Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Caution: If you are using CSM, and you upgrade to ASA Version 9.8(3)26 or later, then you must upgrade CSM to Version 4.19 or later. Earlier versions of CSM are not compatible.

 

 

Revision:  Version 9.8(3)29 – 04/08/2019

Files:  asa983-29-smp-k9.bin

Defects resolved since 9.8(3)26:

 

CSCvo70145

CPU profiling dump not working after the profiler is enabled

CSCvo79288

Traceback at Thread "IP Address Assign" while testing HA Cert Auth AnyConnect

 

 

Revision:  Version 9.8(3)26 – 03/28/2019

Files:  asa983-26-smp-k9.bin

Defects resolved since 9.8(3)21:

 

CSCuz22961

Support for more than 255 characters for Split DNS value

CSCvi54162

ha-replace action not working when peer not present

CSCvj06993

ASA HA with NSF: NSF is not triggered properly when there is an Interface failure  in ASA HA

CSCvk29263

SSH session stuck after committing changes within a Configure Session.

CSCvm17985

Initiating write net command with management access for BVI interfaces does not succeed

CSCvn17347

Traceback and reload when displaying CPU profiling results

CSCvn22833

ADI process fails to start on ASA on Firepower 4100

CSCvn30108

The 'show memory' CLI output is incorrect on ASAv

CSCvn31347

ACL Unable to configure an ACL after access-group configuration error

CSCvn38453

ASA: Not able to load Quovadis Root Certificate as trustpoint when FIPS is enabled

CSCvn55007

DTLS fails after rekey

CSCvn68527

KP:AnyConnect used IP from pool shows as available

CSCvn94100

Process Name: lina | ASA traceback caused by Netflow

CSCvn96898

Memory Leak in DMA_Pool in binsize 1024 with SCP download

CSCvn97591

Packet Tracer fails with "ERROR: TRACER: NP failed tracing packet", with circular asp drop captures

CSCvo02097

Upgrading ASA cluster to 9.10.1.7 cause traceback

CSCvo03808

Deploy from FMC fails due to OOM with no indication of why

CSCvo06216

Support more than 255 chars for Split DNS-commit issue in hanover for CSCuz22961

CSCvo11077

Memory leak found in IPsec when we establish and terminate a new IKEv1 tunnel.

CSCvo13497

Unable to remove access-list with 'log default' keyword

CSCvo23222

AnyConnect session rejected due to resource issue in multi context deployments

CSCvo27109

Standby may enter reboot loop upon upgrading to 9.6(4)20 from 9.6(4)6

CSCvo42174

ASA IPSec VPN EAP Fails to Load Valid Certificate in PKI

CSCvo56675

ASA traceback and reload when trying to switch from ACTIVE to STANDBY. Thread Name: fover_FSM_thread

CSCvo63240

Smart Tunnel bookmarks don't work after upgrade giving certificate error

 

 

Revision:  Version 9.8(3)21 – 02/04/2019

Files:  asa983-21-smp-k9.bin

Defects resolved since 9.8(3)18:

 

CSCvg36254

FTD Diagnostic Interface does Proxy ARP for br1 management subnet

CSCvg40735

GTP inspection may spike cpu usage

CSCvh26447

Firepower 2100 Series might report failure due to MIO-blade heartbeat failure

CSCvi71622

Traceback in DATAPATH on standby FTD

CSCvk18330

Active FTP Data transfers fail with FTP inspection and NAT

CSCvk30739

ASA CP core pinning leads to exhaustion of core-local blocks

CSCvk30775

ENH: Addition of 'show fragment' to 'show tech' output

CSCvk30783

ENH: Addition of 'show aaa-server' to 'show tech' output

CSCvk46038

ERROR: The entitlement is already acquired while the configuration is cached.

CSCvk72958

Qos applied on interfaces doesn't work.

CSCvm08769

Standby unit sending BFD packets with active unit IP, causing BGP neighborship to fail.

CSCvm55091

HA failed primary unit shows active while "No Switchover" status on FP platforms

CSCvm80779

ASA not inspecting H323 H225

CSCvm82290

ASA core blocks depleted when host unreachable in IRB configuration

CSCvm88004

SSH Service on ASA echoes back each typed/pasted character in its own packet

CSCvn03966

FTD - When "object-group-search" is pushed through flexconfig, all ACLs get deleted causing outage.

