Administrators using Palo Alto Networks firewalls running PAN-OS versions 11.1.4-h7 and 11.1.4-h9 are reporting widespread issues of unexpected reboots.
The reboots appear to originate from a bug in the affected PAN-OS versions, with reports indicating that the problem is linked to specific network traffic patterns and SSL interception processes.
Logs from affected devices often show errors such as:
This suggests that the issue may involve memory leaks or mismanagement of packet queues, particularly when SSL interception is enabled.
The ctd_pkt_queue misinterpreting a full state has been identified as a possible trigger for these crashes
The frustration among users is observable. Many have criticized Palo Alto Networks for the delayed response, as a fix is only expected by March 2025, leaving organizations vulnerable in the interim.
One user remarked, “This feels like a joke,” reflecting the sentiment that such a critical issue warrants a more immediate resolution.
Some administrators have shared temporary measures to mitigate the issue:
Palo Alto Networks has acknowledged the issue and released a limited hotfix (PAN-OS 11.1.4-h12) on January 31, 2025, for customers requiring immediate resolution.
However, this hotfix is not yet widely available and must be requested through account teams.
A broader release is expected by the end of February or early March. Additionally, future updates addressing this issue include versions 11.1.6-h1, 11.1.7, and beyond.
While Palo Alto Networks works on a comprehensive fix, administrators must navigate this period with vigilance and temporary workarounds to ensure minimal disruption to their operations.
PCI DSS 4.0 & Supply Chain Attack Prevention – Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…