dotnet8.0-8.0.129-1.el9_8.ML.1

エラータID: AXSA:2026-1546:15

Release date: 
Monday, August 17, 2026 - 10:57
Subject: 
dotnet8.0-8.0.129-1.el9_8.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

* Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 [rhel-9.8.z] (JIRA:RHEL-192467)
* dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:RHEL-192337)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet8.0-8.0.129-1.el9_8.ML.1.src.rpm
    MD5: 9208ac47a1ba41b92a00e9db74335a87
    SHA-256: b8951bda916a8b2f0a0d5d2e72f62110157bb80b8ec4d07495126f0b3d025e2d
    Size: 265.16 MB

Asianux Server 9 for x86_64
  1. aspnetcore-runtime-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: 6b9a802e1e719632e607c9236a9b156f
    SHA-256: c5cc4bbe0a1fd12fa06d8a150809d08fea081bcf678167ecdb0970a3dbac83fc
    Size: 8.02 MB
  2. aspnetcore-runtime-dbg-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: d46875df4969e7ae7e4ebd6e0c4665ff
    SHA-256: ac300b8219984b9199d281881c17b783cf80fbbc4f9825b6efa7f2069007d22d
    Size: 6.53 MB
  3. aspnetcore-targeting-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: de97f796e41e6573257481eb0324ab0b
    SHA-256: a276e08fb7fae33aa4d9d4a1b30d4a6a4e9770bc5afc74f16ae5d29741f22db4
    Size: 1.93 MB
  4. dotnet-apphost-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: 8d55dde19690bf647e9772e77f0bf686
    SHA-256: 8f16866853b12a4599194e9bd982d6c8127505d76d4855bb198223c921fadec9
    Size: 4.06 MB
  5. dotnet-hostfxr-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: 774f5d0d659b2d63417e2c0b2a8c37c5
    SHA-256: 70801c00cab845787b41110799d329228e77d0963af1460fff3e24ac72291168
    Size: 142.40 kB
  6. dotnet-runtime-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: 6b03059932c1e4b2f457655b688280fe
    SHA-256: 0f0be4322054854a8e063ff2a9f779aa5688aeb96c8970d86d9fdc1e3336fba8
    Size: 23.52 MB
  7. dotnet-runtime-dbg-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: 077eeaee96626cea19627cbef6c842b6
    SHA-256: 811efd9e8290afebef17e7947ffe4ca6203cd02b6bddaa8735c3ef372b8870c5
    Size: 14.98 MB
  8. dotnet-sdk-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
    MD5: e64d3e5dae98ace60868f055bc9dc3e5
    SHA-256: 622463b7c6448774d51bbce86dd34b3388f44de2f1a6b89f81755e98a1b0fd52
    Size: 87.58 MB
  9. dotnet-sdk-8.0-source-built-artifacts-8.0.129-1.el9_8.ML.1.x86_64.rpm
    MD5: 6b31b0a358556547a51c24d34dc2c442
    SHA-256: 7a255797692d7ac76c34378099ca7947df2b9f8a28f49e457ae0491d9df74ec2
    Size: 652.65 MB
  10. dotnet-sdk-dbg-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
    MD5: df4b634ad61f404d475a03961148986b
    SHA-256: 1e0f2432b88420819781c82a3981eee2ccd2ab3f8b2796f3a8490e43c98d4fe0
    Size: 59.26 MB
  11. dotnet-targeting-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
    MD5: b6922a8175d2126d8538195c2cfb84cd
    SHA-256: a2f1281547d6e3b23600b9f85238ed3839dffebe9762614a1e849c3091e24262
    Size: 2.91 MB
  12. dotnet-templates-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
    MD5: 687f405d16c3afb86995dbe4fad8183d
    SHA-256: f67d01e77ecd440a00301df7615a44188bd9ad964f5eb94609d199f625e4ccca
    Size: 2.08 MB