R82 Jumbo Hotfix Take 36
Jumbo Hotfix Accumulator for R82
R82 Jumbo Hotfix Take 36
| Download Jumbo Hotfix Accumulator Takes | Download Previous Recommended Takes |
| Note - This Take contains all fixes from all earlier Takes. |
Download CSV
| ID | Product | Description |
|---|---|---|
| Take 36 Released on 31 July 2025 |
||
| Take 36 - New Functionality | ||
| PRJ-60966, PMTR-90911 |
Security Management | NEW: In SmartConsole, the CSV export file of Access Control Policy NAT rules now contains the hit count data: "Hits", "First Hits" and "Last Hits" columns. - Requires R82 SmartConsole Build 1056 or higher. |
| PRJ-60497, PMTR-114492 |
Security Management | NEW: Added statistics for Top Matched Access Control Rules and Top Log Types in the Logs view of SmartConsole and in the response of the " show logs" Management API command. This allows to identify the rules that generate a high volume of logs. |
| PRJ-62732, SMBGWY-12611 |
Security Management | NEW: Added support for the Quantum Spark 2500 appliances (2530, 2550, 2560, 2570, and 2580) in the EA (Early Availability) program. - Requires R82 SmartConsole Build 1057 or higher. |
| Take 36 - Improvements and Resolved Issues | ||
| PRJ-60718, PMTR-114504 |
Logging | UPDATE: Resolved CVE-2025-2028. Lack of TLS validation when downloading a visualization support data file. Refer to sk183349. |
| PRJ-59425, PMTR-112077 |
Mobile Access | UPDATE: Resolved CVE-2024-52885. Mobile Access File Share applications are vulnerable to directory traversal attacks. Refer to sk183137. |
| PRJ-59537, MGMTPROD-1385 |
Security Management | UPDATE: In SmartConsole and Management API, Access and NAT Policies now support Rule Base search for hitcount values. |
| PRJ-62283, PMTR-114192 |
Security Management | UPDATE: Updated the " show asset" command output with the correct details for the X7 4-port card (CPAC-4-10/25F-DA model). |
| PRJ-61388, PRHF-39859 |
Security Management | UPDATE: On Security Management Servers, environment variables set using the override_server_setting.sh script now apply to all processes. Refer to sk165938. |
| PRJ-60245, PMTR-110297 |
Logging | UPDATE: Log Exporter is now delivered as an autoupdatable package, replacing the maintrain-based deployment. This approach shifts from version-based to component-level updates, enabling a more granular and agile update mechanism. Refer to sk182866. |
| PRJ-60790 | Logging | UPDATE: In SmartConsole > Logs & Monitor > Logs, added information to the "Per Session" logs: - NAT fields - Dynamic object name - Updatable object name - Network feed object name - Destination Domain Name field |
| PRJ-59881, PRHF-38023 |
Security Gateway | UPDATE: Improved processing of ICMP packets in the Security Gateway. |
| PRJ-61680 | Security Gateway | UPDATE: Quantum Force 9400 and 9300 appliances with Standalone configuration now run in User Space Firewall (USFW) Mode by default. |
| PRJ-60047, PMTR-110330 |
Security Gateway | UPDATE: Added an out-of-the-box package for updatable objects that is included with clean installations or Jumbo Accumulator Hotfix Takes (when no other package exists). If the out-of-the-box package is present during policy installation, an update is now initiated in addition to the automatic update. |
| PRJ-61470, PMTR-116355 |
VPN | UPDATE: Added the "inclusions" feature to the Split Tunnel Remote Access functionality. Refer to the R82 Remote Access VPN Admin Guide > Dynamic Split Tunneling for SaaS Using Updatable Objects. |
| PRJ-61795, PRHF-40060 |
Scalable Platforms | UPDATE: The " fwha_allow_different_corexl_instances" kernel parameter is now added to prevent cluster members from entering a Down state because of firewall instance count mismatches. |
| PRJ-60352, PMTR-114300 |
Diagnostics | An FD (file descriptor) memory leak may occur when creating a new object in SmartConsole. |
| PRJ-60500, PMTR-114274 |
