Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.5(2)14 – 07/11/2016

Files:  asa952-14-smp-k8.bin

Defects resolved since 9.5(2)11:

 

CSCtw90511

Packet captures cause CPU spike on Multi-Core platforms due to spin_lock

CSCuh99564

Password change page can be displayed without authentication

CSCuu54582

ASA-SFR, ASA should attempt to join Cluster after SFR service module up

CSCux56111

"no ipv6-vpn-addr-assign" CLI not working

CSCux61257

ASA: Traceback in Thread IP Address Assign

CSCux70784

ASA traceback while viewing large ACL

CSCux70812

Add Asynchronous support for DHCP proxy

CSCuy00296

Traceback in Thread: IPsec message handler

CSCuy43857

ASA WebVPN: Java Exception with Kronos application

CSCuy48004

ASDM detects a config change when dACL is pushed for Anyconnect user

CSCuy54567

Evaluation of pix-asa for OpenSSL March 2016

CSCuy63642

ASA 9.1(6) traceback in webvpn-datapath : thread name "DATAPATH-2-1524"

CSCuy67333

SIP call transfer fail due to differences b/w fixing CallId and Refer-To

CSCuy98769

Slow ASA OSPF interface transition from DOWN to WAITING after failover

CSCuz00077

ASA 9.1.6.4 traceback with Thread Name: telnet/ci

CSCuz04534

Memory leak in 112 byte bin when packet hits PBR and WCCP rules

CSCuz14600

Kenton 9.5.1 'boot system/boot config' commands not retained after reload

CSCuz14808

5585-10 traceback in Thread Name: idfw_proc

CSCuz21178

ASA traceback in threadname ssh

CSCuz23576

Allocated memory showing high (invalid) values

CSCuz38180

ASA: Page Fault traceback in DATAPATH on standby ASA after booting up

CSCuz38703

ASA capture type isakmp saving malformed ISAKMP packets

CSCuz38888

WebVPN rewrite fails for MSCA Cert enrollment page / VBScript

CSCuz40081

ASA memory leak due to vpnfo

CSCuz40793

Interfaces get deleted on SFR during HA configuration sync

CSCuz41033

dynamic crypto map fails if named the same as static crypto map

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz54193

ASA: Traceback on ASA in Datapath as we enable SFR traffic redirection

CSCuz54545

ASA Address not mapped traceback - configuring snmp-server host

CSCuz58142

ASA Access-list missing and losing elements Warning Message enhancement

CSCuz60555

ASA-2-321006 May be received invalidly when memory is not high

CSCuz66661

ASA Cut-through Proxy inactivity timeout not working

CSCuz67590

ASA may Traceback with Thread Name: cluster rx thread

CSCuz67596

ASA may Traceback with Thread Name: Unicorn Admin Handler

CSCuz70330

ASA: SSH being denied on the ASA device as the maximum limit is reached

CSCuz79800

ASA cant delete ACL lines and remarks - Specified remark does not exist

 

 

Revision:  Version 9.5(2)11 – 06/10/2016  This is only to be used with the 1.1.3 FX-OS release only.

Files:  asa952-11-smp-k8.bin

Defects resolved since 9.5(2)10:

 

CSCuv76576

RX ring no buffer drops is observed on SSP when cluster sends CLU msgs

CSCux83883

9.6.1/QP - Traceback in appagent_async_client_send_thread

 

 

Revision:  Version 9.5(2)10 – 05/31/2016

Files:  asa952-10-smp-k8.bin

Defects resolved since 9.5(2)6:

 

CSCum70304

FIPS self test power on fails - fipsPostDrbgKat

CSCur49234

ASA Mgmt Session stuck on running "sh block exhaustion snapshot/history"

CSCus37458

ASA traceback in Thread name DATAPATH when handling multicast packet

CSCut10103

ASA 5545x Upgrade to 9.2(2)4 causes Traceback in Thread Name SSL

CSCuv09640

ASA: "Auto-Enable" feature not working with SSH configured with PKF

CSCuv42720

Egress ACL with ICMP Types Misbehaving.

CSCuv47191

9.5.1 - Crash in bcm_esw_init thread

CSCuw30999

ASA5508 5516 Unable to communicate with 100/full configured after reboot.

