dotnet9.0-9.0.119-1.el8_10
エラータID: AXSA:2026-1329:13
リリース日:
2026/07/22 Wednesday - 22:30
題名:
dotnet9.0-9.0.119-1.el8_10
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- .NET には、多数の脆弱性があります。
CVE-2026-47300, CVE-2026-47302, CVE-2026-47303, CVE-2026-47304
CVE-2026-50524, CVE-2026-50525, CVE-2026-50526, CVE-2026-50527
CVE-2026-50528, CVE-2026-50646, CVE-2026-50648, CVE-2026-50649
CVE-2026-50650, CVE-2026-50651, CVE-2026-50659, CVE-2026-56170
CVE-2026-57108
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
追加情報:
N/A
ダウンロード:
SRPMS
- dotnet9.0-9.0.119-1.el8_10.src.rpm
MD5: 887597d4cdc823f39019ab808f3fbd92
SHA-256: 8e99a31b9f02a8402c8e0c530a33121cbf884ab388da318d52b30183993bd9d5
Size: 466.99 MB
Asianux Server 8 for x86_64
- aspnetcore-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 8399d0b68a7dd4ff5e255f23d379f1e9
SHA-256: 25e688ca50f0132c11bc0d52ac6323196d4695359665fc774209065108249c65
Size: 7.87 MB - aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: ab53fbc54443dbb9cdc0b84935afe16d
SHA-256: c295b44f8733867f5b29b562f2ddc5ed34da68f10aff6d78e0e72618047cf738
Size: 1.60 MB - aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: d4d7be0a8b3f0634a09bf50e963ac13f
SHA-256: 3069009148aa8458a4f68061149efad4cb7c23b35fadd65fb43257f0db47ef9c
Size: 1.98 MB - dotnet-apphost-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: e6e7da281659b220f129c75d01374469
SHA-256: 2d341b30200fae8ca2d6365daa6e0498d7e96315084509f3c7c7891f86a6bc1a
Size: 3.86 MB - dotnet-hostfxr-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 5caef9daee16bdb808dd403e198c8fdd
SHA-256: 0e2339e5c8cc657467b13a857e9275ec04ea815878cf52d629b1eee512f49edf
Size: 155.70 kB - dotnet-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: 51eebf2757ad21f434dd213d1666dde0
SHA-256: db12fc8e415d71d40b07867fbfc6890962f51f9f93dad81e90ecc4caedb81c68
Size: 24.57 MB - dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: b99a4ea7c8daa23cce595920cdf5d1f3
SHA-256: 795422d17c489ea1ddebf670254bb5c883b6878f936179ac4e36d113c910bf39
Size: 3.03 MB - dotnet-sdk-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 5626ab0f5beb9eed82d67825e40143ac
SHA-256: 12d6f8a5b8436e9fe9f2adcd0b7df6fed06c28b25cbffaea5eb6bde8eeda9c1c
Size: 83.43 MB - dotnet-sdk-9.0-source-built-artifacts-9.0.119-1.el8_10.x86_64.rpm
MD5: 932022ff1ecb297b47cdd30a1f95a1a7
SHA-256: 0005855bdaff8d4caf0d4a60401ccda4d6bc5ad991a9374bb3454e04fa90df75
Size: 779.91 MB - dotnet-sdk-aot-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: a0e499417dbd7558eb11819facfdbf7d
SHA-256: a4d055df28516bab9843694d9487b2361de0730cf39071c4daf0ec61531af3f6
Size: 18.81 MB - dotnet-sdk-dbg-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 45a0d6d76c444ebddcc69188a0fded7b
SHA-256: fc3e39b339d126453cbf70c36a1155e44cb69dcd1a50e8ae44ed601618ea9f14
Size: 17.33 MB - dotnet-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm
MD5: bab8f447c582e3284e156c487dcb5e24
SHA-256: 80d8e1051d1a3a6680dc91a10d18a8739597eeda53b3d854e75c51329e9ad1a3
Size: 3.23 MB - dotnet-templates-9.0-9.0.119-1.el8_10.x86_64.rpm
MD5: 69ef4e8ecff076bd0ca0a09a146b41af
SHA-256: 3af1f9abec113dd9f6da2bad2442382d8a98d107979dda0e259ce611288a37bb
Size: 4.19 MB - netstandard-targeting-pack-2.1-9.0.119-1.el8_10.x86_64.rpm
MD5: 6986388d24384b771fbc999d77960286
SHA-256: 5b472a2257d360a5c50f69c45b16f0699d299a01fb060c2ffa5765e310be2816
Size: 1.52 MB