Processed new files
This commit is contained in:
@@ -0,0 +1,176 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.15
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Fixes were made to address the following CVEs:
|
||||
|
||||
- [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265)
|
||||
- [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264)
|
||||
- [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263)
|
||||
- [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262)
|
||||
- [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261)
|
||||
- [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258)
|
||||
- [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257)
|
||||
- [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256)
|
||||
- [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259)
|
||||
- [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300)
|
||||
|
||||
## PAN-325120
|
||||
|
||||
Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports.
|
||||
|
||||
## PAN-323243
|
||||
|
||||
Fixed an issue where a configd crash occurred when the **Policies > Security** view was updated or refreshed in the web interface.
|
||||
|
||||
## PAN-322815
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted.
|
||||
|
||||
## PAN-319557
|
||||
|
||||
Fixed an issue where graphical counters did not display correctly in the control plane or dataplane monitor logs.
|
||||
|
||||
## PAN-318784
|
||||
|
||||
Fixed an issue where the firewall stopped processing traffic and all VPN tunnels went down even when the firewall remained in an active state, and the CLI became unresponsive.
|
||||
|
||||
## PAN-318567
|
||||
|
||||
Fixed an issue where the OpenConfig plugin stopped working after a configuration update.
|
||||
|
||||
## PAN-317583
|
||||
|
||||
Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.
|
||||
|
||||
## PAN-317466
|
||||
|
||||
Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field.
|
||||
|
||||
## PAN-317372
|
||||
|
||||
Fixed an issue where custom administrators received an **access denied** error when attempting to view specific policy rule details from the **Rule Shadow** tab after a push from Panorama, even when the administrator had permissions to view Security policy rules.
|
||||
|
||||
## PAN-316631
|
||||
|
||||
Fixed an issue BGP sessions experienced short disruptions across all peers, interfaces, and slots when a multicast event persisted longer than the NGP negotiated hold timers.
|
||||
|
||||
## PAN-315820
|
||||
|
||||
Fixed an issue where User-ID XML API requests took longer than expected to return a response, which caused the web interface and captive portal pages to respond slowly or fail to load. this occurred when sending XML API requests for IP address-to-user mapping.
|
||||
|
||||
## PAN-314875
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewall logs were not visible in the Strata Logging Service even though cloud logging was enabled and the firewall was successfully forwarding logs.
|
||||
|
||||
## PAN-314752
|
||||
|
||||
Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time.
|
||||
|
||||
## PAN-314385
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA clusters only
|
||||
```
|
||||
|
||||
Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall.
|
||||
|
||||
## PAN-314126
|
||||
|
||||
Fixed an issue where session rematch did not properly apply updated Security policy rules to existing traffic flows after committing changes, which caused traffic to still be allowed when a new Security policy was set to **Deny**.
|
||||
|
||||
## PAN-314020
|
||||
|
||||
Fixed an issue where the firewall did not decapsulate GENEVE packets when DNS Security retransmitted a DNS query after receiving a verdict from the cloud.
|
||||
|
||||
## PAN-313828
|
||||
|
||||
Fixed an issue where the firewall did not forward traffic due to memory issues on a forwarding component.
|
||||
|
||||
## PAN-313827
|
||||
|
||||
Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API.
|
||||
|
||||
## PAN-313711
|
||||
|
||||
Fixed an issue where the show system environmentals power CLI command displayed duplicate slot names and associated voltage values.
|
||||
|
||||
## PAN-313700
|
||||
|
||||
Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile.
|
||||
|
||||
## PAN-313193
|
||||
|
||||
```caveat
|
||||
Firewalls in Layer 2 mode only
|
||||
```
|
||||
|
||||
) Fixed an issue where the new sessions were not able to be established due to the firewall intermittently dropping valid MAC address entries for specific VLANs when a manual switchover sent a high volume of traffic to the firewall.
|
||||
|
||||
## PAN-311248
|
||||
|
||||
Fixed an issue where the ABR failed to translate and advertise the default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF backbone area as a Type-5 LSA.
|
||||
|
||||
## PAN-310472
|
||||
|
||||
Fixed an issue on the web interface where checkboxes for **default information originate** and ABR in OSPF NSSA configurations were automatically enabled which resulted in unexpected configuration changes.
|
||||
|
||||
## PAN-307470
|
||||
|
||||
Fixed an issue where an External Dynamic List (EDL) fetch with an invalid certificate was skipped on newly provisioned GlobalProtect gateway instances.
