--- type: Addressed product: PAN-OS version: 10.2.13-h3 --- ## PAN-274570 Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access. ## PAN-273994 A fix was made to address [CVE-2025-0111](https://security.paloaltonetworks.com/CVE-2025-0111). ## PAN-273971 A fix was made to address [CVE-2025-0108](https://security.paloaltonetworks.com/CVE-2025-0108). ## PAN-273278 A fix was made to address [CVE-2025-0109](https://security.paloaltonetworks.com/CVE-2025-0109). ## PAN-273215 Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading. ## PAN-273021 Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules. ## PAN-271926 Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic. ## PAN-270549 Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane. ## PAN-269899 Fixed an issue where the Panorama web interface was slower than expected when querying for device tags. ## PAN-269731 Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously. ## PAN-269624 Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license. ## PAN-268972 Fixed an issue where Panorama was slower than expected when using a high number of device group tags in a non-shared context. ## PAN-268909 Fixed an issue where IP address tags were removed from firewalls after a management server or useridd process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution. ## PAN-268727 Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets. ## PAN-268319 Fixed an issue where **Receive Time** and **Time Generated** were not visible as attributes in the **Filter Builder** for system logs and URL filtering logs. ## PAN-268260 Fixed an issue on hardware firewalls where, when SSL decryption was enabled and Client Hello messages spanned multiple TCP segments, some SSL decrypted sessions failed. ## PAN-267781 Fixed an issue where Panorama did not display the Source Dynamic Address Group. ## PAN-267671 Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting with an OOM condition due to a memory leak on the reportd process. ## PAN-267001 Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds. ## PAN-266312 Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP. ## PAN-265179 Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic. ## PAN-261739 ```caveat VM-Series firewalls in Microsoft Azure environments only ``` Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC. ## PAN-259002 Fixed an issue where frequent external dynamic list updates caused the configd process to restart. ## PAN-256051 Fixed an issue on the firewall where enabling flow basic caused the firewall to stop responding due to a masterd process restart. ## PAN-249597 Fixed an issue where the **Policy** page on the Panorama web interface was slower than expected when a device group had a large number of managed devices. ## PAN-246949 Fixed an issue where custom admin users were not able to click **OK** in the push scope selection window when device group or template were disabled under commit in the admin roles. ## PAN-240739 Fixed an issue where the ECMP FIB update on the dataplane didn't clear the pending change flag, which caused the next non-ECMP FIB update to miss the latest generation ID and age out after 5 minutes ## PAN-225213 Fixed an issue where **Push All Changes** displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group. ## PAN-215038 Fixed an issue where the output of the request logging-service-forwarding status CLI command did not display the correct information after successfully onboarding a firewall to Cloud Delivered Licensing (CDL).