CVE-2026-0297: GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h15Fixed in 6.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.5Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.0 on ChromeOSto a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.0 on Linuxto a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.0 on Windowsto a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.0 on iOSto a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.0 on macOSto a version that resolves this vulnerability.Fixed in 6.0.15 or later - Upgrade
Upgrade
GlobalProtect App 6.2 on Windowsto a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) or later - Upgrade
Upgrade
GlobalProtect App 6.2 on macOSto a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) or later - Upgrade
Upgrade
GlobalProtect App 6.3 on Windowsto a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) or later - Upgrade
Upgrade
GlobalProtect App 6.3 on macOSto a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) or later - Upgrade
Upgrade
GlobalProtect App 6.3/6.1 on Androidto a version that resolves this vulnerability.Fixed in 6.3.5 or later - Upgrade
Upgrade
GlobalProtect App 6.3/6.1 on ChromeOSto a version that resolves this vulnerability.Fixed in 6.3.5 or later - Upgrade
Upgrade
GlobalProtect App 6.3/6.1 on iOSto a version that resolves this vulnerability.Fixed in 6.3.5 or later - Upgrade
Upgrade
GlobalProtect App 6.3/6.2 on Linuxto a version that resolves this vulnerability.Fixed in 6.3.3-h15 or later - Configuration
Modify GlobalProtect Portal configurations to disable IPSec/UDP tunneling by configuring 'Advanced Control for Tunnel Mode Behavior' so clients connect exclusively via SSL VPN mode.
GlobalProtect Portal Advanced Control for Tunnel Mode Behavior = Enable SSL-Only VPN Connections (disable IPSec/UDP tunneling) - Configuration
On the GlobalProtect gateway, go to Network > Gateway > Agent > Tunnel Setting and un-check 'Enable IPSec' to configure an SSL-only tunnel protocol (disables IPSec/UDP tunneling).
GlobalProtect gateway Enable IPSec = unchecked/disabled - Configuration
Ensure a 'Settings' section exists within the GlobalProtect section, then create /opt/paloaltonetworks/globalprotect/pangps.xml with the pre-deployment configuration key full-chain-cert-verify set to 'yes'.
GlobalProtect (pangps.xml) Settings.full-chain-cert-verify = yes - Configuration
Use Xcode to edit /Library/Preferences/com.paloaltonetworks.GlobalProtect.settings.plist; within the 'Settings' section add the key 'full-chain-cert-verify' and set its string value to 'yes'.
GlobalProtect app on macOS (com.paloaltonetworks.GlobalProtect.settings.plist) Settings.full-chain-cert-verify = yes - Configuration
For GlobalProtect 6.2.8 and GlobalProtect app 6.3.3 on Windows and macOS, enable the new configuration 'Enable Strict Certificate Check' to require certificate checks required to mitigate this issue on these platforms.
GlobalProtect app (Windows and macOS) Enable Strict Certificate Check = enabled - Compensating control
Take the pre-deployment/portal/gateway configuration steps so clients connect using SSL-only (disable IPSec/UDP tunneling) to mitigate the risk of the UDP tunnel handshake buffer overflow.
- Operational
Restart macOS after setting full-chain-cert-verify='yes'.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0297?
The severity of CVE-2026-0297 is rated as high with a score of 7.7.
How do I fix CVE-2026-0297?
To fix CVE-2026-0297, update the Palo Alto Networks GlobalProtect app to the latest version that addresses the buffer overflow vulnerability.
What systems are affected by CVE-2026-0297?
CVE-2026-0297 affects the Palo Alto Networks GlobalProtect app running on Windows and macOS systems.
What type of vulnerability is CVE-2026-0297?
CVE-2026-0297 is a buffer overflow vulnerability that can allow for arbitrary code execution.
What are the potential impacts of CVE-2026-0297?
The potential impacts of CVE-2026-0297 include system disruption and escalation of privileges to SYSTEM on Windows or root on macOS.