Loading...
Loading...
Hotfix versions were inferred because the vendor did not list them explicitly: 11.1.6-h1, 11.1.6-h2, 11.1.6-h3, 11.1.6-h4, 11.1.6-h5, 11.1.6-h6, 11.1.6-h7, 11.1.6-h8, 11.1.6-h9, 11.1.6-h10, 11.1.6-h11, 11.1.6-h12, 11.1.6-h13, 11.1.6-h14, 11.1.6-h15, 11.1.6-h16, 11.1.6-h17, 11.1.6-h18, 11.1.10-h1, 11.1.10-h2, 11.1.10-h3, 11.1.10-h4, 11.1.10-h6, 11.2.4-h1, 11.2.4-h2, 11.2.4-h3, 11.2.4-h4, 11.2.4-h5, 11.2.4-h6, 11.2.4-h7, 11.2.4-h8, 11.2.4-h9, 11.2.4-h10, 11.2.4-h11, 11.2.7-h1, 11.2.7-h2, 11.2.7-h3
The earliest recollection of this bug is traced back to PAN-OS 11.1.10-h5 - July 08, 2026. This bug is fixed in PAN-OS versions 11.1.6-h19, 11.1.10-h5, 11.2.4-h12, 11.1.10-h7, 11.2.10, 11.1.12, 11.2.7-h4. Fixed an issue where IPv6 traffic was affected after upgrading the firewall.With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall. Fixed an issue where IPv6 traffic was affected after upgrading the firewall. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall. Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall. For more information: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h5-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h7-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-12-known-and-addressed-issues/pan-os-11-1-12-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-6-known-and-addressed-issues/pan-os-11-1-6-h19-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-10-known-and-addressed-issues/pan-os-11-2-10-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-4-known-and-addressed-issues/pan-os-11-2-4-h12-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-7-known-and-addressed-issues/pan-os-11-2-7-h4-addressed-issues
Click on a version to see all relevant bugs
Palo Alto Networks Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.