PAN-OS 11.1.13-h5 Addressed Issues
Focus
Focus

PAN-OS 11.1.13-h5 Addressed Issues

Table of Contents

PAN-OS 11.1.13-h5 Addressed Issues

Lists the addressed issues in PAN-OS 11.1.13-h5.
After upgrading to this release, all GlobalProtect users will be required to reauthenticate.
Issue ID
Description
Fixes were made to address the following CVEs:
PAN-323243
Fixed an issue where a configd crash occurred when the Policies > Security view was updated or refreshed in the web interface.
PAN-318567
Fixed an issue where the OpenConfig plugin stopped working after a configuration update.
PAN-317583
Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.
PAN-317466
Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field.
PAN-317215
(VM-Series firewalls on ESXi with Intel E810 NICs using PCI passthrough) Fixed an issue where the brdagent process became unresponsive during data port initialization, which resulted in system instability, interface outages, HA split-brain conditions, and unexpected reboots during failover.
PAN-317177
Fixed an issue on firewalls in DHCP Client mode where, after upgrading to an affected release, the SNMP process unexpectedly restarted after a commit, which led to false interface flap notifications on SNMP managers.
PAN-317155
Fixed an issue where the link status of log port 1 and log port 2 were unable to be monitored via SNMP due to the OIDs for the individual ports not being available.
PAN-316631
Fixed an issue BGP sessions experienced short disruptions across all peers, interfaces, and slots when a multicast event persisted longer than the NGP negotiated hold timers.
PAN-315958
(PA-1410 firewalls only) Fixed an issue where the SaaS Quality Profile HTTP/HTTPS monitoring feature failed to send probes due to the firewall being unable to determine the correct egress interface and source IP address for the monitoring probes.
PAN-315912
Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.
PAN-314875
(PA-7500 firewalls only) Fixed an issue where firewall logs were not visible in the Strata Logging Service even though cloud logging was enabled and the firewall was successfully forwarding logs.
PAN-314712
(PA-7500 Series firewalls only) Fixed an issue where the source IP Dynamic Address Group mappings were intermittently not displayed under Monitor > Traffic logs. This occurred even when dynamic address groups were updated via XML API without an expiry time and no unregister requests were observed.
PAN-314435
Fixed an issue on the Panorama web interface where custom application tags for cloud applications were not consistently displayed in the Application Filter or application details even though the tags were configured via CLI and successfully enforced traffic blocking policy rules.
PAN-314147
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.
PAN-314126
Fixed an issue where session rematch did not properly apply updated Security policy rules to existing traffic flows after committing changes, which caused traffic to still be allowed when a new Security policy was set to Deny.
PAN-313193
(Firewalls in Layer 2 mode only) Fixed an issue where the new sessions were not able to be established due to the firewall intermittently dropping valid MAC address entries for specific VLANs when a manual switchover sent a high volume of traffic to the firewall.
PAN-311248
Fixed an issue where the ABR failed to translate and advertise the default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF backbone area as a Type-5 LSA.
PAN-311166
Fixed an issue where the firewall rebooted unexpectedly to the all_task_1 process repeatedly restarting.
PAN-310851
Fixed an issue where firewalls experienced snmpd log flooding with messages such as update_ifTable_utilization_rates(pan_interfacecache.c:1720): Last time is 0 for dedicated-ha2., which caused the snmpd log to overflow and be cleared every five minutes. This occurred because the snmpd process attempted to calculate interface utilization rates without first verifying if the interface had valid sysd configuration data, as the code incorrectly assumed all interfaces in the MIB would possess valid sysd data.
PAN-310499
Fixed an issue on Panorama where, while configuring an an Application Filter with Generative AI tags, the web interface did not retain application exclusions that were added across multiple pages until you clicked OK.
PAN-310472
Fixed an issue on the web interface where checkboxes for default information originate and ABR in OSPF NSSA configurations were automatically enabled which resulted in unexpected configuration changes.
PAN-310402
Fixed an issue where SNMP returned an incorrect down status for HSCI and logging interfaces even when the interfaces were up, and counters for the interfaces displayed only zero values.
