dotnet8.0-8.0.129-1.el8_10.ML.1
エラータID: AXSA:2026-1370:14
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.
Security Fix(es):
* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Update packages.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
N/A
SRPMS
- dotnet8.0-8.0.129-1.el8_10.ML.1.src.rpm
MD5: 85902cd7b25587389c36bd752de58259
SHA-256: 78a1a078b318111d5336370cbd1d86603023c172ec5bcc3356b13d588996e36d
Size: 265.16 MB
Asianux Server 8 for x86_64
- aspnetcore-runtime-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: a201780e51d58f4aef75a1683400668a
SHA-256: 0f4afb88ade9f33afbb628de7cc248d14a12b2d18cec7ad46d9b6cd5315b4556
Size: 8.09 MB - aspnetcore-runtime-dbg-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: a4b1fe56dbd074a257caf2ae7262a733
SHA-256: 3d58371fda21ba627e4e37786eae6e566292849063e91e49e45e86dd2b7beefb
Size: 6.78 MB - aspnetcore-targeting-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: 3aae736d1401480c25de7ee3821693e8
SHA-256: cfed58e39b696c32b8ba6b57b5b6e37383ebe2e615c0b3eb30b4ce327e812e49
Size: 1.98 MB - dotnet-apphost-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: 22b06b6413d02d7c4858170e5c62e53e
SHA-256: 2546f7f05d0777fd9da940245ef9f0f28de19ca272f0b571546b076e8d552bd9
Size: 4.08 MB - dotnet-hostfxr-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: 144bb87be1fb3e7e78ed08c568837a04
SHA-256: b8c5afabca7b7b1f83f0ba687de22d339c8db56480d959a9a7530db019b57f18
Size: 153.91 kB - dotnet-runtime-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: 19ff4ce21e00e3d9c7b3a1ac8a22b5b9
SHA-256: 4b3984ce61a9b3b2af26e0a2027fd98ad27df6ee70127908a08c15aa91c7da38
Size: 23.80 MB - dotnet-runtime-dbg-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: e704ffc066c93d25a559d71890bee0b9
SHA-256: 0c93498b6cd8504ad67176a85b95a07d039367dae3f9fd1c016afd9e2f02dc57
Size: 15.12 MB - dotnet-sdk-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
MD5: 945a0cb510b8849fca625d8afa278189
SHA-256: c4e751f79b19d6351189296b933ea174191effe5365090144e91a3d5084beac1
Size: 89.04 MB - dotnet-sdk-8.0-source-built-artifacts-8.0.129-1.el8_10.ML.1.x86_64.rpm
MD5: 11854bf49c896151b210879718b99dab
SHA-256: e4600767d8bbf8797f8e42cde7cf746b9eb3135101bfb16adfffd2c5651205b8
Size: 685.63 MB - dotnet-sdk-dbg-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
MD5: 64459b09729dccd708c05860fc834fd4
SHA-256: f4467fa8d551b8baee2d55a876f0330b6bb4f2d3fa24051ac6aff50fe5270ce8
Size: 61.26 MB - dotnet-targeting-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
MD5: c019bb46a7c7a7d3bd8e63ccae2c7752
SHA-256: d21d912540810abb211685fd41c48d37cb71380b6a3acd345293b1e1c9c8536b
Size: 3.11 MB - dotnet-templates-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
MD5: fb2982ab6e49233dc56d5305cd048d38
SHA-256: 6a1a2fd392b1f67d05cc7a81646bd99b2e9b60d49a5719e32b4a1731c0081744
Size: 2.10 MB