixed an issue where the all_pktproc process repeatedly
restarted, which caused the firewall to go into a nonfunctional
state.
## PAN-236802
Fixed an issue on firewalls in HA configurations where unexpected
failovers occurred.
## PAN-236261
Fixed an issue where a proxy server was used for External Dynamic
List communication even when the dataplane interface was configured
through service routes.
## PAN-236244
Fixed an issue where you were unable to select Authentication
Profiles via the web interface.
## PAN-236233
Fixed an issue where SNMP reports displayed incorrect values for SSL
Proxy sessions and SSL Proxy utilization.
## PAN-235737
Fixed an issue where the brdagent process stopped
responding due to a sudden increase in logging to the bcm.log.
## PAN-235628
Fixed an issue where you were not prompted for login credentials when
you disconnected and connected back to the GlobalProtect portal when
SAML authentication was selected along with Single Sign-On (SSO) and
Single Log Out (SLO).
## PAN-235557
Fixed an issue where uploads from tunnels, including GlobalProtect,
were slower than expected when the inner and outer sessions were on
different dataplanes.
## PAN-235476
Fixed an issue where threat logs from different Security zones were
aggregated into one log.
## PAN-235168
Fixed an issue where disk space became full even after clearing old
logs and content images.
## PAN-235081
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall
sent packets to its own interface after configuring NAT64.
## PAN-234596
Fixed an issue on firewalls in active/passive HA configurations where
the passive firewall incorrectly became active after a reboot.
## PAN-234459
Fixed an issue with the firewall web interface where local SSL
decryption exclusion cache entries were not visible.
## PAN-234290
Fixed an issue where the firewall displayed incorrect interface
transfer rates when running the CLI command show
system state filter-pretty sys.s1.px with a
filter.
## PAN-234169
Fixed an issue where downloading files failed or was slower than
expected due to malware scanning even when the session was matched
to a Security policy rule with no Anti-Virus profile attached.
## PAN-234031
Fixed an issue on multi-core firewalls where the firewall displayed
packets out of order when capturing packets on the transmit
stage.
## PAN-233833
Fixed an issue where enabling Jumbo frames resulted in software
packet buffer depletion.
## PAN-233789
Fixed an issue with Push and Commit
and Push operations where the user was not correctly
bound to the scope, which caused all device groups to be selected
for a selective push.
## PAN-233692
Fixed an issue on Panorama where the configd process
stopped, which caused performance issues.
## PAN-233684
Fixed an issue on Panorama where Push to
Devices or Commit and Push
operations took longer than expected on the web interface.
## PAN-233603
```caveat
CN-Series firewalls only
```
Fixed an issue where slot
information was not correct after a slotd process
restart on the management pod.
## PAN-233541
Fixed an issue where device group and template administrators with
access to a specific virtual system were able to see logs for all
virtual systems via Context Switch.
## PAN-233517
Fixed an issue on Panorama where managed device templates and device
groups took longer than expected to display in the Push
to Devices window.
## PAN-233463
Fixed an issue where the X-Forwarded-For (XFF) IP addressed value was
not displayed in traffic logs.
## PAN-233207
Fixed an issue where the configd process stopped
responding when a partial configuration revert operation was
performed.
## PAN-233039
Fixed an issue where GENEVE encapsulated packets coming from a GFE
Proxy mapped to an incorrect Security policy rule.
## PAN-232953
Fixed an issue where you were able to cancel the same commit
repeatedly, which displayed the error message Cannot
stop job <job> at this time.
## PAN-232368
Fixed an issue where commits failed with the error message
Error: Max. user groups used in policy 1389 exceed
capacity (1000).
## PAN-232250
Fixed an issue where, when SSH service profiles for management access
were set to None, the reported output was
incorrect.
## PAN-231802
Fixed an issue where an Advanced Routing BGP session flapped with
commits when BGP peer authentication was enabled.
## PAN-231552
Fixed an issue where traffic returning from a third-party Security
chain was dropped.
## PAN-231507
```caveat
PA-1400 Series firewalls only
```
Fixed an issue where, when
an HSCI interface was used as an HA2 interface, HA2 packets were
intermittently dropped on the passive firewall, which caused the HA2
connection to flap due to missing HA2 keepalive messages.
## PAN-231480
Fixed an issue where the firewall CLI output for GlobalProtect log
quota settings did not match the settings configured on the Panorama
web interface.
## PAN-231439
Fixed an issue where, when a VoIP call using dynamic IP and NAT was
put on hold, the audio became one-way due to early termination of
NAT ports.
## PAN-231395
Fixed an intermittent issue where the OCSP query failed.
## PAN-231148
Fixed an issue where no DHCP option list was defined when using
GlobalProtect.
## PAN-230813
Fixed an issue where flex memory leak caused decryption failure and
commit failure with the error message Error preparing
global objects failed to handle
CONFIG_UPDATE_START.
## PAN-230746
Fixed an issue on the web interface where device groups with a large
number of managed firewalls displayed the
Policy page more slowly than
expected.
## PAN-230656
```caveat
Firewalls in HA configurations only
```
Fixed an issue where a
split brain condition occurred on both firewalls after booting up
any firewall, and an HA switchover occurred after booting up a
firewall with a higher HA priority even when no preemptive option
was enabled on the firewall.
## PAN-230377
Fixed an issue where FEC support was not enabled by default for
PAN-25G-SFP28-LR modules.
## PAN-230372
Fixed an issue where OCSP queries did not work after upgrading to a
PAN-OS 11.0 release.
## PAN-230039
Fixed an issue where migrating from an Enterprise License Agreement
(ELA) to a Flexible VM-Series License failed with a deactivation
error message.
## PAN-229985
```caveat
VM-Series firewalls in Amazon Web Services (AWS) only
```
Fixed an issue where, when Gateway Load Balancer (GWLB) overlay
routing was enabled, GWLB packets re-encapsulated with the incorrect
flow cookie in the GENEVE header when transmitting the response back
to GWLB.
