PAN-OS 10.2.13-h3 Addressed Issues
Focus
Focus

PAN-OS 10.2.13-h3 Addressed Issues

Table of Contents

PAN-OS 10.2.13-h3 Addressed Issues

Addressed issues for the PAN-OS 10.2.13-h3 general available hotfix release.
Issue ID
Description
PAN-274570
Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access.
PAN-273994
A fix was made to address CVE-2025-0111.
PAN-273971
A fix was made to address CVE-2025-0108.
PAN-273278
A fix was made to address CVE-2025-0109.
PAN-273215
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
PAN-273021
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
PAN-271926
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.
PAN-270549
Fixed an issue where early TLS data was not handled correctly by the accumulation proxy.
PAN-269899
Fixed an issue where the Panorama web interface was slower than expected when querying for device tags.
PAN-269731
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
PAN-269624
Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.
PAN-268972
Fixed an issue where Panorama was slower than expected when using a high number of device group tags in a non-shared context.
PAN-268909
Fixed an issue where IP address tags were removed from firewalls after a management server or useridd process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution.
PAN-268727
Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.
PAN-268319
Fixed an issue where Receive Time and Time Generated were not visible as attributes in the Filter Builder for system logs and URL filtering logs.
PAN-268260
Fixed an issue on hardware firewalls where, when SSL decryption was enabled and Client Hello messages spanned multiple TCP segments, some SSL decrypted sessions failed.
PAN-267781
Fixed an issue where Panorama did not display the Source Dynamic Address Group.
PAN-267671
Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting with an OOM condition due to a memory leak on the reportd process.
PAN-267001
Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds.
PAN-266312
Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
PAN-265179
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
PAN-261739
(VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.
PAN-259002
Fixed an issue where frequent external dynamic list updates caused the configd process to restart.
PAN-256051
Fixed an issue on the firewall where enabling flow basic caused the firewall to stop responding due to a masterd process restart.
PAN-249597
Fixed an issue where the Policy page on the Panorama web interface was slower than expected when a device group had a large number of managed devices.
PAN-246949
Fixed an issue where custom admin users were not able to click OK in the push scope selection window when device group or template were disabled under commit in the admin roles.
PAN-240739
Fixed an issue where the ECMP FIB update on the dataplane didn't clear the pending change flag, which caused the next non-ECMP FIB update to miss the latest generation ID and age out after 5 minutes
PAN-225213
Fixed an issue where Push All Changes displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
PAN-215038
Fixed an issue where the output of the request logging-service-forwarding status CLI command did not display the correct information after successfully onboarding a firewall to Cloud Delivered Licensing (CDL).