CSCux08838

ASA: Traceback in Checkheaps

CSCux11440

ASA traceback in Unicorn Proxy Thread

CSCux29842

Primary and Secondary ASA in HA is traceback in Thread Name:DataPath

CSCux30780

GTPv1 traceback in gtpv1_process_msg

CSCux33726

ASA traceback - WebVPN CIFS_file_rename_remove operations

CSCux33974

ASA "show chunkstat | redirect" does not work

CSCux35538

Traceback in  ctm_ssl_generate_key with DHE ciphers SSL VPN scaled test

CSCux41876

ASA IPSEC crypto map set df-bit copy-df/clear-df does not take effect

CSCux55923

WebVPN: Unable to play certain online videos

CSCux58172

DAP: debug dap trace not fully shown after +1600 lines

CSCux58483

Deadlock in gtp_lu_process_pdpmcb_info

CSCux66866

Traffic drop due to constant amount of arp on ASASM

CSCux70998

Reload in Thread Name: IKE Daemon

CSCux82835

Nat pool exhausted observed when enabling asp transactional-commit nat

CSCux83705

DNS Reply Modification for Dual-Stack does not work as expected

CSCux94598

ASA using a huge dynamic ACL may cause Anyconnect connectivity failures

CSCux96716

Traceback when unit joins cluster

CSCuy01438

ASA traceback with SIP inspection and SFR enabled in 9.5.2

CSCuy05949

ASA: MAC address changes on active context when WRITE STANDBY is issued

CSCuy07753

Smart tunnel does not work since Firefox 32bit  version 43

CSCuy10665

HA: Number of interfaces mismatch after SFR module reload on both units

CSCuy11281

ASA: Assert traceback in version 9.4.2

CSCuy21206

Traceback when drop is enabled with diameter inspection and tls-proxy

CSCuy21287

STBY ASA does't pass traffic via ASA-IC-6GE-SFP-B ifc after reload

CSCuy34265

ASA Access-list missing and losing elements after configuration change

CSCuy43839

ASA reloads in thread name: DATAPATH while encrypting L2L packet

CSCuy45475

ASA : Configuration not replicated on mate if standby IP is missing

CSCuy49902

inspect ip-option is not allowing "NOP" even when allowed

CSCuy51918

Buffer overflow in RAMFS dirent structure causing traceback

CSCuy57644

ASAv sub-interface failing to send traffic with customised mac-address

CSCuy58084

Unable to configure a user for ssh public auth only (tied w/ CSCuw90580)

CSCuy65416

assert "ctm->async_ref == 0" failed: file "ssl_common.c", line 193-part2

CSCuy73652

Traceback in thread name idfw when modifying object-group having FQDN

CSCuy74218

Assert Traceback in Thread Name: DATAPATH on clustered packet reassembly

CSCuy74362

WebVPN FTP client failing with "Error contacting host" message

CSCuy78802

orignial master not defending all GARP packets after cluster split brain

CSCuy80058

FO replication failed: cmd=no disable, when disabling webvpn-cache

CSCuy85243

ASA traceback when receive Radius attribute with improper variable type

CSCuy87597

ASA - Traceback in CP Processing Thread During Private Key Decryption

CSCuy89425

AAA: RSA/SDI unable to set new PIN

CSCuy90936

ASA may stop responding to OSPF Hello packets

CSCuy91788

ASAv: Free memory is reported as negative in an OOM condition

CSCuy94787

Traceback in DATAPATH or Hi CPU usage due to Threat Detection

CSCuy95543

Improve efficiency of malloc_avail_freemem()

CSCuy96391

ASA clientless rewriter failure at 'CSCOPut_hash' function

CSCuy99280

ENH: ASAv should have a different pre-loaded cert

CSCuz01658

Traceback in gtp_remove_request with duplicate requests

CSCuz06125

Active and Standby ASA use same MAC addr with only active MAC configured

CSCuz08625

ASA traceback in SSH thread

CSCuz09394

infinite loop in JS rewriter state machine when return followed by var

CSCuz10371

ASA Traceback and reload by strncpy_sx.c

CSCuz18707

Intranet page does not load via WebVPN with JavaScript errors

CSCuz21068

CSCOPut_hash can initiate unexepected requests

CSCuz30425

Network command disappears from BGP after reload with name

CSCuz38115

ASA Tback when large ACL applied to interface with object-group-search

CSCuz67349

ASA Cluster fragments reassembled before transmission with no inspection

 

 

Revision:  Version 9.5(2)6 – 03/21/2016

Files:  asa952-6-smp-k8.bin

Defects resolved since 9.5(2)5:

 

CSCtk35575

Debug trace for mps_shash_release with logging.

CSCtz82865

SNMP MIB: Equivalent of "show xlate count" command

CSCtz98516

Observed Traceback in SNMP while querying GET BULK for 'xlate count'

CSCun21186

ASA traceback when retrieving idfw topn user from slave

CSCur87011

ASA low DMA memory on low end ASA-X -5512/5515 devices

CSCus10787

Transactional ACL commit will bypass security policy during compilation

CSCus16416

Share licenses are not activated on failover pair after power cycle

CSCus53126

ASA traffic not sent properly using 'traffic-forward sfr monitor-only'

CSCut40770

Interface TLV to SFR is corrupt when frame is longer than 2048 bytes

CSCuu48197

ASA: Stuck uauth entry rejects AnyConnect user connections

CSCuv20449

Traceback in Thread Name: ssh when using capture or continuous ping

CSCuv49446

ASA traceback on Standby device during config sync in thread DATAPATH

CSCuw02009

ASA - SSH sessions stuck in CLOSE_WAIT causing ASA to send RST

CSCuw19671

ASA traceback while restoring backup configuration from ASDM

CSCuw28735

Cisco ASA Software Version Information Disclosure Vulnerability

CSCuw39685

filter sfr traffic may cause  memory corruption

CSCuw44038

Watchdog traceback in ldap_client_thread with large number of ldap grps

CSCuw51576

SSH connections are not timed out on Standby ASA (stuck in rtcli)

