dotnet8.0-8.0.129-1.el8_10.ML.1

エラータID: AXSA:2026-1370:14

Release date: 
Tuesday, July 28, 2026 - 18:37
Subject: 
dotnet8.0-8.0.129-1.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet8.0-8.0.129-1.el8_10.ML.1.src.rpm
    MD5: 85902cd7b25587389c36bd752de58259
    SHA-256: 78a1a078b318111d5336370cbd1d86603023c172ec5bcc3356b13d588996e36d
    Size: 265.16 MB

Asianux Server 8 for x86_64
  1. aspnetcore-runtime-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: a201780e51d58f4aef75a1683400668a
    SHA-256: 0f4afb88ade9f33afbb628de7cc248d14a12b2d18cec7ad46d9b6cd5315b4556
    Size: 8.09 MB
  2. aspnetcore-runtime-dbg-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: a4b1fe56dbd074a257caf2ae7262a733
    SHA-256: 3d58371fda21ba627e4e37786eae6e566292849063e91e49e45e86dd2b7beefb
    Size: 6.78 MB
  3. aspnetcore-targeting-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: 3aae736d1401480c25de7ee3821693e8
    SHA-256: cfed58e39b696c32b8ba6b57b5b6e37383ebe2e615c0b3eb30b4ce327e812e49
    Size: 1.98 MB
  4. dotnet-apphost-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: 22b06b6413d02d7c4858170e5c62e53e
    SHA-256: 2546f7f05d0777fd9da940245ef9f0f28de19ca272f0b571546b076e8d552bd9
    Size: 4.08 MB
  5. dotnet-hostfxr-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: 144bb87be1fb3e7e78ed08c568837a04
    SHA-256: b8c5afabca7b7b1f83f0ba687de22d339c8db56480d959a9a7530db019b57f18
    Size: 153.91 kB
  6. dotnet-runtime-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: 19ff4ce21e00e3d9c7b3a1ac8a22b5b9
    SHA-256: 4b3984ce61a9b3b2af26e0a2027fd98ad27df6ee70127908a08c15aa91c7da38
    Size: 23.80 MB
  7. dotnet-runtime-dbg-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: e704ffc066c93d25a559d71890bee0b9
    SHA-256: 0c93498b6cd8504ad67176a85b95a07d039367dae3f9fd1c016afd9e2f02dc57
    Size: 15.12 MB
  8. dotnet-sdk-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
    MD5: 945a0cb510b8849fca625d8afa278189
    SHA-256: c4e751f79b19d6351189296b933ea174191effe5365090144e91a3d5084beac1
    Size: 89.04 MB
  9. dotnet-sdk-8.0-source-built-artifacts-8.0.129-1.el8_10.ML.1.x86_64.rpm
    MD5: 11854bf49c896151b210879718b99dab
    SHA-256: e4600767d8bbf8797f8e42cde7cf746b9eb3135101bfb16adfffd2c5651205b8
    Size: 685.63 MB
  10. dotnet-sdk-dbg-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
    MD5: 64459b09729dccd708c05860fc834fd4
    SHA-256: f4467fa8d551b8baee2d55a876f0330b6bb4f2d3fa24051ac6aff50fe5270ce8
    Size: 61.26 MB
  11. dotnet-targeting-pack-8.0-8.0.29-1.el8_10.ML.1.x86_64.rpm
    MD5: c019bb46a7c7a7d3bd8e63ccae2c7752
    SHA-256: d21d912540810abb211685fd41c48d37cb71380b6a3acd345293b1e1c9c8536b
    Size: 3.11 MB
  12. dotnet-templates-8.0-8.0.129-1.el8_10.ML.1.x86_64.rpm
    MD5: fb2982ab6e49233dc56d5305cd048d38
    SHA-256: 6a1a2fd392b1f67d05cc7a81646bd99b2e9b60d49a5719e32b4a1731c0081744
    Size: 2.10 MB