Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:41899

Опубликовано: 23 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: .NET 9.0 security, bug fix, and enhancement update

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18.

Security Fix(es):

  • dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)

  • dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)

  • ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)

  • ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)

  • ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)

  • dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)

  • dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)

  • dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)

  • dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)

  • dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)

  • dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)

  • dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)

  • dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)

  • dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)

  • dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)

  • .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)

  • dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

  • Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 (JIRA:Rocky Linux-192469)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
aspnetcore-runtime-9.0x86_641.el8_10aspnetcore-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
aspnetcore-runtime-dbg-9.0x86_641.el8_10aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
aspnetcore-targeting-pack-9.0x86_641.el8_10aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
dotnet-apphost-pack-9.0x86_641.el8_10dotnet-apphost-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
dotnet-hostfxr-9.0x86_641.el8_10dotnet-hostfxr-9.0-9.0.18-1.el8_10.x86_64.rpm
dotnet-runtime-9.0x86_641.el8_10dotnet-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
dotnet-runtime-dbg-9.0x86_641.el8_10dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
dotnet-sdk-9.0x86_641.el8_10dotnet-sdk-9.0-9.0.119-1.el8_10.x86_64.rpm
dotnet-sdk-aot-9.0x86_641.el8_10dotnet-sdk-aot-9.0-9.0.119-1.el8_10.x86_64.rpm
dotnet-sdk-dbg-9.0x86_641.el8_10dotnet-sdk-dbg-9.0-9.0.119-1.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
8 дней назад

Important: .NET 8.0 security, bug fix, and enhancement update

rocky
8 дней назад

Important: .NET 10.0 security, bug fix, and enhancement update

rocky
8 дней назад

Important: .NET 10.0 security, bug fix, and enhancement update

rocky
8 дней назад

Important: .NET 9.0 security, bug fix, and enhancement update

rocky
8 дней назад

Important: .NET 8.0 security, bug fix, and enhancement update