dotnet9.0-9.0.119-1.el9_8.ML.1
エラータID: AXSA:2026-1557:15
リリース日:
2026/08/18 Tuesday - 16:05
題名:
dotnet9.0-9.0.119-1.el9_8.ML.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- .NET には、多数の脆弱性があります。
CVE-2026-47300, CVE-2026-47302, CVE-2026-47303, CVE-2026-47304
CVE-2026-50524, CVE-2026-50525, CVE-2026-50526, CVE-2026-50527
CVE-2026-50528, CVE-2026-50646, CVE-2026-50648, CVE-2026-50649
CVE-2026-50650, CVE-2026-50651, CVE-2026-50659, CVE-2026-56170
CVE-2026-57108
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50649
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
追加情報:
N/A
ダウンロード:
SRPMS
- dotnet9.0-9.0.119-1.el9_8.ML.1.src.rpm
MD5: ad469f2781f375dd4de52ccb26fe65a8
SHA-256: 0310f4aa3db325aa87becd2a16e7c44ce41ea859344b1c6d9240adbe990ccf56
Size: 466.99 MB
Asianux Server 9 for x86_64
- aspnetcore-runtime-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: 267a71d980bb527682076cebaeef4496
SHA-256: 423dfcd2f103e7a9190a0e7143965380d455520a4b04a2574e999ee9b55ca4e4
Size: 7.78 MB - aspnetcore-runtime-dbg-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: a137a8c505aed3a77f8d22667334ea28
SHA-256: 0365d2f75b5ed73a7c9654ea24d7ea4d764cce15946d7a82410bb2baed6153e7
Size: 1.63 MB - aspnetcore-targeting-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: 063351018dd4175ab5a1c4680405a059
SHA-256: c85df1cefd7d5763b7ff88edf86f118c2e8ecc2576ea823e4c4b71cea062adb7
Size: 1.92 MB - dotnet-apphost-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: 19923c2ba0c8e7b6d8e0261a427410e5
SHA-256: e16f72e02306f9c759d288008885400202e7a4775e7dbc6dd4c8bd5aed511366
Size: 3.82 MB - dotnet-hostfxr-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: ffb05ba882111ee667ea9793c3a2caf4
SHA-256: be8fa511560da0bb461d8bebee92a0c8a288e88e8b12450a916638bc6b4b9016
Size: 143.73 kB - dotnet-runtime-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: 1898890ae6873dcd805566a1dea34e60
SHA-256: 1c9069fb2467b2c5c0347df7a782ed14feb65185cdc18280fc40b2bd7bfdd7e0
Size: 24.32 MB - dotnet-runtime-dbg-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: f4b4e84cccaf57162bf59dd43ffdab3f
SHA-256: 726aa85625eb2a3483099a37aeef585d77ad896c5fc9d9dad2796d59941101f2
Size: 3.16 MB - dotnet-sdk-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: faef508c82ae92e4f1c962069cb3cfab
SHA-256: d05082d5b5d850f4b9ab0855113a5a092996417c5c0b65e949b07ed068b3d968
Size: 81.91 MB - dotnet-sdk-9.0-source-built-artifacts-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: c53a553e1fe1c15f9f3d621aeefbe868
SHA-256: 87af224ff2b05583869ce949944285b6a255f2e355517fa381def04b867d17b3
Size: 772.62 MB - dotnet-sdk-aot-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: e7b59686113f2940e4aa4478dcdbff41
SHA-256: 61c5b7e8677d433f39cdcfd65e2a0ccbe2f6ec91aa242676692715779b13df4a
Size: 15.98 MB - dotnet-sdk-dbg-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: eb17f4e1ae098e60210fe767ed702f73
SHA-256: ecdce548ead3a37bd9538b5a9bc81cbcc38ca29b25b839533467b9c30b6f456b
Size: 15.43 MB - dotnet-targeting-pack-9.0-9.0.18-1.el9_8.ML.1.x86_64.rpm
MD5: b29ccff25357f9ca1e2feb4780e7753b
SHA-256: 015d472f03b41c5e35529c0202472c3629d2e9e711d7a36c29572210979e8a99
Size: 3.03 MB - dotnet-templates-9.0-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: c216d36fdfd234071f035e0163cb38f9
SHA-256: 1f9cea665c7c9348df87e007b42e351f06cc661e43acf07cfdec03215b28d755
Size: 2.57 MB - netstandard-targeting-pack-2.1-9.0.119-1.el9_8.ML.1.x86_64.rpm
MD5: 46e265b0b229ade53018463cee5879da
SHA-256: b243262ca43cf0477ef00ec26923b7405e7ce6f2f6e94bdafcced02bd7382af5
Size: 1.35 MB