dotnet8.0-8.0.129-1.el9_8.ML.1
エラータID: AXSA:2026-1546:15
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.
Security Fix(es):
* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)
Bug Fix(es) and Enhancement(s):
* Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 [rhel-9.8.z] (JIRA:RHEL-192467)
* dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:RHEL-192337)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Update packages.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
N/A
SRPMS
- dotnet8.0-8.0.129-1.el9_8.ML.1.src.rpm
MD5: 9208ac47a1ba41b92a00e9db74335a87
SHA-256: b8951bda916a8b2f0a0d5d2e72f62110157bb80b8ec4d07495126f0b3d025e2d
Size: 265.16 MB
Asianux Server 9 for x86_64
- aspnetcore-runtime-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: 6b9a802e1e719632e607c9236a9b156f
SHA-256: c5cc4bbe0a1fd12fa06d8a150809d08fea081bcf678167ecdb0970a3dbac83fc
Size: 8.02 MB - aspnetcore-runtime-dbg-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: d46875df4969e7ae7e4ebd6e0c4665ff
SHA-256: ac300b8219984b9199d281881c17b783cf80fbbc4f9825b6efa7f2069007d22d
Size: 6.53 MB - aspnetcore-targeting-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: de97f796e41e6573257481eb0324ab0b
SHA-256: a276e08fb7fae33aa4d9d4a1b30d4a6a4e9770bc5afc74f16ae5d29741f22db4
Size: 1.93 MB - dotnet-apphost-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: 8d55dde19690bf647e9772e77f0bf686
SHA-256: 8f16866853b12a4599194e9bd982d6c8127505d76d4855bb198223c921fadec9
Size: 4.06 MB - dotnet-hostfxr-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: 774f5d0d659b2d63417e2c0b2a8c37c5
SHA-256: 70801c00cab845787b41110799d329228e77d0963af1460fff3e24ac72291168
Size: 142.40 kB - dotnet-runtime-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: 6b03059932c1e4b2f457655b688280fe
SHA-256: 0f0be4322054854a8e063ff2a9f779aa5688aeb96c8970d86d9fdc1e3336fba8
Size: 23.52 MB - dotnet-runtime-dbg-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: 077eeaee96626cea19627cbef6c842b6
SHA-256: 811efd9e8290afebef17e7947ffe4ca6203cd02b6bddaa8735c3ef372b8870c5
Size: 14.98 MB - dotnet-sdk-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
MD5: e64d3e5dae98ace60868f055bc9dc3e5
SHA-256: 622463b7c6448774d51bbce86dd34b3388f44de2f1a6b89f81755e98a1b0fd52
Size: 87.58 MB - dotnet-sdk-8.0-source-built-artifacts-8.0.129-1.el9_8.ML.1.x86_64.rpm
MD5: 6b31b0a358556547a51c24d34dc2c442
SHA-256: 7a255797692d7ac76c34378099ca7947df2b9f8a28f49e457ae0491d9df74ec2
Size: 652.65 MB - dotnet-sdk-dbg-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
MD5: df4b634ad61f404d475a03961148986b
SHA-256: 1e0f2432b88420819781c82a3981eee2ccd2ab3f8b2796f3a8490e43c98d4fe0
Size: 59.26 MB - dotnet-targeting-pack-8.0-8.0.29-1.el9_8.ML.1.x86_64.rpm
MD5: b6922a8175d2126d8538195c2cfb84cd
SHA-256: a2f1281547d6e3b23600b9f85238ed3839dffebe9762614a1e849c3091e24262
Size: 2.91 MB - dotnet-templates-8.0-8.0.129-1.el9_8.ML.1.x86_64.rpm
MD5: 687f405d16c3afb86995dbe4fad8183d
SHA-256: f67d01e77ecd440a00301df7615a44188bd9ad964f5eb94609d199f625e4ccca
Size: 2.08 MB