Security Management | VPN certificate renewal may generate certificates with 2K key sizes instead of the 3K size specified in Global Properties. |
| PRJ-61469, PRHF-109056 |
Security Management | The " Management rejected fetch for this module - version matching problem" error is displayed when running the " fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to sk183298. |
| PRJ-61359, PRHF-39806 |
Security Management | In some scenarios, a cluster object may not be listed in the "Uninstall Threat Prevention Policy" window. |
| PRJ-61318, PRHF-39827 |
Security Management | Fetching branches from an LDAP Server fails with " Failed to connect to LDAP Server. Please ensure that the administrator's credentials are correct and try again" when the LDAP Server does not support anonymous bind (when a client connects to an LDAP server without providing any credentials). To enable the ability, refer to sk183461. |
| PRJ-61477, PRHF-40016 |
Security Management | In rare scenarios, the CPRLIC process may exit with core files generated to the /var/log/dump/usermode/ directory on the Security Management Server. |
| PRJ-60470, PRHF-38859 |
Security Management | Deleting a user that is used in a user group with more than 1000 users may cause SmartConsole to time out. |
| PRJ-60433, PRHF-38563 |
Security Management | Virtual System routes and interfaces may not be synchronized to the Standby Security Management Servers. |
| PRJ-59100, PRHF-33411 |
Security Management | In some scenarios, when exporting the Gateways and Servers View to CSV, the resulting file may contain an extra empty column. Refer to sk182233. |
| PRJ-60961, PRHF-38808 |
Security Management | In rare scenarios, in multi-site Multi-Domain Security Management environments, operations across two or more Servers, such as Global Domain Assignment, IPS and Application Control update may fail. |
| PRJ-58352, PRHF-37197 |
Security Management | In some scenarios, policy installation fails with the " _/opt/ |
| PRJ-60699, PRHF-39297 |
Security Management | The Management API command " _set simple-gateway name 'XXX' usercheck-portal-settings.enabled {false |
| PRJ-61043, PRHF-39465 |
Security Management | In rare scenarios, accelerated policy installation fails to initialize, the full Access Control Policy installation is executed instead and it may take up to 20 minutes. |
| PRJ-56522, PRHF-35230 |
Security Management | In rare scenarios, the first packet of a connection is incorrectly dropped when a non-FQDN object is used in the Rule Base. |
| PRJ-58202, PRHF-34401 |
Security Management | The " vsx-run-operation" Management API command may fail on the Multi-Domain Security Management Server. Refer to sk182524. |
| PRJ-60762, PRHF-39098 |
Security Management | In rare scenarios, after deleting Data Center objects: - Login to the Security Management Server may fail with timeout. - Publish operations may take a long time. |
| PRJ-57975, PRHF-36695 |
Security Management | In some scenarios, the Postgres database on the Standby Security Management Server is growing after every High Availability synchronization. Refer to sk182868. |
| PRJ-61585, PRHF-37905 |
Security Management | Access Control policy installation may take a long time when updatable objects are used in the policy. |
| PRJ-59370, PMTR-110008 |
Security Management | The " show lsm-gateway" and "show lsm-gateways" Management API commands may return an empty "version" field. |
| PRJ-60013, PMTR-114030 |
Security Management | In rare scenarios, policy installation may get stuck at 99%. |
| PRJ-59625, PRHF-38414 |
Multi-Domain Security Management | In rare scenarios, Domain creation fails with " Failed to create Domain server ' |
| PRJ-60660, PMTR-114305 |
SmartProvisioning | In SmartProvisioning application: - Performing "push policy" on a Gaia LSM Cluster fails with the " local failure of CPRID" error. - The "Get Gateway Data" operation fails with " Execution error Error: Unspecified error". - The " cphaprob stat" command returns a core dump file. |
| PRJ-61987, PMTR-116260 |
CPView | CPView history may be corrupted. |
| PRJ-61489, PRHF-39983 |
Security Gateway | In a rare scenario, the FWK process may restart unexpectedly. |
| PRJ-60129, PRHF-38666 |
Security Gateway | When the Mirror and Decrypt feature is enabled, the SKB memory leak may occur. |
| PRJ-60126, PRHF-38574 |
Security Gateway | When Mirror and Decrypt features are enabled, the Security Gateway may experience unexpected reboots. The crashes are caused by " put_cred_rcu()" errors with negative usage values and memory leaks in the ARP cache. |
| PRJ-60949, PRHF-39471 |
Security Gateway | In a rare scenario, the CPD daemon may exit on the Security Gateway. |
| PRJ-61309, PMTR-115595, HEC-371 |
Security Gateway | ElasticXL members communicating with the pivot cluster member may transition to DOWN state when synchronization between the pivot and other members is lost. Refer to sk183434. |
| PRJ-60579, PRHF-38995 |
Security Gateway | In rare cases, failovers may occur because the FWK process unexpectedly exits. |
| PRJ-59157, PRHF-37774 |
Security Gateway | Security Gateways with default MDPS task settings using proxy can fetch CPUSE updates and licenses successfully. On MPLANE updatable objects are not updated while everything works on DPLANE. |
| PRJ-61449, PRHF-39840 |
Security Gateway | When handling interface statistics, the CPD or FWK processes may unexpectedly restart with an error related to IOCTL printed in logs. Refer to sk183544. |
| PRJ-60455, PMTR-114419 |
Security Gateway | Enabling debugging in Quick UDP Internet Connections (QUIC) flows may cause an FWK process crash. |
| PRJ-62174, PRJ-59649 |
Security Gateway | In rare scenarios, the FWK process may unexpectedly exit when stopping the Security Gateway using the " cpstop" command while a packet capture tool is running. |
| PRJ-60669, PMTR-114653 |
Security Gateway | In rare scenarios, downloading large files over HTTPS may get stuck. |
| PRJ-60427, PMTR-114342 |
Security Gateway | In rare scenarios, the FWK process may unexpectedly exit when the IPS Software Blade logs triggered protections. |
| PRJ-60539, PRHF-38647 |
Security Gateway | In a rare scenario, after an upgrade, the Security Gateway may crash with a vmcore. |
| PRJ-59895, PRHF-38438 |
Security Gateway | The VSX Security Gateway may crash when an external interface connected to the Virtual Router or Virtual Switch starts flapping. |
| PRJ-60446, PRHF-38975 |
Security Gateway | RADIUS authentication fails when a response packet contains the Message-Authenticator attribute. Refer to sk183244. |
| PRJ-60216, PRHF-34528 |
Threat Prevention | In some scenarios, external IoC feeds are not correctly fetched in VSX environments after a reboot. |
| PRJ-57978, PRHF-36739 |
Threat Extraction | In a rare scenario, a script related to CPView may take a long time to execute and the SCRUBD process becomes unresponsive. |
| PRJ-58005, PRHF-36322 |
Anti-Virus | In rare scenarios, Security Gateways with the Content Awareness Software Blade enabled may fail to properly process certain .zip file formats, resulting in " Failed to process files" errors during the Anti-Virus inspection. |
| PRJ-59857, PRHF-38565 |
Anti-Virus | In some failure scenarios, the Anti-Virus Software Blade does not report the failure in a SmartConsole log. |
| PRJ-60663, PMTR-114734 |
Anti-Bot | In rare scenarios, the RAD process may unexpectedly exit. |
| PRJ-60616, PRHF-39184 |
Mobile Access | The Mobile Access Portal hosted on a Security Gateway R81.20 or lower becomes unresponsive, and CVPND core files are generated after the Security Management Server is upgraded to version R82. |
| PRJ-60700, PMTR-108872 |
SSL Inspection | The "HTTPS Inspection Statistics" view in Demo Mode of SmartView in SmartConsole shows " No data found". The issue is cosmetic only. |
| PRJ-59766, PRHF-38539 |
ClusterXL | If both bond subordinate interfaces are down, the output of " cphaprob show_bond bond" command is corrupted. |