PAN-309927
Fixed an issue on Panorama where the multi-clone XML API operation reported a successful configuration change even when the specific device group did not exist.
PAN-309306
Fixed a rare issue on Octeon Dataplane platforms where the firewall experienced an unexpected dataplane restart due to a race condition that occurred during session teardown for traffic undergoing software-based Content Threat detection.
PAN-308564
Fixed an issue where packets were dropped on SD-WAN interfaces when a proxy was enabled due to an MTU inconsistency where the firewall failed to rewrite the maximum segment size in SYN/ACK packets based on the SD-WAN virtual interface MTU.
Note: This fix does not apply when the traffic egress interface is SD-WAN Direct Internet Access (DIA) interface and proxy is enabled.
PAN-308377
(PA-7050 firewalls in HA configurations only) Fixed an issue where the firewall reached 100% disk utilization due to the logrcvr process repeatedly restarting and dumping core files due to a blocked hints processing thread, which caused a failover.
PAN-307714
(VM-Series firewalls only) Fixed an issue where insufficient i-node space was available on the sysroot0 partition.
PAN-305188
Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the Client Hello was split into multiple segments and arrived out of order.
PAN-303826
Fixed an issue where scheduled software upgrades from the Software Change Management (SCM) server to the firewall failed with a timeout error during download.
PAN-303663
Fixed an issue on the firewall where SolarWinds monitoring systems reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers due to an inaccurate reported packet buffer.
PAN-302703
(Panorama virtual appliances only) Fixed an issue where Panorama was inaccessible with the error message Timed out while getting config lock.
PAN-302387
Fixed an issue where on PA-7500 firewalls, SNMP incorrectly reported the administrative and operational status of High Speed Chassis Interconnect (HSCI) interfaces as down, even when the interfaces were physically up. Additionally, interface counters for these interfaces displayed all zeroes.
PAN-295728
Fixed an issue where configuring an OSPFv2 NSSA area range caused OSPF-learned routes to become unreachable due to the incorrect installation of a discard route when the NSSA range prefix matched an existing OSPF route.
PAN-295309
Fixed an issue where OSPF session using MD5 authentication experienced intermittent flapping due to out-of-order packet processing.
PAN-294998
Fixed an issue where the LogDB incorrectly reported that the database quota for extpcap logs was reached.
PAN-294434
Fixed an issue where memory leaks occurred. These leaks were caused by two distinct scenarios: the failure to deallocate memory for a nodeset when a new nodeset was assigned to the same variable, and the failure to free a UUID hash table during error conditions.
PAN-293644
(Firewalls in HA configurations only) Fixed an issue where the configd process stopped responding during an External Dynamic List (EDL) refresh.
PAN-285181
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF. To use this fix, run the CLI command debug iot eal memory-gc native.
PAN-277629
Fixed an issue where the firewall did not match the correct policy for SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS 10.2.9-h1 to PAN-OS 11.2.3.
PAN-271643
Fixed an issue where, when a commit job ID was higher than 65535, the XML API truncated the ID to a 16-bit unsigned integer due to an incorrect type case during printing, which resulted in an incorrect job ID being reported compared to the CLI output for the same commit.
PAN-264762
Fixed an issue where the firewall showed the status of SFP+ interfaces as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was connected.
PAN-264349
Fixed an issue where the Management Processor Card (MPC) on modular firewalls became unresponsive when a disk drive entered a low-power state and failed to wake up.
PAN-248913
Fixed an issue where the Elasticsearch client certificate was not auto renewed, which caused it to enter a Red state, and logs were not displayed in Panorama.
PAN-242952
Fixed an issue where high SSL traffic depleted flex memory, which prevented the firewall from revalidating SSLVPN client CAs during configuration pushes.
PAN-241467
(Cloud NGFWs in Microsoft Azure environments only) Fixed an issue where, on Panorama management servers, firewalls connected through a public IP address did not automatically receive content updates. This occurred when the Panorama server had the latest content downloaded but the content information was not updated in the contentinfo.xml file.