126 lines
4.4 KiB
Markdown
126 lines
4.4 KiB
Markdown
---
|
|
type: Addressed
|
|
product: PAN-OS
|
|
version: 10.2.13-h3
|
|
---
|
|
|
|
## PAN-274570
|
|
|
|
Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access.
|
|
|
|
## PAN-273994
|
|
|
|
A fix was made to address [CVE-2025-0111](https://security.paloaltonetworks.com/CVE-2025-0111).
|
|
|
|
## PAN-273971
|
|
|
|
A fix was made to address [CVE-2025-0108](https://security.paloaltonetworks.com/CVE-2025-0108).
|
|
|
|
## PAN-273278
|
|
|
|
A fix was made to address [CVE-2025-0109](https://security.paloaltonetworks.com/CVE-2025-0109).
|
|
|
|
## PAN-273215
|
|
|
|
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
|
|
|
|
## PAN-273021
|
|
|
|
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
|
|
|
|
## PAN-271926
|
|
|
|
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.
|
|
|
|
## PAN-270549
|
|
|
|
Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane.
|
|
|
|
## PAN-269899
|
|
|
|
Fixed an issue where the Panorama web interface was slower than expected when querying for device tags.
|
|
|
|
## PAN-269731
|
|
|
|
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
|
|
|
|
## PAN-269624
|
|
|
|
Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.
|
|
|
|
## PAN-268972
|
|
|
|
Fixed an issue where Panorama was slower than expected when using a high number of device group tags in a non-shared context.
|
|
|
|
## PAN-268909
|
|
|
|
Fixed an issue where IP address tags were removed from firewalls after a management server or useridd process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution.
|
|
|
|
## PAN-268727
|
|
|
|
Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.
|
|
|
|
## PAN-268319
|
|
|
|
Fixed an issue where **Receive Time** and **Time Generated** were not visible as attributes in the **Filter Builder** for system logs and URL filtering logs.
|
|
|
|
## PAN-268260
|
|
|
|
Fixed an issue on hardware firewalls where, when SSL decryption was enabled and Client Hello messages spanned multiple TCP segments, some SSL decrypted sessions failed.
|
|
|
|
## PAN-267781
|
|
|
|
Fixed an issue where Panorama did not display the Source Dynamic Address Group.
|
|
|
|
## PAN-267671
|
|
|
|
Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting with an OOM condition due to a memory leak on the reportd process.
|
|
|
|
## PAN-267001
|
|
|
|
Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds.
|
|
|
|
## PAN-266312
|
|
|
|
Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
|
|
|
|
## PAN-265179
|
|
|
|
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
|
|
|
|
## PAN-261739
|
|
|
|
```caveat
|
|
VM-Series firewalls in Microsoft Azure environments only
|
|
```
|
|
|
|
Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.
|
|
|
|
## PAN-259002
|
|
|
|
Fixed an issue where frequent external dynamic list updates caused the configd process to restart.
|
|
|
|
## PAN-256051
|
|
|
|
Fixed an issue on the firewall where enabling flow basic caused the firewall to stop responding due to a masterd process restart.
|
|
|
|
## PAN-249597
|
|
|
|
Fixed an issue where the **Policy** page on the Panorama web interface was slower than expected when a device group had a large number of managed devices.
|
|
|
|
## PAN-246949
|
|
|
|
Fixed an issue where custom admin users were not able to click **OK** in the push scope selection window when device group or template were disabled under commit in the admin roles.
|
|
|
|
## PAN-240739
|
|
|
|
Fixed an issue where the ECMP FIB update on the dataplane didn't clear the pending change flag, which caused the next non-ECMP FIB update to miss the latest generation ID and age out after 5 minutes
|
|
|
|
## PAN-225213
|
|
|
|
Fixed an issue where **Push All Changes** displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
|
|
|
|
## PAN-215038
|
|
|
|
Fixed an issue where the output of the request logging-service-forwarding status CLI command did not display the correct information after successfully onboarding a firewall to Cloud Delivered Licensing (CDL).
|