Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.4(2)11 – 02/23/2016

Files:  asa942-11-smp-k8.bin

Defects resolved since 9.4(2)6:

 

CSCux45179

SSL sessions stop processing -"Unable to create session directory" error

CSCux61257

ASA: Traceback in Thread IP Address Assign

CSCux85725

ASA WebVPN: Java RDP Plugin does not launch

CSCuy03024

ASA Crashes and reloads citing Thread Name: idfw_proc

CSCuy28710

ARP source IP sanity check against proxy-arp list

CSCuy32321

Traceback in ldap_client_thread with ldap attr mapping and pw-mgmt

CSCuy41986

OCSP validation fails when multiple certs in chain are verified

 

 

Revision:  Version 9.4(2)6 – 01/28/2016

Files:  asa942-6-smp-k8.bin

Defects resolved since 9.4(2)4:

 

CSCuo08193

Traceback in Thread Name: DATAPATH-1-1382 while processing nat-t packet

CSCur87011

ASA low DMA memory on low end ASA-X -5512/5515 devices

CSCus10787

Transactional ACL commit will bypass security policy during compilation

CSCus16416

Share licenses are not activated on failover pair after power cycle

CSCus53126

ASA traffic not sent properly using 'traffic-forward sfr monitor-only'

CSCut40770

Interface TLV to SFR is corrupt when frame is longer than 2048 bytes

CSCuu48197

ASA: Stuck uauth entry rejects AnyConnect user connections

CSCuv49446

ASA traceback on Standby device during config sync in thread DATAPATH

CSCuw02009

ASA - SSH sessions stuck in CLOSE_WAIT causing ASA to send RST

CSCuw19671

ASA traceback while restoring backup configuration from ASDM

CSCuw22130

ASA traceback when removing dynamic PAT statement from cluster

CSCuw39685

filter sfr traffic may cause  memory corruption

CSCuw44038

9.1.6.8 traceback in Thread Name: ldap_client_thread

CSCuw87910

PCP 10.6 Clientless VPN Access is Denied when accessing Pages

CSCux04374

ASA: Failover logging message appears in user context

CSCux05081

RSA 4096 key generation causes failover

CSCux07002

ASA: assertion "pp->pd == pd" failed: file "main.c", line 192

CSCux09181

http-form authentication fails after 9.3.2

CSCux09310

ASA traceback when using an ECDSA certificate

CSCux16427

PBR incorrect route selection for deny clause

CSCux20178

OSPF neighbor goes down after "reload in xx" commnad in 9.2 and later

CSCux23659

ASA 9.1.6.10 traceback after remove compact flash and execute dir cmd

CSCux26443

DAP URL-List Command Says It Supports 491 Characters; Only Supports 245

CSCux35272

ASA TCP normalizer checksum verification cannot be disabled

CSCux37442

Cisco signed certificate expired for WebVpn Port Forward Binary on ASA

CSCux42936

ASA 9.5.1 traceback in Threadname Datapath due to SIP Inspection

CSCux43978

DHCP Relay fails for cluster ASAs with long interface names

CSCux47195

ASA(9.5.2) changing the ACK number sent to client with SFR redirection

CSCux56111

"no ipv6-vpn-addr-assign" CLI not working

CSCux59122

ASA L7 policy-map comes into affect only if the inspection is re-applied

 

 

Revision:  Version 9.4(2)4 – 01/14/2016

Files:  asa942-4-smp-k8.bin

Defects resolved since 9.4(2)3:

 

CSCux29978

ASA IKEv1 and IKEv2 Vulnerability

 

CSCux42019

IKEv2 Fragments may get dropped with a specific sequence of fragments

 

 

Revision:  Version 9.4(2)3 – 11/09/2015

Files:  asa942-3-smp-k8.bin

Defects resolved since 9.4(2):

 

CSCtx43501

CPU hog due to snmp polling of ASA memory pool information

CSCut71095

ASA WebVPN clientless cookie authentication bypass

CSCuu02848

Disable ECDSA SSL Ciphers When Manually Configuring RSA Cert for SSL

CSCuu82229

ikev2 with DH 19 and above fails to pass traffic after phase2 rekey

CSCuu88412

When > 510 characters entered in CLI, context switches to admin/system

CSCuu91304

Immediate FIN from client after GET breaks scansafe connection

CSCuv50709

Standby ASA inside IP not reachable after Anyconnect disconnect

CSCuv58559

Traceback in Thread Name: DATAPATH on modifying "set connection" in MPF

CSCuv66333

ASA picks incorrect trustpoint to verify OCSP Response

CSCuv87150

ASA traceback in Thread Name: fover_parse (ak47/ramfs)

CSCuv92371

ASA traceback: SSH Thread: many users logged in and dACLs being modified

CSCuv92384

ASA TCP Normalizer sends PUSH ACK for invalid ACK for half-open CONNS

CSCuv94338

ASA traceback  in Thread  Name: CP Crypto Result Processing.

CSCuv96011

OSPF over IKEv2 L2L tunnel is broken on ASA with 9.2.1 onwards

CSCuw14334

Trace back with Thread Name: IP Address Assign

CSCuw16607

ASA EIGRP does not send poison reverse for neighbors to remove route

CSCuw17930

Improper S2S IPSec Datapath Selection for Remote Overlapping Networks

CSCuw26991

ASA: Traceback in Thread Unicorn Admin Handler due to Threat Detection

CSCuw28735

Cisco ASA Software Version Information Disclosure Vulnerability

CSCuw36853

ASA: ICMP error loop on cluster CCL with Interface PAT

CSCuw41548

DNS Traceback in channel_put()

CSCuw44744

Traceback in WebVPN rewriter

CSCuw66397

DHCP Server Process stuck if dhcpd auto_config already enabled from CLI