## PAN-229874
Fixed an issue where the firewall was unable to form OSPFv3 adjacency
when using an ESP authentication profile.
## PAN-229873
```caveat
PA-7050 firewalls only
```
Fixed an issue related to
brdagent process errors.
## PAN-229315
Fixed an issue where Octets in NetFlow records were always reported
to be 0 despite having a non-zero packet count.
## PAN-229069
Fixed an issue where clientless VPN portal users were unable to
access clientless applications due to an SSL renegotiation being
triggered.
## PAN-228457
```caveat
PA-7000 firewalls only
```
Fixed an issue where the GTP logs
forwarded from the firewall to the log collector did not include the
pcap.
## PAN-228442
Fixed an issue on firewalls in active/passive HA configurations where
sessions did not fail over from the active firewall to the passive
firewall when upgrading PAN-OS.
## PAN-228323
Fixed an issue where a large number of Panorama management server
cookies were created in the Redis database when the Cloud-Service
plugin sent an authentication request every second, and logging in
to or using Panorama was slower than expected.
## PAN-227973
Fixed an issue where commits failed after renaming an address object
or object group with a selective commit.
## PAN-227939
Fixed an issue where the all_task process stopped
responding due to high wifclient memory usage, which caused the
firewall to reboot.
## PAN-227887
Fixed an issue where IP address checksums were calculated
incorrectly.
## PAN-227510
Fixed an issue where the error message Failed to
establish GRPC connection to UrlCat service: failed to start
grpc connection was displayed in the system log
when the Advanced URL Filtering license was applied but not
configured.
## PAN-227064
Fixed an issue with high availability (HA) sync failure when
performing a partial commit after creating a Security policy via
REST API.
## PAN-226489
Fixed an issue where Panorama was unable to push scheduled dynamic
updates to firewalls with the error message Failed to
add deploy job. Too many (30) deploy jobs pending for
device.
## PAN-225090
Fixed an issue on Panorama where Commit and
Push was grayed out when making changes to a
template or device group.
## PAN-225064
Fixed an issue where Panorama stopped responding and entered a
non-functional state after moving multiple Security policy rules at
the same time from one device group to another device group.
## PAN-224938
Fixed an issue where the CLI command settings for set
system setting logging max-log-rate did not
persist after a mgmtsrvr process restart.
## PAN-224584
Fixed an issue on Panorama where generating UAR reports for 30 days
or more was slower than expected, and reports showed the same logs
repeatedly in a loop.
## PAN-224424
```caveat
PA-3440 firewalls only
```
Fixed an issue where you were
unable to set the link speed as 25Gbps from the drop-down in the
template for Ethernet ports 1/23 through 1/26.
## PAN-224060
```caveat
PA-220 Series firewalls only
```
Fixed an issue where multiple
dataplane processes stopped responding after an upgrade.
## PAN-223365
Fixed an issue where Panorama was unable to query any logs if the
Elasticsearch health status for any log collector was degraded.
## PAN-223172
Fixed an issue on Panorama where host IDs manually added to the
device quarantine list were unexpectedly removed.
## PAN-222188
A CLI command was introduced to address an issue where SNMP
monitoring performance was slower than expected, which resulted in
snmpwalk timeouts.
## PAN-222002
Fixed an issue where content updates failed with the error message
Unable to get key pancontent-8.0.pass from
cryptod. Error -9.
## PAN-220931
```caveat
Panorama appliances in FIPS-CC mode only
```
Fixed an issue
where scheduled email reports did not contain PDF attachments.
## PAN-219805
Fixed an issue where the reportd process stopped
responding due to a race condition.
## PAN-219113
Fixed an issue where, when a port on the NPC was configured for log
forwarding, the ingress traffic on the card was sent for processing
to the LPC, and the LPC card was reloaded when the ingress volume of
traffic was high.
## PAN-217619
Fixed an issue where supported Bi-DI transceivers were not recognized
which caused ports to not come up.
## PAN-217307
Fixed an issue where the log-start and
log-end policy rule filters did not
return reliable results when set to no
or yes.
## PAN-217241
Fixed an issue where predict session conversion failed for RTP and
RTCP traffic.
## PAN-209574
Fixed an issue with HTTP/2 traffic where downloading large files did
not work when decryption was enabled.
## PAN-205482
Fixed an issue related to the configd process where
Panorama displayed the error Server not
responding when editing policies.
## PAN-199141
Fixed an issue where renaming a device group and then performing a
partial commit led to the device group hierarchy being incorrectly
changed.
## PAN-196395
```caveat
PA-5450 firewalls only
```
Fixed an issue where the firewall
accepted 12 aggregate ethernet interfaces, but you were unable to
configure interfaces 9-12 via the web interface.
## PAN-174454
Fixed an issue where the firewall did not fetch group and user
membership due to the Okta sync domain not matching the active Cloud
Identity Engine domain.
@@ -0,0 +1,418 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h13
---
## PAN-279604
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of
the report content.
## PAN-278088
Fixed an issue where the show system resources
follow CLI command was not available.
## PAN-274791
Fixed an issue where the firewall rebooted when Shared Pool Type 32
was depleted and traffic matched advanced features.
## PAN-274592
```caveat
Firewalls in HA configurations only
```
Fixed an issue where
the firewall did not fail over when the active firewall experienced
data plane issues.
## PAN-273994
A fix was made to address CVE-2025-0111.
## PAN-273971
A fix was made to address CVE-2025-0108.
## PAN-273278
A fix was made to address CVE-2025-0109.
## PAN-273129
Fixed an issue on the web interface where the
negate option was visible when you
clicked on the rule name, but not when you viewed the target options
from the rulebase attribute.
## PAN-273085
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
## PAN-273026
Fixed an issue where traffic logs did not display correctly when
filters were applied.
## PAN-273019
Fixed an intermittent issue where SSL decryption failed.