| PRJ-60780, PMTR-110618 |
ClusterXL | The ROUTED daemon may incorrectly initialize as Subordinate rather than Master after a " cpstop;cpstart" command when executed on the sole Active member in a cluster configuration. |
| PRJ-58336, PRHF-36801 |
ClusterXL | A Multi-Version Cluster (MVC) member with VPN enabled may crash when performing an upgrade from R80.40. |
| PRJ-59213, HEC-1195 |
ClusterXL | In High Availability Bridge Mode ClusterXL environments, the management interface of a Standby member becomes inaccessible. Refer to sk183124. |
| PRJ-57369, PRHF-36165 |
ClusterXL | In VSX environments, deleting a Virtual System interface through SmartConsole fails to remove certain bindings, causing the interface to be automatically re-added. |
| PRJ-60378, PMTR-114234 |
SecureXL | When printing the Deny list on a Security Gateway during Threat Prevention policy installation after deleting a large IoC feed from Security Management, an uninformative IOCTL error is displayed instead of a proper error message. The issue is cosmetic only. |
| PRJ-61467, PMTR-111760 |
SecureXL | The USIM process to exit during error logging. |
| PRJ-60592, PMTR-113834 |
SecureXL | In a rare scenario, no traffic is passed in the 6in4 tunnel and the two hosts cannot reach each other. The output for the " tcpdump" command in the tunnel shows " ip: unknown ip 0". |
| PRJ-61966, PRJ-61915 |
SecureXL | The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active. |
| PRJ-61021, PMTR-115089 |
SecureXL | In rare scenarios, when SecureXL works in User Mode, running the " reset_gw" or " vsx_util reconfigure" commands may cause the Security Gateway to crash. |
| PRJ-59503, PRHF-38095 |
ClusterXL | In rare scenarios, after enabling Bridge Mode, a cluster member may stuck in a boot loop. |
| PRJ-61182, PRHF-39695 |
SecureXL | Multicast traffic is dropped when the Packet-Broker operates in Monitor Mode with Promiscuous Mode disabled. |
| PRJ-60722, PMTR-114790 |
SecureXL | The Security Gateway may crash when connected to the Smart-1 Cloud Management Server and a maas_tunnel interface is repeatedly added and deleted. |
| PRJ-60999, PMTR-115074 |
SecureXL | After MTU for Jumbo Frames is configured on a physical interface for the first time, until the Security Gateway is rebooted, there may be potential packet drops. |
| PRJ-59988, PRHF-38501 |
Gaia OS | Multiple SNMP OIDs return incorrect data types. Refer to sk183166. |
| PRJ-62065, PRHF-40577 |
Gaia OS | Stability issue on Quantum Force appliances 9300 and 9400. Refer to sk183438. |
| PRJ-58413, PRHF-37416 |
Gaia OS | Exporting logs using the " backup -l" command may fail. |
| PRJ-58040, PRHF-36803 |
Gaia OS | SNMP OID .1.3.6.1.4.1.2620.1.6.7.5.1.5.X falsely reports high CPU due to malformed calculation. Refer to sk182784. |
| PRJ-59922, PRHF-38669 |
Gaia OS | In rare scenarios, users may be disconnected from SmartConsole, and an FWM process core dump is generated. |
| PRJ-60162, PRHF-38736 |
Routing | The ROUTED daemon core dump file may be generated because of an assertion failure in the OSPF code. |
| PRJ-61331, PMTR-115613 |
Routing | When working in User Mode (UPPAK), SecureXL may crash when multiple SND cores perform simultaneous next hop lookup for the same next hop. |
| PRJ-60813, PMTR-114871 |
Routing | In a rare scenario, a Security Gateway crash and temporary loss of routing adjacency occur when the cluster messaging system attempts to process a deletion request for a BFD session that no longer exists. |
| PRJ-59742, PRHF-37444 |
Routing | The ROUTED daemon may exit when processing OSPF network updates in a cluster environment. This occurs because of a timing issue in the routing protocol synchronization process. |
| PRJ-61214, PMTR-115308 |