|
||||
|
||||
## PAN-298960
|
||||
|
||||
Fixed an issue where the firewall continuously rebooted when the useridd process repeatedly restarted.
|
||||
|
||||
## PAN-295309
|
||||
|
||||
Fixed an issue where OSPF session using MD5 authentication experienced intermittent flapping due to out-of-order packet processing.
|
||||
|
||||
## PAN-294001
|
||||
|
||||
Fixed an issue on Panorama managed firewalls generated **Failed in get_pwchange_required** error messages in the authd logs for local administators.
|
||||
|
||||
## PAN-293142
|
||||
|
||||
Fixed an issue where firewall components became unresponsive during sustained operation.
|
||||
|
||||
## PAN-289706
|
||||
|
||||
Fixed an issue where the authd process crashed intermittently on VM-Series firewalls due to authentication sequence failures. The crashes occurred during memory management operations within a library while releasing memory to its central cache.
|
||||
|
||||
## PAN-285213
|
||||
|
||||
Fixed an issue where proxy requests for certificate status (OCSP/CRL) from sslmgr contained incorrect values that caused unknown certificates to be blocked.
|
||||
|
||||
## PAN-282335
|
||||
|
||||
Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled.
|
||||
|
||||
## PAN-273805
|
||||
|
||||
Fixed an issue where SAML authentication for GlobalProtect failed when the GlobalProtect portal was accessed externally on a non-standard port.
|
||||
|
||||
## PAN-271412
|
||||
|
||||
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
|
||||
|
||||
## PAN-257879
|
||||
|
||||
Fixed an issue where, after a system event, selecting a configuration file from maintenance mode loaded the incorrect configuration.
|
||||
|
||||
## PAN-236914
|
||||
|
||||
Fixed an issue where TCP MSS adjustment did not function as expected for GRE tunnels when TCP SYN or SYN-ACK packets that were received had an MMS higher than 1460 bytes.
|
||||
@@ -0,0 +1,84 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.2.12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Fixes were made to address the following CVEs:
|
||||
|
||||
- [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265)
|
||||
- [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264)
|
||||
- [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263)
|
||||
- [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262)
|
||||
- [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261)
|
||||
- [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258)
|
||||
- [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257)
|
||||
- [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256)
|
||||
- [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259)
|
||||
- [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300)
|
||||
|
||||
## PAN-325120
|
||||
|
||||
Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports.
|
||||
|
||||
## PAN-322815
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted.
|
||||
|
||||
## PAN-318275
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot.
|
||||
|
||||
## PAN-317583
|
||||
|
||||
Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.
|
||||
|
||||
## PAN-315912
|
||||
|
||||
Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.
|
||||
|
||||
## PAN-315176
|
||||
|
||||
Added an enable and disable CLI command to address an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic.
|
||||
|
||||
## PAN-314319
|
||||
|
||||
Added a CLI command to enable and disable AHO software offload optimization.
|
||||
|
||||
## PAN-314147
|
||||
|
||||
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.
|
||||
|
||||
## PAN-314018
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the decrypt mirror port did not function expected, which prevented decrypted traffic from reaching the intended destination collector.
|
||||
|
||||
## PAN-313700
|
||||
|
||||
Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile.
|
||||
|
||||
## PAN-313216
|
||||
|
||||
Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned.
|
||||
|
||||
## PAN-312514
|
||||
|
||||
Fixed an issue where correlation logs were not forwarded via syslog or email.
|
||||
|
||||
## PAN-312354
|
||||
|
||||
Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to **ERR_CONNECTION_RESET** error messages in the browser with SSL decryption and CTD handshake inspection enabled.
|
||||
@@ -79,7 +79,8 @@
|
||||
"11.2.10-h6.md",
|
||||
"11.2.10-h7.md",
|
||||
"11.2.10-h8.md",
|
||||
"11.2.11.md"
|
||||
"11.2.11.md",
|
||||
"11.2.12.md"
|
||||
],
|
||||
"known": [
|
||||
"11.2.0.md",
|
||||
@@ -184,7 +185,8 @@
|
||||
"11.1.13-h3.md",
|
||||
"11.1.13-h5.md",
|
||||
"11.1.13-h6.md",
|
||||
"11.1.14.md"
|
||||
"11.1.14.md",
|
||||
"11.1.15.md"
|
||||
],
|
||||
"known": [
|
||||
"11.1.0.md",
|
||||
|
||||
Reference in New Issue
Block a user