CSCvn09322

FTD device rebooted after taking Active State for less than 5 minutes

CSCvn09367

Prevent administrators from installing CXSC module on ASA 5500-X

CSCvn15757

ASA may traceback due to SCTP traffic inspection without NULL check

CSCvn23254

SNMPv2 pulls empty ifHCInOctets value if Nameif is configured on the interface

CSCvn30393

ASA Traceback in emweb/https during Anyconnect Auth/DAP assessment

CSCvn32657

ASA traceback when removing interface configuration used in call-home

CSCvn33943

Standby node traceback in wccp_int_statechange() with HA configuration sync

CSCvn37829

ASA should allow GCM(SSL) connections to use DMA_ALT1 when primary DMA pool is exhausted

CSCvn44201

ASA discards OSPF hello packets with LLS TLVs sent from a neighbor running on IOS XE 16.5.1 or later

CSCvn47599

RA VPN + SAML authentication causes 2 authorization requests against the RADIUS server

CSCvn47800

ASA stops authenticating new AnyConnect connections due to fiber exhaustion

CSCvn61662

ASA 5500-X may reload without crashinfo written due to CXSC module continuously reloading

CSCvn62787

To support multiple retry on devcmd failure to CRUZ during flow table configuration update.

CSCvn64418

ISA300 interop issue with Nokia 7705 router

CSCvn69213

ASA traceback and reload due to multiple threads waiting for the same lock - watchdog

CSCvn73962

ASA 5585 9.8.3.14 traceback in Datapath with ipsec

CSCvn76829

ASA as an SSL Client Memory Leak in Handshake Error path

CSCvn78174

traceback on inspect_process

 

 

Revision:  Version 9.8(3)18 – 12/14/2018

Files:  asa983-18-smp-k9.bin

Defects resolved since 9.8(3)16:

 

CSCvh14743

IKEv2 MOBIKE session with Strongswan/3rd party client fails due to DPD with NAT detection payload.

CSCvk30779

ENH: Addition of 'show ipv6 interface' to 'show tech' output

CSCvk51181

FTD IPV6 traffic outage after interface edit and deployment part 1/2

CSCvm24706

GTP delete bearer request is being dropped

CSCvm53531

PIX-ASA rest-api unauthorized access.

 

CSCvm56371

ASA wrongly removes dACL for all Anyconnect clients which has the same dACL attached

CSCvm67273

ASA: Memory leak due to PC alloc_fo_ipsec_info_buffer_ver_1+136

CSCvm78449

Unable to modify access control license entry with log default command

CSCvm82930

FTD: SSH to ASA Data interface fails if overlapping NAT statement is configured

CSCvn09640

FTD: Need ability to trust ethertype ACLs from the parser. Need to allow BPDU to pass through

CSCvn19823

ASA : Failed SSL connection not getting deleted and depleting DMA memory

 

 

Revision:  Version 9.8(3)16 – 11/13/2018

Files:  asa983-16-smp-k9.bin

Defects resolved since 9.8(3)14:

 

CSCvm43975

Cisco Adaptive Security Appliance Software and FTD Software Denial of Service Vulnerability

 

 

Revision:  Version 9.8(3)14 – 10/26/2018

Files:  asa983-14-smp-k9.bin

Defects resolved since 9.8(3)11:

 

CSCvg01119

IPV4: Implementing buffered reliability mechanism for routing updates

CSCvh01213

An ASA may Traceback and reload when processing traffic

CSCvi42008

Stuck uauth entry rejects AnyConnect user connections

CSCvi90633

Edit GUI language on ASDM AC downloads but ignores the change FPR-21XX

CSCvj42269

ASA 9.8.2  Receiving syslog 321006 reporting System Memory as 101%

CSCvj47256

ASA SIP and Skinny sessions drop, when two subsequent failovers take place

CSCvj58342

Multicast dropped after deleting a security context

CSCvj67258

Change 2-tuple and 4-tuple hash table to lockless

CSCvj97213

ASA IKEv2 capture type isakmp is saving corrupted packets or is missing packets

CSCvk14768

ASA traceback with Thread Name: DATAPATH-1-2325

CSCvk18330

Active FTP Data transfers fail with FTP inspection and NAT

CSCvk24297

IKEv2 RA with EAP fails due to Windows 10 version 1803 IKEv2 fragmentation feature enabled.

CSCvk31035

KVM (FTD): Mapping web server through outside not working consistent with other platforms

CSCvk34648

Firepower 2100 tunnel flap at data rekey with high throughput Lan-to-Lan VPN traffic

CSCvk36087

When logging into the ASA via ASDM, syslog 611101 shows IP as 0.0.0.0 as remote IP

CSCvk66771

The CPU profiler stops running without having hit the threshold and without collecting any samples.

CSCvm01053

ASA 9.8(2)24 traceback on FPR9K-SM-44

CSCvm07458

Using EEM to track VPN connection events may cause traceback and reload

CSCvm23370

ASA: Memory leak due to PC cssls_get_crypto_ctxt

CSCvm25972

ASA Traceback: Thread Name NIC Status Poll.

CSCvm49283

Make Object Group Search Threshold disabled by default, and configurable. Causes outages.

CSCvm56019

Cisco Adaptive Security Appliance WebVPN - VPN not connecting through Browser

CSCvm56719

Traceback HA standby unit Thread Name: vpnfol_thread_msg

CSCvm65725

ASA kerberos auth fails switch to TCP if server has response too big (ERR_RESPONSE_TOO_BIG)

CSCvm80874

ASAv/FP2100 Smart Licensing - Unable to register/renew license

 

 

Revision:  Version 9.8(3)11 – 09/21/2018

Files:  asa983-11-smp-k8.bin

Defects resolved since 9.8(3)8:

 

CSCux69220

WebVPN 'enable intf' with DHCP , CLI missing when ASA boot

CSCvd28906

ASA traceback at first boot in 5506 due to unable to allocate enough LCMB memory

CSCve95403

ASA boot loop caused by logs sent after FIPS boot test

CSCvf85831

asdm displays error uploading image

CSCvh16252

ASA may traceback and reload in Thread Name: fover_rep during conn replication

CSCvh98781

ASA/FTD Deployment ERROR 'Management interface is not allowed as Data is in use by this instance'

CSCvi34164

ASA does not send 104001 and 104002 messages to TCP/UDP syslog

CSCvi53708

ASA NAT position discrepancy between CLI and REST-API causing REST to delete wrong config

CSCvi85382

ASA5515 Low DMA memory when ASA-IC-6GE-SFP-A module is installed

CSCvi96442

Slave unit drops UDP/500 and IPSec packets for S2S instead of redirecting to Master

CSCvj15572

Flow-offload rewrite rules not updated when MAC address of interface changes

CSCvj54840

create/delete context stress test causes traceback in nameif_install_arp_punt_service

CSCvj67776

clear crypto ipsec ikev2 commands not replicated to standby

CSCvj72309

FTD does not send Marker for End-of-RIB after a BGP Graceful Restart

CSCvj75793

2100/4100/9300: stopping/pausing capture from Management Center doesn't lower the CPU usage

CSCvj88514

IP Local pools configured with the same name.

CSCvj91449

ASA traceback when logging host command is enable for IPv6 after each reboot

CSCvj95451

webvpn-l7-rewriter: Bookmark logout fails on IE

CSCvk02250

show memory binsize and "show memory top-usage" do not show correct information (Complete fix)

CSCvk04592

Flows get stuck in lina conn table in half-closed state

CSCvk18378

ASA Traceback and reload when executing show process (rip: inet_ntop6)

CSCvk26887

Certificate import from Local CA fails due to invalid Content-Encoding

CSCvk30665

ASA "snmp-server enable traps memory-threshold" hogs CPU resulting in "no buffer" drops

CSCvk36733

mac  address is flapping on huasan switch when  asa etherchannel is configued with active mode

