dotnet9.0-9.0.119-1.el8_10
エラータID: AXSA:2026-1329:13
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18.
Security Fix(es):
* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)
Bug Fix(es) and Enhancement(s):
* Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 (JIRA:RHEL-192469)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Update packages.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
N/A
SRPMS
- dotnet9.0-9.0.119-1.el8_10.src.rpm
MD5: 887597d4cdc823f39019ab808f3fbd92
SHA-256: 8e99a31b9f02a8402c8e0c530a33121cbf884ab388da318d52b30183993bd9d5
Size: 466.99 MB
Asianux Server 8 for x86_64
- aspnetcore-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 8399d0b68a7dd4ff5e255f23d379f1e9
SHA-256: 25e688ca50f0132c11bc0d52ac6323196d4695359665fc774209065108249c65
Size: 7.87 MB - aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: ab53fbc54443dbb9cdc0b84935afe16d
SHA-256: c295b44f8733867f5b29b562f2ddc5ed34da68f10aff6d78e0e72618047cf738
Size: 1.60 MB - aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: d4d7be0a8b3f0634a09bf50e963ac13f
SHA-256: 3069009148aa8458a4f68061149efad4cb7c23b35fadd65fb43257f0db47ef9c
Size: 1.98 MB - dotnet-apphost-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: e6e7da281659b220f129c75d01374469
SHA-256: 2d341b30200fae8ca2d6365daa6e0498d7e96315084509f3c7c7891f86a6bc1a
Size: 3.86 MB - dotnet-hostfxr-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 5caef9daee16bdb808dd403e198c8fdd
SHA-256: 0e2339e5c8cc657467b13a857e9275ec04ea815878cf52d629b1eee512f49edf
Size: 155.70 kB - dotnet-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 51eebf2757ad21f434dd213d1666dde0
SHA-256: db12fc8e415d71d40b07867fbfc6890962f51f9f93dad81e90ecc4caedb81c68
Size: 24.57 MB - dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: b99a4ea7c8daa23cce595920cdf5d1f3
SHA-256: 795422d17c489ea1ddebf670254bb5c883b6878f936179ac4e36d113c910bf39
Size: 3.03 MB - dotnet-sdk-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 5626ab0f5beb9eed82d67825e40143ac
SHA-256: 12d6f8a5b8436e9fe9f2adcd0b7df6fed06c28b25cbffaea5eb6bde8eeda9c1c
Size: 83.43 MB - dotnet-sdk-9.0-source-built-artifacts-9.0.119-1.el8_10.x86_64.rpm
MD5: 932022ff1ecb297b47cdd30a1f95a1a7
SHA-256: 0005855bdaff8d4caf0d4a60401ccda4d6bc5ad991a9374bb3454e04fa90df75
Size: 779.91 MB - dotnet-sdk-aot-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: a0e499417dbd7558eb11819facfdbf7d
SHA-256: a4d055df28516bab9843694d9487b2361de0730cf39071c4daf0ec61531af3f6
Size: 18.81 MB - dotnet-sdk-dbg-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 45a0d6d76c444ebddcc69188a0fded7b
SHA-256: fc3e39b339d126453cbf70c36a1155e44cb69dcd1a50e8ae44ed601618ea9f14
Size: 17.33 MB - dotnet-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: bab8f447c582e3284e156c487dcb5e24
SHA-256: 80d8e1051d1a3a6680dc91a10d18a8739597eeda53b3d854e75c51329e9ad1a3
Size: 3.23 MB - dotnet-templates-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 69ef4e8ecff076bd0ca0a09a146b41af
SHA-256: 3af1f9abec113dd9f6da2bad2442382d8a98d107979dda0e259ce611288a37bb
Size: 4.19 MB - netstandard-targeting-pack-2.1-9.0.119-1.el8_10.x86_64.rpm
MD5: 6986388d24384b771fbc999d77960286
SHA-256: 5b472a2257d360a5c50f69c45b16f0699d299a01fb060c2ffa5765e310be2816
Size: 1.52 MB