## PAN-272959
Fixed an issue where the firewall generated BGP update packets larger
than 1500 bytes when the interface MTU was 1500 bytes and jumbo
frames were enabled globally.
## PAN-272006
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device)
sent a Non-Maskable Interrupt (NMI) to the CPU.
## PAN-271937
```caveat
PA-5450 firewalls only
```
Fixed an issue where the
logrcvr process stopped responding when processing
logs from a large number of sources.
## PAN-271926
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
## PAN-270549
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
## PAN-270471
```caveat
Firewalls in active/active configurations only
```
Fixed an
issue where the firewall did not detect configuration changes when
only the interface of an IKE gateway was changed, which caused IPSec
tunnels to not come up after migrating the IKE gateway IP address
from a subinterface to a physical interface.
## PAN-270077
```caveat
VM-Series firewalls in Amazon Web Services (AWS) environments only
```
Fixed an issue template values were missing in newly
spun firewalls in auto scale deployments without an explicit push
with forced template values from Panorama.
## PAN-269731
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch
(ES) getting restarted continuously.
## PAN-269539
Fixed an issue where whitespace was added before the timestamp in
syslog logs forwarded from Panorama.
## PAN-269499
Fixed an issue where the firewall stopped responding when receiving a
high number of logs.
## PAN-269106
Fixed issue where the wifclient
restarted and multiple processes stopped responding.
## PAN-268909
Fixed an issue where IP address tags were removed from firewalls
after a management server or useridd process restart.
This occurred when a Panorama serial-number based configuration was
used for User-ID redistribution.
## PAN-268815
Fixed an issue where the firewall entered a non-functional state due
to duplicate entries in the shared memory.
## PAN-268727
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
## PAN-267781
Fixed an issue where Panorama did not display the Source Dynamic
Address Group.
## PAN-267762
```caveat
Panorama virtual appliances in Management-Only mode
```
Fixed
a issue where the maximum configuration size was lower than
expected.
## PAN-267671
Fixed an issue where the firewall rebooted unexpectedly
due to the all_task process restarting with an OOM
condition due to a memory leak on the reportd
process.
## PAN-267430
Fixed an issue where Panorama was unable to return logs for queries
that were longer than 64,000 characters.
## PAN-267097
Fixed an issue where the replay database size increased significantly
due to local and special configurations not being purged after
commits.
## PAN-266581
Fixed an issue where a failed SSL connection to a syslog server
resulted in a /tmp/srvr.crt.xxxxxx file
not being removed, which caused index node (inode) exhaustion.
## PAN-266559
Fixed an issue where partial commits failed when objects that were
referenced in a high number of Security policy rules were
renamed.
## PAN-266354
Fixed an issue where Hybrid-SWG explicit proxy connections failed
when the number of destination domains exceeded 1024.
## PAN-265745
Fixed an issue where the firewall displayed incorrect MAC receive
error counters for VMWare devices hosted in ESXi.
## PAN-265179
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
## PAN-265160
Fixed an issue where the firewall created multiple connections to a
syslog server and remained in the FINWAIT1 state, which caused logs
to drop while being forwarded to the syslog server.
## PAN-264369
Fixed an issue where the 7 Day Threat Report
was empty in the scheduled reports sent via email.
## PAN-263291
Fixed an issue where Microsoft Outlook did not work as expected when
the GlobalProtect clientless VPN was configured.
## PAN-262627
Fixed an issue where the firewall rebooted into maintenance mode due
to a service failure in the configd process.
## PAN-262383
Fixed an issue where the firewall was unable to decompress the HTTP2
header, which caused the session to be classified as unknown-tcp
instead of web-browsing.
## PAN-262254
Fixed an issue where the firewall experienced an OOM condition and
the useridd process stopped responding, which caused
the firewall to drop interfaces from their respective aggregate
groups.
## PAN-261998
Fixed an issue where the firewall configuration process restarted
during an External Dynamic List refresh or a commit and push
operation.
## PAN-260290
Fixed an issue for fixed model licenses to support new content size
requirements by reducing the total sessions supported to be
equivalent to their flex memory counterpart
## PAN-260149
Fixed an issue where the management plane DNS cache size was lower
than expected.
## PAN-259055
Fixed an issue where the firewall stopped responding when receiving
SNMPv3 traps.
## PAN-258996
Fixed an issue where the firewall displayed the SFP ports as
PowerDown when the SFP transceiver
was removed and reinserted or the port was shut down and brought
back up on the peer device.
## PAN-257390
```caveat
PA-5250 firewalls only
```
Fixed an issue where the
logrcvr process stopped responding due to a
segmentation fault.
## PAN-256669
Fixed an issue where the memory usage reported by SNMP did not match
the memory usage reported by the top command.
## PAN-255773
Fixed an issue where errors related to applications in
Content-preview caused commit
failures.
## PAN-255747
Fixed an issue on the firewall where CLI commands returned
Server error: op command for client dagger timed
out as client is not available.
## PAN-255653
Fixed an HA failover issue where, when Management Processing Card
(MPC) or Base Card (BC) failures occurred, the HA link went down,
which caused fpp-down events on one firewall.
## PAN-253485
```caveat
Firewalls in active/passive HA configurations only
```
Fixed
an issue where dataplane packet capture filter configuration failed
on the active firewall with the error op command for
client dagger timed out as client is not
available.
## PAN-252669
Fixed an issue where the ikemgr process stopped
responding with a SIGSEGV error.
## PAN-252036
Fixed an issue where, when the GlobalProtect portal was not
configured, accessing the GlobalProtect gateway still loaded a
portal malformed page.
## PAN-252224
Fixed an issue where Panorama did not forward logs to a syslog server
over an SSL connection using CRL as a revocation verification
method.
## PAN-250585
Fixed an issue where the firewall CPU use increased after upgrading
from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
resource reporting by the REST API.
## PAN-246209
Fixed an issue where IPSec VPN tunnels went down after receiving a
DHCP server message that the DHCP client cleared the IP address on
the interface.