CSCuw55813

Standby ASA traceback in Thread Name: EIGRP-IPv4

CSCuw87331

ASA: Traceback in Thread name DATAPATH-7-1918

CSCuw90116

ASA 9.4.1 traceback upon clearing and reconfiguring ACL

CSCuw92005

Thread Name: DATAPATH-17-3095: ASA in Cluster Reloads Unexpectedly

CSCux03626

Traceback in thread name: Unicorn Proxy Thread

CSCux05081

RSA 4096 key generation causes failover

CSCux07002

ASA: assertion "pp->pd == pd" failed: file "main.c", line 192

CSCux08783

CWS: ASA does not append XSS headers

CSCux09181

http-form authentication fails after 9.3.2

CSCux09310

ASA traceback when using an ECDSA certificate

CSCux15273

show memory indicates inaccurate free memory available

CSCux16427

PBR incorrect route selection for deny clause

CSCux20178

OSPF neighbor goes down after "reload in xx" commnad in 9.2 and later

CSCux22468

VPN connection may fail when using an ECDSA certificate

CSCux23659

ASA 9.1.6.10 traceback after remove compact flash and execute dir cmd

CSCux26443

DAP URL-List Command Says It Supports 491 Characters; Only Supports 245

CSCux29929

ASA 9.4.2 traceback in DATAPATH

CSCux35272

ASA TCP normalizer checksum verification cannot be disabled

CSCux36112

PBR: Mem leak by snp_policy_based_route_lookup in cluster mode

CSCux37303

Port-Channel Config on Gi 0/0 causes Boot Loop - FIPS related

CSCux37442

Cisco signed certificate expired for WebVpn Port Forward Binary on ASA

CSCux41145

Evaluation of pix-asa for OpenSSL December 2015 Vulnerabilities

CSCux41622

"set connection timeout idle" is not applied.

CSCux42936

ASA 9.5.1 traceback in Threadname Datapath due to SIP Inspection

CSCux43978

DHCP Relay fails for cluster ASAs with long interface names

CSCux47195

ASA(9.5.2) changing the ACK number sent to client with SFR redirection

CSCux59122

ASA L7 policy-map comes into affect only if the inspection is re-applied

CSCux59851

Anyconnect IKEv2 with Host Scan can't connect with SSL disabled

CSCux60798

ASA showing Error as "(No such device)" while doing write net

CSCux69220

WebVPN 'enable intf' with DHCP , CLI missing when ASA boots up

CSCux69987

ASA: Traceback on ASA device after adding FQDN objects in NAT rule

CSCux71197

"show resource usage" gives wrong number of routes after shut/no sh

CSCux72610

ASA TACACS+: process tacplus_snd uses large percentage of CPU

CSCux72835

ASA 9.5 - OCSP check using global routing table instead of management

CSCux81683

ASA Traceback on Thread Name: Unicorn Admin Handler

CSCux86769

VLAN mapping doesn't work when connection falls back to TLS

CSCux87457

ASA traceback in Thread  Name: https_proxy

CSCux88237

ASA traceback in DATAPATH thread

CSCux90767

Resolve CSCtz82865 - Equivalent of "show xlate count" command

CSCux99392

Uploaded/downloaded files via CIFS have Zero Byte size (same WebFolder)

CSCuy01420

ASA traceback in Thread Name: Unicorn Proxy Thread.

CSCuy11021

Webvpn bookmark subtitles not visible

CSCuy11905

ASA 5585 traceback when the User name is mentioned in the Access list

CSCuy13937

ASA Watchdog traceback in CP Processing thread during TLS processing

CSCuy22561

VPN Load-Balancing does not send load-balancing cert for IPv6 Address

CSCuy30069

ASA 9.5.2 does not send CERT_REQ for 512-bit certificate

CSCuy32321

Traceback in ldap_client_thread with ldap attr mapping and pw-mgmt

 

 

Revision:  Version 9.5(2)5 – 02/23/2016

Files:  asa952-5-smp-k8.bin

Defects resolved since 9.5(2)2:

 

CSCux45179

SSL sessions stop processing -"Unable to create session directory" error

CSCux85725

ASA WebVPN: Java RDP Plugin does not launch

CSCuy03024

ASA Crashes and reloads citing Thread Name: idfw_proc

CSCuy41986

OCSP validation fails when multiple certs in chain are verified

 

 

Revision:  Version 9.5(2)2 – 01/28/2016

Files:  asa952-2-smp-k8.bin

Defects resolved since 9.5(2):

 

CSCux29978

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

CSCux42019

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability