dotnet9.0-9.0.119-1.el9_8.ML.1

エラータID: AXSA:2026-1557:15

Release date: 
Tuesday, August 18, 2026 - 16:05
Subject: 
dotnet9.0-9.0.119-1.el9_8.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dotnet9.0-9.0.119-1.el9_8.ML.1.src.rpm
    MD5: ad469f2781f375dd4de52ccb26fe65a8
    SHA-256: 0310f4aa3db325aa87becd2a16e7c44ce41ea859344b1c6d9240adbe990ccf56
    Size: 466.99 MB

Asianux Server 9 for x86_64
  1. aspnetcore-runtime-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: 267a71d980bb527682076cebaeef4496
    SHA-256: 423dfcd2f103e7a9190a0e7143965380d455520a4b04a2574e999ee9b55ca4e4
    Size: 7.78 MB
  2. aspnetcore-runtime-dbg-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: a137a8c505aed3a77f8d22667334ea28
    SHA-256: 0365d2f75b5ed73a7c9654ea24d7ea4d764cce15946d7a82410bb2baed6153e7
    Size: 1.63 MB
  3. aspnetcore-targeting-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: 063351018dd4175ab5a1c4680405a059
    SHA-256: c85df1cefd7d5763b7ff88edf86f118c2e8ecc2576ea823e4c4b71cea062adb7
    Size: 1.92 MB
  4. dotnet-apphost-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: 19923c2ba0c8e7b6d8e0261a427410e5
    SHA-256: e16f72e02306f9c759d288008885400202e7a4775e7dbc6dd4c8bd5aed511366
    Size: 3.82 MB
  5. dotnet-hostfxr-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: ffb05ba882111ee667ea9793c3a2caf4
    SHA-256: be8fa511560da0bb461d8bebee92a0c8a288e88e8b12450a916638bc6b4b9016
    Size: 143.73 kB
  6. dotnet-runtime-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: 1898890ae6873dcd805566a1dea34e60
    SHA-256: 1c9069fb2467b2c5c0347df7a782ed14feb65185cdc18280fc40b2bd7bfdd7e0
    Size: 24.32 MB
  7. dotnet-runtime-dbg-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: f4b4e84cccaf57162bf59dd43ffdab3f
    SHA-256: 726aa85625eb2a3483099a37aeef585d77ad896c5fc9d9dad2796d59941101f2
    Size: 3.16 MB
  8. dotnet-sdk-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: faef508c82ae92e4f1c962069cb3cfab
    SHA-256: d05082d5b5d850f4b9ab0855113a5a092996417c5c0b65e949b07ed068b3d968
    Size: 81.91 MB
  9. dotnet-sdk-9.0-source-built-artifacts-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: c53a553e1fe1c15f9f3d621aeefbe868
    SHA-256: 87af224ff2b05583869ce949944285b6a255f2e355517fa381def04b867d17b3
    Size: 772.62 MB
  10. dotnet-sdk-aot-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: e7b59686113f2940e4aa4478dcdbff41
    SHA-256: 61c5b7e8677d433f39cdcfd65e2a0ccbe2f6ec91aa242676692715779b13df4a
    Size: 15.98 MB
  11. dotnet-sdk-dbg-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: eb17f4e1ae098e60210fe767ed702f73
    SHA-256: ecdce548ead3a37bd9538b5a9bc81cbcc38ca29b25b839533467b9c30b6f456b
    Size: 15.43 MB
  12. dotnet-targeting-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
    MD5: b29ccff25357f9ca1e2feb4780e7753b
    SHA-256: 015d472f03b41c5e35529c0202472c3629d2e9e711d7a36c29572210979e8a99
    Size: 3.03 MB
  13. dotnet-templates-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: c216d36fdfd234071f035e0163cb38f9
    SHA-256: 1f9cea665c7c9348df87e007b42e351f06cc661e43acf07cfdec03215b28d755
    Size: 2.57 MB
  14. netstandard-targeting-pack-2.1-9.0.119-1.el9_8.ML.1.x86_64.rpm
    MD5: 46e265b0b229ade53018463cee5879da
    SHA-256: b243262ca43cf0477ef00ec26923b7405e7ce6f2f6e94bdafcced02bd7382af5
    Size: 1.35 MB