## PAN-242739
Fixed an issue on the firewall where the dataplane repeatedly
restarted.
## PAN-240225
Fixed an issue where authentication failed on web-based GlobalProtect
portal.
## PAN-238594
Fixed an issue where the firewall rebooted when a QSFP28 cable was
removed from the port while the port was passing traffic.
## PAN-232833
Fixed an issue where the following error message displayed for IoT
trial licenses: IoT Security license is required for
the feature to function.
## PAN-232550
Fixed an issue where SNMPv3 authentication failed when using SHA-512
Auth protocol.
## PAN-225228
Fixed an issue where filtering threat logs using any value under
THREAT ID/NAME displayed the error
Invalid term.
## PAN-218873
Fixed an issue where a HIP mask was reused when an existing IP
address user mapping was updated by a new IP address user mapping
that had a different username but the same IP address.
## PAN-216054
Fixed an issue that caused the firewall's fan speed to increase while
it was idle.
## PAN-214430
Fixed an issue where some commands did not have executable
permissions.
## PAN-212197
Fixed an issue where you were able to create local administrator
usernames that contained only numbers.
## PAN-207972
Fixed an issue on the web interface where the BGP routing table did
not display advertised routes.
## PAN-193285
Fixed an issue where the policy optimizer feature did not add entries
back to the mongodb database after
removing them during an upgrade or downgrade.
@@ -0,0 +1,75 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h15
---
## PAN-282236
Fixed an issue where large IPv6 packets were reassembled on the
firewall when the packets arrived fragmented over an IPv4
tunnel.
## PAN-280471
Fixed an issue where navigating PanoramaMonitorLogs was slower than expected.
## PAN-279746
Fixed an issue where SMTP packets were not sent out when the Client
Hello arrived at the firewall in multiple out-of-order segments and
the traffic was not subject to SSL decryption.
## PAN-279191
Fixed an issue where a GlobalProtect gateway stopped responding when
handling HTTP/1.1 traffic with web inspection enabled.
## PAN-278684
```caveat
PA-445 firewalls only
```
Fixed an issue where the firewall
did not properly power cycle during a reboot.
## PAN-275905
Fixed an issue where the Panorama web interface was slower than
expected and Elasticsearch CPU usage was high.
## PAN-275032
Fixed an issue where the Elasticsearch cluster certificate (CC)
status displayed with a past expiration date, which caused all
shards to be unassigned.
## PAN-273141
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec
tunnel.
## PAN-272085
Fixed an issue where the firewall might crash and reboot when DoH is
enabled for DNS Security and multiple DoH transactions are sent in a
single HTTP/1 connection.
## PAN-270744
Fixed an issue where API calls to Panorama failed with the error
Server error : Timed out while getting config
lock. Please try again.
## PAN-268279
Fixed an issue where autocommits failed if the management IPv6
gateway was the same as the dataplane interface IP address.
## PAN-242130
Fixed an issue where the firewall displayed the speed and duplex of
its dataplane interfaces as Unknown even
though the link was up.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h16
---
## PAN-282022
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
@@ -0,0 +1,156 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h17
---
## PAN-282022
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
## PAN-281885
Fixed an issue where, when exporting and importing CSV files, the
hash values of pre-shared key variables set at template and template
stack levels changed inconsistently, which resulted in both
variables displaying the same hash value.
## PAN-280505
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
## PAN-280243
Fixed an issue where the firewall lost the pre-shared key
configuration assigned from a PSK variable when an unrelated device
group configuration was loaded.
## PAN-279336
Fixed an issue where the CLI did not display a message to commit
prior changes before loading a partial configuration.
## PAN-279176
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
## PAN-277762
```caveat
VM-Series firewalls only
```
Fixed an issue where unexpected
failovers occurred on firewalls running PAN-OS 11.2.2-h2.
## PAN-275713
Fixed an issue where the dscd process stopped responding
when Endpoint Serial Number was enabled,
which resulted in the Active Directory
returning a list of serial numbers for a specific firewall from the
Cloud Identity Engine.
## PAN-275077
Fixed an issue where DNS Security intermittently logs malicious
domain URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
## PAN-274750
Fixed an issue where the detailed log view in Panorama did not
display all packet details for traffic logs received from the cloud.
## PAN-273694
Fixed an issue where the firewall rebooted due to an out-of-bounds
memory access that occurred as a result of the SIP content length
value being split across packets.
## PAN-272538
Fixed an issue where the configd process stopped
responding during a commit-all validation when there were
uncommitted changes and
share-unused-objects-with-devices
was set to off.
## PAN-272171
Fixed an issue where the firewall dropped the AAAA DNS server
response and caused delays in traffic from Ubuntu or Linux clients
when DNS Security was enabled.
## PAN-270607
```caveat
Firewalls in active/passive HA configurations only
```
Fixed
an issue where OSPF failed to establish after a failover from the
active firewall to the passive firewall.
## PAN-271351
A fix was made to address CVE-2025-0116.
## PAN-267091
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
## PAN-264678
Fixed an issue where Preview Changes did not
display configuration changes in Commit and push > Push
Scope.
## PAN-262511
Fixed an issue on firewalls in HA configurations where OSPF neighbors
were not established after an HA failover.
## PAN-261825
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
## PAN-259706
Fixed an issue on Panorama where the web interface was slower than
expected or unresponsive when monitoring definitions were added in
the Kubernetes plugin.
## PAN-257183
Fixed an issue where the firewall dropped DNS traffic when using DNS
Security.
## PAN-254174
A fix was made to address CVE-2025-0115.
## PAN-248762
Fixed an issue where, when the Advanced Routing Engine was configured
with OSPF, the firewall stopped responding when attempting to
connect to the neighbor while exchanging route maps.
## PAN-239201
Fixed an issue where partial commit or partial validation operations
failed for non-super user administrators with the error
<device-group-name> is invalid. meta data not
found for dg <device-group-name>.
