Описание
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
A flaw was found in .NET. This vulnerability, stemming from improper link resolution before file access, allows an authorized local attacker to perform tampering. This could lead to unauthorized modification of data or system files.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:41893 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:41895 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:41897 | 20.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet8.0 | Fixed | RHSA-2026:58566 | 24.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet9.0 | Fixed | RHSA-2026:58567 | 24.08.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:41899 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:41900 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:41901 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:41894 | 20.07.2026 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2500565dotnet: .NET: Local tampering via improper link resolution
7 High
CVSS3
Связанные уязвимости
CVSS3: 7
ubuntu
2 месяца назад
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVSS3: 7
nvd
2 месяца назад
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVSS3: 7
github
около 2 месяцев назад
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
7 High
CVSS3