PAN-OS 11.2.7-h20 Addressed Issues
Focus
Focus

PAN-OS 11.2.7-h20 Addressed Issues

Table of Contents

PAN-OS 11.2.7-h20 Addressed Issues

Lists the addressed issues in PAN-OS 11.2.7-h20.
The following table lists the addressed issues in PAN-OS 11.2.7-h20.
Issue ID
Description
Fixes were made to address the following CVEs:
PAN-330016
Fixed an issue where enabling App Acceleration resulted in connectivity disruption for GlobalProtect users and branches connected through ION devices, which prevented access to applications. With this fix, App Acceleration functions as expected without causing connectivity issues.
PAN-326734
Fixed an issue where a Security policy rule configured in the Shared device group on Panorama was not displayed in the web interface for a child device group, which caused a discrepancy between the displayed configuration and the actual deployed configuration on the associated device. With this fix, the user interface accurately reflects the deployed security policy rules.
PAN-326056
Fixed an issue where ACE applications did not match the correct Security policy rules when the service was not set to Application Default after an upgrade, which caused traffic to be incorrectly denied.
PAN-320324
Fixed an issue where incorrect source region information appeared in GlobalProtect logs, which occurred because the location service lookup did not consistently return region information for public IP addresses. With this fix, accurate source region information is consistently displayed.
PAN-319343
(Prisma Access Gateways only) Fixed an issue where the global management plane stopped responding, which caused SSH and HTML disconnections, HIP database lookup failures, and significantly slower SCM commits. This occurred when egress IP allow listing was enabled in SCM and changes were made to EDLs.
PAN-316721
Fixed an issue where multiple EDL fetches were queued and did not complete.
PAN-312870
Fixed an issue on Panorama where Apps Seen was not updated in Security policy rules even when the firewall correclty recorded the **Last App Seen* timestamp and Panorama received monitor logs.
PAN-309960
Fixed an issue where a memory leak related to the useridd process on the passive device led to an OOM condition.
PAN-308668
Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts.
PAN-307933
(Panorama appliances in Log Collector mode only) Fixed an issue where the log collectors became unstable for an extended period of time when receiving large amounts of traffic.
PAN-296184
Fixed an issue where the useridd process stopped responding during user-id-agent configuration when the SSL context was not properly initialized to NULL after being freed.
PAN-295095
Fixed an issue where, when you used a syslog forwarding profile with the CEF format, an additional string was appended to the end of the log message when viewing the log entry from the Universal Forwarder directory.
PAN-291984
Fixed an issue where SSH/SFTP traffic was intermittently blocked by URL filtering due to the firewall incorrectly applying URL categories from previous sessions.
PAN-289652
Fixed an issue related to external URL lists where pushing configuration changes from Panorama failed.
PAN-285862
Fixed an issue where repeated unexpected terminations of a system component would cause the Data Plane to restart. With this fix, the Data Plane maintained stability.