dotnet10.0-10.0.110-1.el8_10
エラータID: AXSA:2026-1334:13
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10.
Security Fix(es):
* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)
Bug Fix(es) and Enhancement(s):
* Update .NET 10.0 to SDK 10.0.110 and Runtime 10.0.10 (JIRA:RHEL-192459)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Update packages.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
N/A
SRPMS
- dotnet10.0-10.0.110-1.el8_10.src.rpm
MD5: 48ac4556f40b93c623cc16fa7636d301
SHA-256: 0e3ebf8b39d9c3b945ac767a19245a4ba27c17fe05284b78f2b0fd9d68cb6e7a
Size: 460.15 MB
Asianux Server 8 for x86_64
- aspnetcore-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 8a9c2dd0f3482dfe4b7fb2ea03fbb508
SHA-256: e5ec17ca59889e36cbef0eb66be5e0202c4c1071b857803521d9e1574c75eaf4
Size: 8.19 MB - aspnetcore-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 37436a228937245d78cff5e54e3f18c0
SHA-256: 5192a13711ad14708cc4a05363373dbd4310b0fefe1d003e43d7a4812c54eb31
Size: 1.70 MB - aspnetcore-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 0e502b4a2608bd632fbc1e8fc1ea3b93
SHA-256: b2cd472ec09bd1546373416a33fcf2690d3dce5bc384bf704432f1ec677ebb4e
Size: 3.85 MB - dotnet-10.0.110-1.el8_10.x86_64.rpm
MD5: 32f725ff9241b8f4037cccdad608a04f
SHA-256: 06be958cc955d52de1b4f6583bc93d92e8323c4b7b8fb1c8322b3cd369ad55ea
Size: 8.91 kB - dotnet-apphost-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 9f878a9ccd9524bdaf6f7a0c7f686cb3
SHA-256: 87a3fd4705751ca2cb2bbba9f55165e55a475ccacad89487a08480dac1356337
Size: 3.86 MB - dotnet-host-10.0.10-1.el8_10.x86_64.rpm
MD5: 4960eefbba0f424d557bbf614417dc10
SHA-256: 0cf7e01b3ee9c546e508090b084480a114a0302051796544dacac646347ed61c
Size: 218.14 kB - dotnet-hostfxr-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: f14404b3c25bc2ec188cbd666b5db448
SHA-256: 54abf83c91757c05ec8456b1a339ced9281a33682ea6248405f6a76bf73becd0
Size: 153.09 kB - dotnet-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 703bdabbc3005cd4a8253a147768acba
SHA-256: b836c36b37c987cd5dc12f705094cc8e32178addfc543afd155c4584a9d90184
Size: 25.11 MB - dotnet-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 7455202c13ddf2326a6ff0c6b905aa39
SHA-256: ba1d761abc3c6c3aaea6ddd7ba6114cda2ca3723dc29e168ee18bf8428e41235
Size: 3.14 MB - dotnet-sdk-10.0-10.0.110-1.el8_10.x86_64.rpm
MD5: 09340416e012cd4c5af2596e52945f1b
SHA-256: 0c2e8c60ae29c1d81779401a03ce6cb0097f6b27d11ba31aa57e2af9c9271c7e
Size: 99.70 MB - dotnet-sdk-10.0-source-built-artifacts-10.0.110-1.el8_10.x86_64.rpm
MD5: 5fd6184093eec06b0d41615e5161eb19
SHA-256: b7ffa5b6800d209e48c959d8995ee8ec12cbbd2f2b12c8d321c1fc62e53f02b1
Size: 1.10 GB - dotnet-sdk-aot-10.0-10.0.110-1.el8_10.x86_64.rpm
MD5: 587c3b6f31d7e95bb51f64ed93481030
SHA-256: cacee1047301bae446a3555c73dd7f601108f0c62f4b0e433496f6d299ed8fad
Size: 18.82 MB - dotnet-sdk-dbg-10.0-10.0.110-1.el8_10.x86_64.rpm
MD5: 9b2b2585c44101d451f1e92fa58a95ed
SHA-256: a72d0912717895bb692a32e44f09c95ed2090433467f773615b142275890ecc3
Size: 20.17 MB - dotnet-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm
MD5: 60552cde84b2a586e43173c321aeb2b0
SHA-256: 3145f9d7296bd3e20cd73e0a3e884f60a189440d53b79317940266b79fb7a934
Size: 3.33 MB - dotnet-templates-10.0-10.0.110-1.el8_10.x86_64.rpm
MD5: 829d9795cb1cce1e3157b5d92291b90e
SHA-256: d5311379fffcc0921761ab2b814e7668db321ecb756dabc008bc443aebec7687
Size: 4.31 MB