CSCvk38176

Traceback and reload due to GTP inspection and Failover

CSCvk43865

Traceback: ASA 9.8.2.28 while doing mutex lock

CSCvk45443

ASA cluster: Traffic loop on CCL with NAT and high traffic

CSCvk54779

Async queue issues with fragmented packets leading to block depletion 9344

CSCvk57516

Firepower Threat Defense: Low DMA memory leading to VPN failures due to incorrect crypto maps

CSCvk67239

ASA traceback and reload in "Thread Name: Logger Page fault: Address not mapped"

CSCvk67569

ASA unable to handle Chunked Transfer-encoding returned in HTTP response pages in Clientless WebVPN

CSCvk70676

Clientless webvpn fails when  ASA sends HTTP as a message-body

 

 

Revision:  Version 9.8(3)8 – 08/09/2018

Files:  asa983-8-smp-k8.bin

Defects resolved since 9.8(3):

 

CSCvd13180

AVT : Missing Content-Security-Policy Header in ASA 9.5.2

CSCvd76939

ASA policy-map configuration is not replicated to cluster slave

CSCve53415

ASA traceback in DATAPATH thread while running captures

CSCve85565

Traceback when syslog sent over VPN tunnel

CSCvg76652

Default DLY value of port-channel sub interface mismatch

CSCvh55340

ASA Running config through REST-API Full Backup does not contain the specified context configuration

CSCvh83849

DHCP Relay With Dual ISP and Backup IPSEC Tunnels Causes Flapping

CSCvi03103

BGP ASN cause policy deployment failures.

CSCvi07974

Layer 2 traffic should not be hardcoded to be sent to Snort for inspection

CSCvi19220

ASA fails to encrypt after performing IPv6 to IPv4 NAT translation

CSCvi37644

PKI:- ASA fails to process CRL's with error "Add CA req to pool failed. Pool full."

CSCvi38151

ASA pair: IPv6 static/connected routes are not sync/replicated between Active/Standby pairs.

CSCvi51515

REST-API:500 Internal Server Error

CSCvi79691

LDAP over SSL crypto engine error

CSCvi79999

256 Byte block leak observed due to ARP traffic when using VTI

CSCvi97729

To-the-box traffic being routing out a data interface when failover is transitioning on a New Active

CSCvi99743

Standby traceback in Thread "Logger" after executing "failover active" with telnet access

CSCvj32264

ASA - zonelabs-integrity : Traceback and High CPU due to Process 'Integrity FW task'

CSCvj37448

ASA : Device sends only ID certificate in SSL server certificate packet after reload

CSCvj37924

CWE-20: Improper Input Validation

CSCvj42450

LINA traceback in Thread Name: DATAPATH-14-17303

CSCvj44262

portal-access-rule changing from "deny" to "permit"

CSCvj48340

ASA memory Leak - snp_svc_insert_dtls_session

CSCvj49883

ASA traceback on Firepower Threat Defense 2130-ASA-K9

CSCvj50024

ASA portchannel lacp max-bundle 1 hot-sby port not coming up after link failure

CSCvj56909

ASA does not unrandomize the SLE and SRE values for SACK packet generated by ASA module

CSCvj67740

Static IPv6 route prefix will be removed from the ASA configuration

CSCvj73581

Traceback in cli_xml_server Thread

CSCvj74210

Traceback at "ssh" when executing 'show service-policy inspect gtp pdp-context detail'

CSCvj79765

Netflow configuration on Active ASA is replicated in upside down order on Standby unit

CSCvj91619

1550 Block Depletions leading to ASA reload.

CSCvj92048

Large Config and ACL May Cause Data Interface Health Check Fail on Slave Join

CSCvj97157

WebPage is not loading due to client rewriter issue on JS files

CSCvj98964

ASA may traceback due to SCTP traffic

CSCvk08377

ASA 5525 running 9.8.2.20 memory exhaustion.

CSCvk11898

GTP soft traceback seen while processing v2 handoff

CSCvk18578

Enabling compression necessary to load ASA SSLVPN login page customization

CSCvk19435

Unwanted IE present error when parsing GTP APN Restriction

CSCvk27686

ASA may traceback and reload when acessing qos metrics via ASDM/Telnet/SSH

CSCvk66963

ASA 9.8.3 Smart Licensing Default Config Incorrect