Routing | If BFD (Bidirectional Forwarding Detection) timing parameters, such as "min-rx-interval", are modified during an active BFD session deletion process, and a new BFD session is established before the deletion fully completes (deletion typically requires up to 2 hours), the newly created session inherits the previous timing configuration rather than applying the updated timing settings. |
| PRJ-60776, PMTR-114870 |
Routing | In some scenarios, the ROUTED daemon may exit with a core dump file. |
| PRJ-60745, PMTR-114835 |
Routing | In some scenarios, BGP routing updates may not be processed properly. |
| PRJ-62111, PRHF-40540 |
Routing | A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps. |
| PRJ-58688, PMTR-110631 |
Gaia OS | NFS mount does not support hyphen "-". |
| PRJ-59137, PMTR-110490 |
Gaia OS | When deleting a bond interface with slaves still attached while maintaining both Gaia Portal and SSH sessions, the deletion succeeds but generates " unregister_netdevice" syslog messages and terminates the Gaia Portal session. The issue occurs because local connections to the Gateway cause slow bond interface deletion, leading to Gaia Portal timeout. |
| PRJ-57175, PRHF-36109 |
Gaia OS | In rare scenarios, when using IP Aliasing, deleting an interface by IP address reference may incorrectly delete the wrong IP address because of incorrect error handling. |
| PRJ-61371, PMTR-115542 |
VPN | In rare scenarios, VPN traffic connectivity may be lost during policy installation. |
| PRJ-58955, PMTR-111093 |
VPN | VPN connection may be unstable because of packet fragmentation issues. |
| PRJ-61225, PRHF-39785 |
VPN | In a rare scenario, the FWK process may exit during VPN traffic decryption and routing when the PPPoE interface is enabled. |
| PRJ-58320, PRHF-37066 |
VSX | Virtual Router advanced routes may be assigned incorrect priorities in policy-based routing configurations. |
| PRJ-58334, PRHF-37228 |
VSX | The " fw stat" command output may not display the correct policy name for a Virtual System. |
| PRJ-58791, PRJ-37719 |
VSX | The " vsx_util view_vs_conf" command output may show " N/A" for a Gateway when an object in the Domain shares the same name as the Virtual System object. |
| PRJ-57350, PRHF-36278 |
VSX | A static route to 0.0.0.0, regardless of the subnet mask, is incorrectly treated as the default route (0.0.0.0/0) and does not appear in the VSX Gateway's routing table. Refer to sk182742. |
| PRJ-59033, PMTR-111124, HEC-953 |
VSNext | In a large scale VSNext environment, creating over 50 Virtual Systems (VSs) fails. |
| PRJ-60961, PMTR-115016 |
SD-WAN | SD-WAN fails to obtain next hop address automatically from the DHCP Server. |
| PRJ-59427, PRHF-38271 |
SD-WAN | SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway. |
| PRJ-60748, PMTR-114442 |
SD-WAN | In rare scenarios, SD-WAN policy installation hangs indefinitely. |
| PRJ-58304, PRHF-37070 |
Scalable Platforms | In a Maestro environment, migrating a Virtual System between Security Groups may cause a member to crash. |
| PRJ-56586, PRHF-35421 |
Scalable Platforms | Connections with fragmented packets drop with the " Virt Defrag Timeout" error. Refer to sk182559. |
| PRJ-60448, HEC-914 |
Scalable Platforms | After a reboot, IPv6 addresses configured on data interfaces disappear from the " ifconfig" output when the Same VMAC feature is enabled in SmartConsole. |
| PRJ-59499, FMW-3594 |
Scalable Platforms | In rare scenarios, the connection between the Security Gateway (acting as a proxy) and the Security Management Server is not closed correctly. |
| PRJ-60672, PRHF-38834 |
Scalable Platforms | Running " cpstop" on a specific Virtual System may cause traffic interruption in dual site deployments. |
| PRJ-61502, PRHF-39967 |
Scalable Platforms | A cluster member may crash when performing a manual site failover and the deployment is using "Interface Active Check" with IPv6 enabled. |
| PRJ-60052, PRHF-38689 |
Scalable Platforms | One member in a Maestro Security Group may be reported as down and inaccessible, the /var/log/messages and fwk.elg logs indicate: - " _State change: ACTIVE -> DOWN |