dotnet10.0-10.0.110-1.el8_10

エラータID: AXSA:2026-1334:13

Release date: 
Thursday, July 23, 2026 - 14:00
Subject: 
dotnet10.0-10.0.110-1.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

* Update .NET 10.0 to SDK 10.0.110 and Runtime 10.0.10 (JIRA:RHEL-192459)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet10.0-10.0.110-1.el8_10.src.rpm
    MD5: 48ac4556f40b93c623cc16fa7636d301
    SHA-256: 0e3ebf8b39d9c3b945ac767a19245a4ba27c17fe05284b78f2b0fd9d68cb6e7a
    Size: 460.15 MB

Asianux Server 8 for x86_64
  1. aspnetcore-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 8a9c2dd0f3482dfe4b7fb2ea03fbb508
    SHA-256: e5ec17ca59889e36cbef0eb66be5e0202c4c1071b857803521d9e1574c75eaf4
    Size: 8.19 MB
  2. aspnetcore-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 37436a228937245d78cff5e54e3f18c0
    SHA-256: 5192a13711ad14708cc4a05363373dbd4310b0fefe1d003e43d7a4812c54eb31
    Size: 1.70 MB
  3. aspnetcore-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 0e502b4a2608bd632fbc1e8fc1ea3b93
    SHA-256: b2cd472ec09bd1546373416a33fcf2690d3dce5bc384bf704432f1ec677ebb4e
    Size: 3.85 MB
  4. dotnet-10.0.110-1.el8_10.x86_64.rpm
    MD5: 32f725ff9241b8f4037cccdad608a04f
    SHA-256: 06be958cc955d52de1b4f6583bc93d92e8323c4b7b8fb1c8322b3cd369ad55ea
    Size: 8.91 kB
  5. dotnet-apphost-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 9f878a9ccd9524bdaf6f7a0c7f686cb3
    SHA-256: 87a3fd4705751ca2cb2bbba9f55165e55a475ccacad89487a08480dac1356337
    Size: 3.86 MB
  6. dotnet-host-10.0.10-1.el8_10.x86_64.rpm
    MD5: 4960eefbba0f424d557bbf614417dc10
    SHA-256: 0cf7e01b3ee9c546e508090b084480a114a0302051796544dacac646347ed61c
    Size: 218.14 kB
  7. dotnet-hostfxr-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: f14404b3c25bc2ec188cbd666b5db448
    SHA-256: 54abf83c91757c05ec8456b1a339ced9281a33682ea6248405f6a76bf73becd0
    Size: 153.09 kB
  8. dotnet-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 703bdabbc3005cd4a8253a147768acba
    SHA-256: b836c36b37c987cd5dc12f705094cc8e32178addfc543afd155c4584a9d90184
    Size: 25.11 MB
  9. dotnet-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 7455202c13ddf2326a6ff0c6b905aa39
    SHA-256: ba1d761abc3c6c3aaea6ddd7ba6114cda2ca3723dc29e168ee18bf8428e41235
    Size: 3.14 MB
  10. dotnet-sdk-10.0-10.0.110-1.el8_10.x86_64.rpm
    MD5: 09340416e012cd4c5af2596e52945f1b
    SHA-256: 0c2e8c60ae29c1d81779401a03ce6cb0097f6b27d11ba31aa57e2af9c9271c7e
    Size: 99.70 MB
  11. dotnet-sdk-10.0-source-built-artifacts-10.0.110-1.el8_10.x86_64.rpm
    MD5: 5fd6184093eec06b0d41615e5161eb19
    SHA-256: b7ffa5b6800d209e48c959d8995ee8ec12cbbd2f2b12c8d321c1fc62e53f02b1
    Size: 1.10 GB
  12. dotnet-sdk-aot-10.0-10.0.110-1.el8_10.x86_64.rpm
    MD5: 587c3b6f31d7e95bb51f64ed93481030
    SHA-256: cacee1047301bae446a3555c73dd7f601108f0c62f4b0e433496f6d299ed8fad
    Size: 18.82 MB
  13. dotnet-sdk-dbg-10.0-10.0.110-1.el8_10.x86_64.rpm
    MD5: 9b2b2585c44101d451f1e92fa58a95ed
    SHA-256: a72d0912717895bb692a32e44f09c95ed2090433467f773615b142275890ecc3
    Size: 20.17 MB
  14. dotnet-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
    MD5: 60552cde84b2a586e43173c321aeb2b0
    SHA-256: 3145f9d7296bd3e20cd73e0a3e884f60a189440d53b79317940266b79fb7a934
    Size: 3.33 MB
  15. dotnet-templates-10.0-10.0.110-1.el8_10.x86_64.rpm
    MD5: 829d9795cb1cce1e3157b5d92291b90e
    SHA-256: d5311379fffcc0921761ab2b814e7668db321ecb756dabc008bc443aebec7687
    Size: 4.31 MB