Files

795 lines
24 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixes were made to address the following CVEs:
<ul id="pan_os_11_2_13_addressed_issues_ul-nwg_dxl_vjc" class="ul">
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0283"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0283</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0287"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0287</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0279"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0279</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0282"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0282</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0288"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0288</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0286"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0286</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0285"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0285</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0280"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0280</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0284"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0284</a
>
</li>
<li class="li">
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2026-0281"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2026-0281</a
>
</li>
</ul>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-328145</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall functioning as an Area Border Router
did not correctly translate NSSA Type-7 LSAs to Type-5 LSAs when OSPF
neighbors set the Nt bit in the NSSA Area, and routes were not
advertised to upstream OSPF neighbors in the backbone area, which
resulted in traffic being silently discarded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-321699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry intermittently failed to send
files, which resulted in critical alerts in system files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-321150</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the interface remained down after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-320598</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where internal and external DNS names did not resolve
when connected to a GlobalProtect gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-319798</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances in AWS environments only</tt
>) Fixed an issue where logging disks failed to mount or reported an
unknown file system type.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-319793</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 12.1.5, GlobalProtect
Clientless VPN failed to access JavaScripts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-319266</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Cloud IPS only</tt>) Increased scale limit for zone
mappings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-319228</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where External Dynamic List (EDL) refresh and commit
operations remained in a pending state, which prevented any subsequent
operations from completing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-318120</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic was silently dropped when traffic was
processed by a Security policy with an Anti-Spyware profile that had
Inline cloud Analysis enabled for SSL C2 Detector with an action other
than allow or alert.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-318106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SCM did not update device telemetry for the
firewall after upgrading to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-318030</b></div>
</td>
<td class="entry relcol">
<div class="p">
<tt class="ph tt">VM-Series firewalls in Hyper-V only</tt>) Fixed an
issue where the throughput was reported to be twice as high as the
actual traffic rate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-317755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where selective push operations failed when
plugin configurations included access-domain or log-collector
references.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-317614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high throughput and increased packet rates caused
high dataplane CPU usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-317466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SIP sessions stopped progressing after the
firewall received fragmented packets, fragmented at header field.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-317215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on ESXi with Intel E810 NICs using PCI
passthrough</tt
>) Fixed an issue where the
<span class="ph systemoutput">brdagent</span> process became
unresponsive during data port initialization, which resulted in system
instability, interface outages, HA split-brain conditions, and
unexpected reboots during failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-315919</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect pre-logon tunnel session was not
cleared even after the user was logged in. With this fix, the session
is cleared after the session timeout expires.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-315337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect throughput was reduced after an
upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-315314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a push operation from Panorama to the
firewall failed, accounting logs stopped forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-314512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal became inaccessible when
the dataplane was configured with a DHCP assigned IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-314061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was disrupted during IPSec rekey
operations due to a 2 second delay in sending the DELETE message for
the previous Security Association (SA) to the peer gateway after a new
SA was negotiated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-314020</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not decapsulate GENEVE packets
when DNS Security retransmitted a DNS query after receiving a verdict
from the cloud.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-313850</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series firewalls in HA configurations only</tt
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
links went down while upgrading when the HA configuration used
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
interfaces for HA2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-313828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward traffic due to
memory issues on a forwarding component.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-312330</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the Clientless VPN applications failed to load
due to the firewall dataplane incorrectly processing session
information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311658</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ospfd</a
>
process, which caused RAM usage to continuously increase until the
device stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311192</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>device-telemetry collect-now</a
>
process became unresponsive when the process was initiated multiple
times with other processes running concurrently, which prevented
subsequent telemetry collection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311040</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding and caused the firewall to reboot
unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-310240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where software packet buffers were completely utilized
when performing a Data Loss Prevention longevity test.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308775</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive configurations only</tt
>) Fixed an issue where NTP status intermittently showed as rejected
on the active firewall, which prevented the firewalls from
synchronizing time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307976</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where tunnels failed to come up with the error
message
<span class="ph systemoutput"
>failed to find a socket for transmission</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307618</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a debug CLI command to address where remote networks for Prisma
Access tenants randomly dropped monitoring packets from peer devices,
which caused tunnels to be marked as down. This occurred when a CPU
core suddenly experienced high utilization.
</div>
<div class="p">
To utilize this fix, run
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt use-new-peek-window yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307470</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an External Dynamic List (EDL) fetch with an
invalid certificate was skipped on newly provisioned GlobalProtect
gateway instances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306356</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process on a firewall stopped responding due to a document node being
unexpectedly freed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped after multiple content versions were installed and the
memory limits were reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall continuously rebooted when the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where policy cache corruption led to unexpected policy
rule behavior or operational instability. This occurred when an
internal system process restarted while a commit was in progress or
when a commit operation failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295806</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks on the
<span class="ph systemoutput">configd</span> process occurred due to a
hash insert operation failing during connection management and SSL
connections.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294434</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks occurred. These leaks were caused by
two distinct scenarios: the failure to deallocate memory for a nodeset
when a new nodeset was assigned to the same variable, and the failure
to free a UUID hash table during error conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250445</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DLP logs accumulated in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
cache when using DLP in mirror mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Rule Usage</span> and
<span class="ph uicontrol">Apps Seen</span> under Security policy
rules stopped incrementing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234302</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commit operations took longer than expected to
complete due to EDL timeouts occurring on passive nodes when a service
route was enabled.
</div>
</td>
</tr>
</tbody>
</table>