dotnet10.0-10.0.110-1.el9_8.ML.1

エラータID: AXSA:2026-1550:16

Release date: 
Monday, August 17, 2026 - 16:06
Subject: 
dotnet10.0-10.0.110-1.el9_8.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet10.0-10.0.110-1.el9_8.ML.1.src.rpm
    MD5: 5def85f7bf6502847dd0a0f2e24f4a6e
    SHA-256: b5ead125fd559c96bca65c5895b8eb513a7d9e050130f929674cd661b42f3668
    Size: 460.16 MB

Asianux Server 9 for x86_64
  1. aspnetcore-runtime-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 9337642e7bea2c75e7e297305fafe458
    SHA-256: b3c41be73ba52db7d8bfc601fb8c1c86a59f8ef32de1f678922359eb698df589
    Size: 8.09 MB
  2. aspnetcore-runtime-dbg-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 7f73869a9d447cb2809ea9d63bb28980
    SHA-256: 1dd3f58cf34fa5c018a825649f0fa7a5e7dec60602ffea80be9278b81a72936c
    Size: 1.75 MB
  3. aspnetcore-targeting-pack-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: eec93c5b5345f88f3720f0a068ea1975
    SHA-256: 94c6a72569fc64a7a7e5123b3acef28e6d8d71fd5a24bfeff86c3a2a81b6da00
    Size: 3.49 MB
  4. dotnet-apphost-pack-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: d58a1e94e3482b367d00e6aa46b5726b
    SHA-256: 2069bd06e78a5545cf47bfc513ff47700dca21fce3c40364e63088f532dd00bc
    Size: 3.83 MB
  5. dotnet-host-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 339986cc2c08444e33749b8743b2f48b
    SHA-256: fa2d2f86c9870f93c583392a939789d94a8929fe9ea0bc545e2269001bb3ebcd
    Size: 234.86 kB
  6. dotnet-hostfxr-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: ab2dcda2cb408938c4444c19f37eb23a
    SHA-256: cb36e9b99885656e0b9638524e9a81457f724d86622075289f9478a5c7a52fb0
    Size: 154.07 kB
  7. dotnet-runtime-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 3f891d552368884603873a1645a4bbe4
    SHA-256: 3119591ba9529ea5417c8fd4347c45dcbf6884e8da074b646315acc67fd731e8
    Size: 24.93 MB
  8. dotnet-runtime-dbg-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 8ce3290da7704583d48078faa6c60c23
    SHA-256: e57edb50d2312aaa2d6103e38cc3f65cd595c825c415bba375349c44d7621d86
    Size: 3.27 MB
  9. dotnet-sdk-10.0-10.0.110-1.el9_8.ML.1.x86_64.rpm
    MD5: 460c7228fa600acb16d7375e933da799
    SHA-256: 605584fc38878f96999476e59e5b89eadc48a970140c2f98f18a2f938f050386
    Size: 97.00 MB
  10. dotnet-sdk-10.0-source-built-artifacts-10.0.110-1.el9_8.ML.1.x86_64.rpm
    MD5: 33f6a3123f162fb6d7c2e565b0e69230
    SHA-256: cb74be95e02564cd89ec54ee25bbb9045280db138327a31d7fc80ff5ab72814b
    Size: 1.09 GB
  11. dotnet-sdk-aot-10.0-10.0.110-1.el9_8.ML.1.x86_64.rpm
    MD5: 24c489f5fcdda5d113239a86025344df
    SHA-256: 0a1615c7e91b7a209fb00e777102785eb529ecfde43e860eedfc3d7a20c09f8f
    Size: 15.91 MB
  12. dotnet-sdk-dbg-10.0-10.0.110-1.el9_8.ML.1.x86_64.rpm
    MD5: 168d45f62119a21a9d19337007ca9679
    SHA-256: 7d1470de69858592b45c8cda4c14a5ae576011639a0c98fe1e995f4475f5332c
    Size: 17.85 MB
  13. dotnet-targeting-pack-10.0-10.0.10-1.el9_8.ML.1.x86_64.rpm
    MD5: 18756667f092638159b2571c50c1eb77
    SHA-256: 852cefbcc732bf81ead6f15c2ddc363a23d3e570249bd9ac9fdc38d825fc8355
    Size: 3.13 MB
  14. dotnet-templates-10.0-10.0.110-1.el9_8.ML.1.x86_64.rpm
    MD5: 54d2d6e5c9a080b049ae7eb615f1e1a2
    SHA-256: 1f6c8b743423cc06622799252a1e48f078b11956f92a4405f3dafc31efb99d56
    Size: 2.77 MB