## PAN-235733
Fixed an issue where the displayed NTP information was incorrect if
the DNS servers timed out.
@@ -0,0 +1,70 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h18
---
## PAN-286255
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a
slow buffer resource leak.
## PAN-282069
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
## PAN-280942
Fixed an issue where the logrcvr process stopped
responding.
## PAN-273949
Fixed an issue where the firewall generated the following error
message in the snmpd logs:
pan_get_keystr_from_cryptod(pan_snmpinterface.c:181):
Key X2F1dGhfa2V5 import from cryptod failed.
## PAN-271273
Fixed an issue where dynamic update downloads failed when
IPv6 firewalling was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
## PAN-270193
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
## PAN-268614
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
Highlight Unused Rules checkbox.
## PAN-265621
Fixed an issue where the restart option for
IPSec tunnels was greyed out when you attempted to restart the
tunnel from NetworkIPSec TunnelsIKE Info.
## PAN-260300
```caveat
PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only
```
Fixed an issue related to the
all_pktproc process where DPC slot 3 stopped
responding.
## PAN-259535
Fixed an issue where the firewall failed to boot up after running
power cycle tests due to ehmon process heartbeat
failures.
@@ -0,0 +1,66 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h1
---
## PAN-245690
Fixed an issue where the Managed Collectors
health status on Panorama displayed as empty.
## PAN-259733
Fixed an issue where a custom report was not deleted on Panorama when
expected.
## PAN-259480
Fixed an issue where the varrcvr process stopped
responding after running out of memory due to how the process queued
and dequeued files for WildFire file forwarding when a WildFire
Analysis Security profile was enabled.
## PAN-257615
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
## PAN-257462
Fixed an issue related to the varrcvr process where the
management plane CPU was higher than expected during WildFire
updates.
## PAN-257028
```caveat
Firewalls in active/passive HA configurations only
```
Fixed
an issue where firewalls entered a non-functional state and
displayed the error message Dataplane down: path
monitor failure during the fail-over.
## PAN-255711
Fixed an issue where the firewall displayed a malformed request error
when selecting a custom format and clicking
OK on the configuration window due to the
log type Correlation incorrectly being
displayed (Device > Log Setting - Correlation > Syslog
Server Profile > Custom Log Format >
Correlation).
## PAN-254373
Fixed an issue where the firewall did not handle error code 500
responses from the WildFire cloud correctly.
## PAN-225213
Fixed an issue where Push All Changes
displayed changes that were already committed in the push scope for
another device group after performing a selective commit and
selective push to the first device group.
@@ -0,0 +1,100 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h25
---
## PAN-292261
Fixed an issue where the firewall repeatedly reported an unreachable
syslog server as back online when the
server remained unavailable. This resulted in misleading alternating
connection status messages in the system logs.
## PAN-287423
Fixed an issue where content loading issues occurred on IPv6 websites
due to the firewall incorrectly setting the IPv6 header flow label
to 0.
## PAN-286255
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a
slow buffer resource leak.
## PAN-282069
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
## PAN-280942
Fixed an issue where the logrcvr process stopped
responding.
## PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
## PAN-279901
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them
correctly.
To enable this fix, run: debug dataplane set ssl-decrypt
accumulate-client-hello disjoined yes.
## PAN-273949
Fixed an issue where the firewall generated the following error
message in the snmpd logs:
pan_get_keystr_from_cryptod(pan_snmpinterface.c:181):
Key X2F1dGhfa2V5 import from cryptod failed.
## PAN-271273
Fixed an issue where dynamic update downloads failed when
IPv6 firewalling was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
## PAN-270193
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
## PAN-268614
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
Highlight Unused Rules checkbox.
## PAN-265621
Fixed an issue where the restart option for
IPSec tunnels was greyed out when you attempted to restart the
tunnel from NetworkIPSec TunnelsIKE Info.
## PAN-260300
```caveat
PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only
```
Fixed an issue related to the
all_pktproc process where DPC slot 3 stopped
responding.
## PAN-259535
Fixed an issue where the firewall failed to boot up after running
power cycle tests due to ehmon process heartbeat
failures.
@@ -0,0 +1,54 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h27
---
## PAN-301801
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
## PAN-292159
A fix was made to address CVE-2025-4615.
## PAN-291661
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
## PAN-286164
A fix was made to address CVE-2025-4614.
## PAN-282093
Enhanced the CLI command request legacy
reset to delete the legacy certificate files that
were being used to connect with the secondary Panorama appliance.
## PAN-278296
Fixed an issue where the system MAC address of the aggregate
interface was the same on the active firewall and the passive
firewall after an upgrade.
## PAN-272539
```caveat
Panorama appliances on Microsoft Azure environments only
```
Fixed an issue where user to IP address mapping was missing for some
users connected to specific Prisma Access gateways, which caused the
collection layer Azure firewall to not form the mapping.
## PAN-271221
A fix was made to address CVE-2025-4615.
## PAN-251715
Fixed an issue where the firewall closed the SSL connection to the
user ID agent.
@@ -0,0 +1,343 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h4
---
## PAN-265963
Fixed an issue where the escd process caused a memory
leak when session resiliency was enabled on the firewall.
## PAN-265349
Fixed an issue where multiple segments of HTTP proxy connect messages
were not handled correctly by proxy.
## PAN-264421
Fixed an issue on Panorama where Push Scope
did not populate automatically after changing the device group
configuration.
## PAN-263987
Fixed an issue on the firewall where, when a NAT transversal IPSec
tunnel was terminated, and the NAT rule that was applied to the
NAT-T IPSec tunnel was on the same firewall, traffic flowing through
the tunnel was not correctly translated.
## PAN-263559
Fixed an issue where the dataplane stopped responding and the
firewall unexpectedly rebooted due to multiple process restarts.
## PAN-263226
Fixed an issue where, when SSL decryption was enabled and Client
Hello messages spanned multiple TCP segments, some SSL decrypted
sessions failed.
