dotnet9.0-9.0.119-1.el8_10

エラータID: AXSA:2026-1329:13

Release date: 
Wednesday, July 22, 2026 - 22:30
Subject: 
dotnet9.0-9.0.119-1.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

* Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 (JIRA:RHEL-192469)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet9.0-9.0.119-1.el8_10.src.rpm
    MD5: 887597d4cdc823f39019ab808f3fbd92
    SHA-256: 8e99a31b9f02a8402c8e0c530a33121cbf884ab388da318d52b30183993bd9d5
    Size: 466.99 MB

Asianux Server 8 for x86_64
  1. aspnetcore-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: 8399d0b68a7dd4ff5e255f23d379f1e9
    SHA-256: 25e688ca50f0132c11bc0d52ac6323196d4695359665fc774209065108249c65
    Size: 7.87 MB
  2. aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: ab53fbc54443dbb9cdc0b84935afe16d
    SHA-256: c295b44f8733867f5b29b562f2ddc5ed34da68f10aff6d78e0e72618047cf738
    Size: 1.60 MB
  3. aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: d4d7be0a8b3f0634a09bf50e963ac13f
    SHA-256: 3069009148aa8458a4f68061149efad4cb7c23b35fadd65fb43257f0db47ef9c
    Size: 1.98 MB
  4. dotnet-apphost-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: e6e7da281659b220f129c75d01374469
    SHA-256: 2d341b30200fae8ca2d6365daa6e0498d7e96315084509f3c7c7891f86a6bc1a
    Size: 3.86 MB
  5. dotnet-hostfxr-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: 5caef9daee16bdb808dd403e198c8fdd
    SHA-256: 0e2339e5c8cc657467b13a857e9275ec04ea815878cf52d629b1eee512f49edf
    Size: 155.70 kB
  6. dotnet-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: 51eebf2757ad21f434dd213d1666dde0
    SHA-256: db12fc8e415d71d40b07867fbfc6890962f51f9f93dad81e90ecc4caedb81c68
    Size: 24.57 MB
  7. dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: b99a4ea7c8daa23cce595920cdf5d1f3
    SHA-256: 795422d17c489ea1ddebf670254bb5c883b6878f936179ac4e36d113c910bf39
    Size: 3.03 MB
  8. dotnet-sdk-9.0-9.0.119-1.el8_10.x86_64.rpm
    MD5: 5626ab0f5beb9eed82d67825e40143ac
    SHA-256: 12d6f8a5b8436e9fe9f2adcd0b7df6fed06c28b25cbffaea5eb6bde8eeda9c1c
    Size: 83.43 MB
  9. dotnet-sdk-9.0-source-built-artifacts-9.0.119-1.el8_10.x86_64.rpm
    MD5: 932022ff1ecb297b47cdd30a1f95a1a7
    SHA-256: 0005855bdaff8d4caf0d4a60401ccda4d6bc5ad991a9374bb3454e04fa90df75
    Size: 779.91 MB
  10. dotnet-sdk-aot-9.0-9.0.119-1.el8_10.x86_64.rpm
    MD5: a0e499417dbd7558eb11819facfdbf7d
    SHA-256: a4d055df28516bab9843694d9487b2361de0730cf39071c4daf0ec61531af3f6
    Size: 18.81 MB
  11. dotnet-sdk-dbg-9.0-9.0.119-1.el8_10.x86_64.rpm
    MD5: 45a0d6d76c444ebddcc69188a0fded7b
    SHA-256: fc3e39b339d126453cbf70c36a1155e44cb69dcd1a50e8ae44ed601618ea9f14
    Size: 17.33 MB
  12. dotnet-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
    MD5: bab8f447c582e3284e156c487dcb5e24
    SHA-256: 80d8e1051d1a3a6680dc91a10d18a8739597eeda53b3d854e75c51329e9ad1a3
    Size: 3.23 MB
  13. dotnet-templates-9.0-9.0.119-1.el8_10.x86_64.rpm
    MD5: 69ef4e8ecff076bd0ca0a09a146b41af
    SHA-256: 3af1f9abec113dd9f6da2bad2442382d8a98d107979dda0e259ce611288a37bb
    Size: 4.19 MB
  14. netstandard-targeting-pack-2.1-9.0.119-1.el8_10.x86_64.rpm
    MD5: 6986388d24384b771fbc999d77960286
    SHA-256: 5b472a2257d360a5c50f69c45b16f0699d299a01fb060c2ffa5765e310be2816
    Size: 1.52 MB