Описание
A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized attacker to perform a Denial of Service (DoS) attack over a network by allocating resources without limits or throttling. This can lead to the unavailability of the service for legitimate users.
Меры по смягчению последствий
To mitigate this issue, configure resource limits and throttling for ASP.NET Core applications. This can be achieved by implementing request limits within the application configuration or by utilizing resource quotas provided by container orchestration platforms like OpenShift/Kubernetes. Additionally, web servers acting as reverse proxies can be configured to rate limit incoming requests. Example for OpenShift/Kubernetes ResourceQuotas:
Consult ASP.NET Core documentation for application-level request throttling configurations. Ensure that any changes to resource limits or throttling are thoroughly tested to avoid unintended service disruptions. A service restart or reload may be required for changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 9 | dotnet6.0 | Not affected | ||
| Red Hat Enterprise Linux 9 | dotnet7.0 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:4450 | 12.03.2026 |
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:4451 | 12.03.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:4453 | 12.03.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:4443 | 12.03.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:4455 | 12.03.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:4458 | 12.03.2026 |
| Red Hat Enterprise Linux 9 | dotnet10.0 | Fixed | RHSA-2026:4445 | 12.03.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:4454 | 12.03.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
7.5 High
CVSS3