## PAN-262593
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
## PAN-262340
Fixed an issue where FQDN resolution failed for address objects, and
all FQDN traffic was denied by the interzone-default policy
rule.
## PAN-262287
Fixed an issue where dereferencing a NULL pointer that occurred when
App-ID stopped responding caused the firewall to restart.
## PAN-261991
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
## PAN-261917
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
## PAN-261909
Fixed an issue where the GlobalProtect client did not display the
dialog box for an MFA verification code.
## PAN-261489
Fixed an issue where an out-of-memory (OOM) condition caused a
firewall outage.
## PAN-261484
Fixed an issue on the firewall where DPDK allocated twice the amount
of memory as requested for pre-allocation.
## PAN-261001
Fixed an issue where GlobalProtect users were unable to switch
gateways after upgrading to GlobalProtect version 6.2.3.
## PAN-260974
Fixed an issue where the Cloud Identity Engine (CIE) user context did
not correctly redistribute user/IP address port mapping to
on-premises firewalls.
## PAN-259997
```caveat
PA-3410, PA-3420, and PA-3430 firewalls only
```
Fixed an
issue where the install failed when upgrading from PAN-OS 10.2.3-h3
and later 10.2 releases to PAN-OS 10.2.10 due to the number of
configured vsys zones exceeding the zone limit in PAN-OS
10.2.10.
## PAN-259769
Fixed an issue where the GlobalProtect portal was not accessible via
a web browser and displayed the error
ERR_EMPTY_RESPONSE.
## PAN-259151
Fixed an issue where unused objects were pushed to the firewall,
which caused configuration pushes to fail with the error
Number of address groups exceed platform
capacity.
## PAN-258736
Fixed an issue where policy rule configurations pushed from Panorama
were not reflected on the firewall if the rule had 63
characters.
## PAN-258225
Fixed an issue on the Panorama web interface where Security policy
rules loaded more slowly than expected.
## PAN-257957
```caveat
Firewalls and Panorama appliances in FIPS-CC mode only
```
Fixed an issue where the authd process restarted if RADIUS
PAP/CHAP authentication was used.
## PAN-257925
```caveat
CN-Series firewalls only
```
Fixed an issue where the CLI
command show system setting ctd state did not
work as expected.
## PAN-256725
Fixed an issue on the Panorama interface where
Traffic and
Unified event details loaded more slowly
than expected.
## PAN-256666
Fixed an issue where the configdprocess stopped responding
when Commit and Push operations were performed on multiple
device groups.
## PAN-256385
```caveat
CN-Series firewalls only
```
Fixed an issue where
communication was broken between the management plane and the
dataplane when anti-spyware profiles were configured in a Security
policy rule.
## PAN-256350
Fixed an issue where, when you cloned an admin role or an LDAP server
profile and then changed the name of the clone, the configuration
change was not reflected on the managed firewall after pushing the
configuration from Panorama.
## PAN-256320
```caveat
Firewalls in active/passive HA configurations only
```
Fixed
an issue where GTP sessions remained as allocated sessions on the
passive firewall even when there were no active sessions.
## PAN-255930
Fixed an issue where persistent DIPP NAT entries were deleted even
when being used during an active session.
## PAN-255266
Fixed an issue where you were unable to clone a template stack with
the Pre-Shared Key variable.
## PAN-254826
Fixed an issue where the firewall stopped responding when processing
traffic.
## PAN-254671
Fixed an issue where excessive Timed out while getting
config lock error messages were generated when
making bulk changes via XML API.
## PAN-254423
Fixed an issue on Panorama where custom role-based admin users with
read only access were able to make changes to configurations.
## PAN-253626
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently fail.
## PAN-253213
Fixed an issue where the firewall sent HIP notifications every time
it received a HIP report instead of every two hours.
## PAN-252300
Fixed an issue where you were unable to select device groups in the
push scope for user accounts.
## PAN-251676
Fixed an issue on Panorama appliances in large-scale deployments
where configd process core files consumed more space in
the /opt/panlogs partition than was available.
## PAN-251655
Fixed an issue where the firewall stopped forwarding files to the
WildFire cloud and a restart of the varrcvr process was
required.
## PAN-250787
Fixed an issue where network issues between the firewall and the log
collector caused logrcvr process memory exhaustion.
## PAN-250419
Fixed an issue where XML API explorer inserted a plus (+) character
in the Xpath when a space was used in the object name.
## PAN-250062
Fixed an issue where device telemetry failed after upgrading due to
bundle generation failure.
## PAN-249266
Fixed an issue where the config process virtual memory
was exceeded due to delays in post-commit processing.
## PAN-249011
Fixed an issue where the firewall became unresponsive when committing
a configuration change with a large number of uncommitted changes in
the replay database.
## PAN-247099
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
## PAN-246304
Fixed an issue on Panorama where commits failed due to a timeout in
the sysd process during decryption.
## PAN-246220
Fixed an issue where a dynamic peer connection was rejected when
using an FQDN for the peer address.
## PAN-244039
```caveat
PA-5450 firewalls only
```
Fixed an issue where the firewall
dropped packets when attempting to reuse a TCP session.
## PAN-243098
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
## PAN-241781
Fixed an issue where partial commit and commit-all operations took
more time than expected to create the job ID.
## PAN-241044
Fixed an issue where traffic was denied by the interzone-default
policy rule when a Security policy rule with an FQDN destination was
configured.
## PAN-234560
Fixed an issue where the daily summary report displayed IPv6
addresses instead of IPv4 addresses.
## PAN-233727
Fixed an issue on the web interface where the following error message
was incorrectly displayed for an IKE gateway with a valid
configuration: ikev2->pq-ppk->negotiation-mode is
invalid.
## PAN-237582
Fixed an issue where logs were intermittently missing on the log
collector due to missing aliases for some indices
## PAN-234094
Fixed an issue on Panorama where Deploy Master Keyresulted in
the error message Failed to communicate with device due to a low
connection timeout value.
## PAN-232214
Fixed an issue where GlobalProtect clients remained in the connecting
state during portal pre-login when Kerberos single sign-on (SSO) was
enabled.
## PAN-230825
Fixed an issue where link flaps occurred on Panorama appliances in HA
configurations.
@@ -0,0 +1,133 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h7
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
## PAN-268823
Fixed an issue where MonitorLog Display did not display all logs when you applied a
filter.
## PAN-265785
Fixed an issue where the firewall rebooted due to a sysd
variable being modified before it was created.
## PAN-264883
```caveat
PA-7080 appliances with LPCs only
```
Fixed an issue where
syslog forwarding over TCP stopped after upgrading.
## PAN-263369
Fixed an issue where commits from Panorama to Panorama virtual
appliances failed with the error message Internal
error during commit processing. Commit/Validate
failed after upgrading Panorama.
## PAN-261673
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where, when Accelerated Networking was enabled,
traffic was dropped because of the
flow_parse_ip_hdr counter related
to an Nvidia driver issue.
## PAN-261371
```caveat
PA-5410 firewalls in active/passive high availability (HA) configurations only
```
Fixed an issue where the
reportd process restarted, which caused the
firewall to reboot.
## PAN-261209
```caveat
Firewalls in active/active HA configuration only
```
Fixed an
issue where the firewall displayed the HA2 status as down when the
HSCI port was used for both HA2 and HA3.
## PAN-260905
Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a
cold boot and remained in an incorrect state.
## PAN-260316
Fixed an issue where the all_task process stopped
responding and the firewall rebooted.
## PAN-259351
A fix was made to address CVE-2024-3393.
## PAN-259002
Fixed an issue where frequent external dynamic list updates caused
the configd process to restart.
## PAN-257601
```caveat
PA-5450 firewalls only
```
Fixed an issue where Networking
Cards (NC) experienced an internal link fault which caused path
monitoring failure on the Dataplane Processing Card (DPC).
## PAN-257327
Fixed an issue where a failover event occurred unexpectedly on the
firewall.
## PAN-256223
Fixed an issue where device telemetry log collection filled the root
partition.
## PAN-254794
Fixed an issue where the Panorama management server stopped
responding.
## PAN-249384
Fixed an issue on Panorama where configuration locks were observed
during a partial rulebase commit.
## PAN-243240
Fixed an issue where the using QoS caused packet buffer utilization
to increase exponentially and the PKI POOL
DFLT pool depleted until a reboot was
performed.
## PAN-242479
Fixed an issue where a high number of packets caused high packet
descriptors on the firewall when handling EtherIP traffic.
## PAN-230893
Added a CLI command to address an issue where system lock files
blocked authentication.
@@ -0,0 +1,275 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4-h9
---
## PAN-273215
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
## PAN-271912
Fixed an issue on Panorama where the *configd* process stopped
responding when filtering in the configuration audit window after
upgrading to PAN-OS 11.1.3.
## PAN-271613
Fixed an issue where configuration pushes from Panorama to the
firewall failed due to an OOXML commit error.
## PAN-271314
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
## PAN-270224
Fixed an issue where indices were not opened after a query.
## PAN-269956
Fixed an issue where the all_pktproc process stopped
responding, which caused internal path monitor failures.
## PAN-269899
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
## PAN-269673
Fixed an issue where ElasticSearch was not set up after an
upgrade.
## PAN-269000
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
## PAN-268972
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
## PAN-268501
Fixed an issue where the firewall was unable to generate a TSF file
due to a full root partition.
## PAN-266639
Fixed an issue where administrators were unable to edit or add
virtual router configurations when a filter was applied to the
viewer.
## PAN-266114
Fixed an issue where, when a new set of URL logs came in, the content
of the earlier URL and traffic logs were lost.
## PAN-265973
Fixed an issue where administrator sessions were logged out with an
ERR_CONNECTION_REFUSED error on the
browser.
## PAN-265742
Fixed an issue on the Panorama web interface where the
OK button on the GlobalProtect gateway
configuration dialog box was not clickable.
## PAN-265219
```caveat
VM-Series firewalls only
```
Fixed an issue where GRE traffic
did not work properly.
## PAN-264871
Fixed an issue on Panorama where the configd process
stopped responding when viewing IP addresses on dynamic address
groups with a large number of IP addresses.
## PAN-264249
Fixed an issue on the firewall where SNMP queries timed out when
using SNMP.
## PAN-263973
Fixed an issue where log collectors had a low incoming log rate.
## PAN-263287
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
## PAN-263208
```caveat
PA-5440 and PA-5445 firewalls only
```
Fixed an issue where
interrupts were generated at a certain packet rate, and dataplane
processes missed heartbeats, which caused the dataplane to go
down.
## PAN-263017
Fixed an issue where the firewall was unable to mount a disk
partition due to a corrupted filesystem.
## PAN-261485
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
## PAN-260604
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
## PAN-260512
Fixed an issue where accessing the IP address of the device address
group objects from the user interface caused the
configd process to stop responding.
## PAN-260461
Fixed an issue where traffic logs showed a non-zero destination port
number on ICMP echo sessions through the firewall.
## PAN-260417
Fixed an issue on Panorama where
UpdateLicDB was triggered every few
minutes when firewalls with PAYG licenses were onboarded.
## PAN-260235
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when
Enhanced Application Logging was enabled.
## PAN-259910
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
## PAN-259881
Fixed an issue on Panorama where traffic log details were not
displayed under detailed log view.
## PAN-259802
```caveat
Panorama appliances in high availability (HA) clusters only
```
Fixed an issue where, after replacing a secondary
Panorama appliance in a Panorama HA cluster, the ElasticSearch
cluster was unable to establish SSL tunnels due to
SSLHandshakeException errors.
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed: Error 500:
Internal Server Error.
## PAN-258799
Fixed an issue where, when updating a Security Policy
Policy Optimizer, the web interface
stopped responding.
## PAN-257961
Fixed an issue on Panorama where Test Security Policy
Match failed when the From or
To zone fields were populated.
## PAN-255915
Fixed an issue where a memory leak in the sslmgr process
caused the firewall to restart.
## PAN-254904
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
## PAN-254577
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
## PAN-253829
Fixed an issue where the CLI command show running
security-policy timed out when the Security
policy was large.
## PAN-252381
Fixed an issue where the Panorama web interface was slower than
expected when opening interfaces, virtual routers, and zones in a
template or template stack.
## PAN-250394
Fixed an issue where a large amount of group data caused
serialization errors and prevented synchronization.
## PAN-249581
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
## PAN-246699
Fixed an issue on Panorama where the Rule
Usage and Apps Seen under
Security policy rules stopped incrementing.
## PAN-246567
Fixed an issue where a firewall with a copper SFP transceiver
(PAN-SFP-CG) flapped during a commit.
## PAN-242331
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
## PAN-241004
Fixed an issue where DNS Proxy dropped client requests of the type
ns for a root domain.
## PAN-235808
```caveat
Panorama appliances in Log Collector mode only
```
Fixed an
issue where an unnamed core file was generated after a reboot.
## PAN-233197
Fixed an issue where the CLI command to set the FEC parameter for the
front panel ports was not supported on platforms supporting 25G and
100G.
@@ -0,0 +1,102 @@
---
type: Addressed
product: PAN-OS
version: 11.1.4
---
## PAN-256181
Fixed an issue where the management interface and front panel port interface statistics were not populated in asynchronous mode of SNMP operations.
## PAN-255868
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the firewall entered maintenance mode after enabling kernel data collection during the silent reboot.
## PAN-253317
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where you were unable to log in to the firewall after a private data reset.
## PAN-252517
Fixed an issue where SNMP failed to respond to multiple Object Identifier (OID) queries in a single SNMP GET request.
## PAN-251639
Fixed an issue where an out of memory condition might occur due to a
memory leak in the varrcvr process when a Wildfire
Analysis security profile is enabled.
## PAN-250597
Fixed an issue where Global Find for a Panorama pushed shared address object displayed Others in the results.
## PAN-250270
Fixed an issue where partial commits did not merge changes when the complete rule base was updated with edit operations via XML API.
## PAN-249814
Fixed an issue where multiple all_task processes stopped responding, which caused
the dataplane to fail.
## PAN-249292
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where CPU usage was higher than expected after a
hotplug event when Accelerated Networking was enabled for the
management interface.
## PAN-245157
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall restarted after an HA failover when DPDK was enabled.
## PAN-245125
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where file descriptors were not closed due to invalid configurations.
## PAN-244746
Fixed an issue where changes committed on Panorama were not reflected on the firewall after a successful push.
## PAN-238183
Fixed an issue where Panorama displayed deviating device system logs for non-connected interfaces.
## PAN-236497
Fixed an issue where the firewall was unable to purge expired GTP-U sessions that remained as allocated sessions even after the TTL was expired.
## PAN-234977
Fixed an issue where, when a Layer 2 interface that was a member of a VLAN was down, all traffic transmitted over the VLAN was dropped.
## PAN-231642
Fixed an issue on the Panorama web interface where users that were logged in through multiple sessions were able to see an active lock on only one session.
## PAN-214773
Fixed an issue where RTP packets traversing inter-vsys were dropped on the outgoing vsys.
## PAN-202095
Fixed an issue on the web interface where the language setting was not retained.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.1.5-h1
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
File diff suppressed because it is too large Load Diff
+38
View File
@@ -84,6 +84,44 @@
"addressed": [ "addressed": [
"11.1.0_2026-03-13.md", "11.1.0_2026-03-13.md",
"11.1.0-h1_2026-03-13.md", "11.1.0-h1_2026-03-13.md",
"11.1.0-h2_2026-03-16.md",
"11.1.0-h3_2026-03-16.md",
"11.1.0-h4_2026-03-16.md",
"11.1.1_2026-03-16.md",
"11.1.1-h1_2026-03-16.md",
"11.1.1-h2_2026-03-16.md",
"11.1.2_2026-03-16.md",
"11.1.2-h1_2026-03-16.md",
"11.1.2-h3_2026-03-16.md",
"11.1.2-h4_2026-03-16.md",
"11.1.2-h9_2026-03-16.md",
"11.1.2-h12_2026-03-16.md",
"11.1.2-h14_2026-03-16.md",
"11.1.2-h15_2026-03-16.md",
"11.1.2-h16_2026-03-16.md",
"11.1.2-h18_2026-03-16.md",
"11.1.3_2026-03-16.md",
"11.1.3-h1_2026-03-16.md",
"11.1.3-h2_2026-03-16.md",
"11.1.3-h4_2026-03-16.md",
"11.1.3-h6_2026-03-16.md",
"11.1.3-h10_2026-03-16.md",
"11.1.3-h11_2026-03-16.md",
"11.1.3-h13_2026-03-16.md",
"11.1.4_2026-03-16.md",
"11.1.4-h1_2026-03-16.md",
"11.1.4-h4_2026-03-16.md",
"11.1.4-h7_2026-03-16.md",
"11.1.4-h9_2026-03-16.md",
"11.1.4-h13_2026-03-16.md",
"11.1.4-h15_2026-03-16.md",
"11.1.4-h16_2026-03-16.md",
"11.1.4-h17_2026-03-16.md",
"11.1.4-h18_2026-03-16.md",
"11.1.4-h25_2026-03-16.md",
"11.1.4-h27_2026-03-16.md",
"11.1.5_2026-03-16.md",
"11.1.5-h1_2026-03-16.md",
"11.1.6_2026-03-13.md", "11.1.6_2026-03-13.md",
"11.1.6-h1_2026-03-13.md", "11.1.6-h1_2026-03-13.md",
"11.1.6-h3_2026-03-13.md", "11.1.6-h3_2026-03-13.md",