Red Hat Product Errata RHSA-2026:28009 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28009 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.118 and .NET Runtime 9.0.17. Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM dotnet9.0-9.0.118-1.el10_0.src.rpm SHA-256: 8ae7efb79c6fb0ef67253b929341d551806a4eb0d876c826f3ffe1db68e5eff9 x86_64 aspnetcore-runtime-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 9113966f8c3c28deaa3388a65a140967cc01865a2d20e7d2f97bfe34a4008713 aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 93b31b54b03014eb6c8f46d63eda1be6030e48601fbdb825c2dc002a7b1c0f37 aspnetcore-targeting-pack-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 7cfbb0320f4261ed14334317ab7cec0e23ae59d3fac17408fb9eaa1afbb85927 dotnet-apphost-pack-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 484d685d609810cb644296ea62e862d0052835fdcc90fac36d8cc83af5e87981 dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_0.x86_64.rpm SHA-256: 6438ea4150db122387e061d8e989b907af049a1cfe65fc94b9f452e446714304 dotnet-host-9.0.17-1.el10_0.x86_64.rpm SHA-256: ad02a2bbc5ba26296bbd53859319facd9d6e59d8907be224e9effd8577149af9 dotnet-host-debuginfo-9.0.17-1.el10_0.x86_64.rpm SHA-256: 8ed7f8c301ca61617fe3bd56501cca7037b51de73556aca0b9367ca729d8bc49 dotnet-hostfxr-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 7bdfc4825ebf8b934cce3c0c632138967ec021fe0d2b03699e5b7952d3232c3c dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_0.x86_64.rpm SHA-256: 32820317f663d0a1874fa2ca2e015837508bb862b419172078ad676b244d4197 dotnet-runtime-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 8e3cc76f5dad7113c9d8dde4780c97d957977b0f03a81330a9eb14537def56cc dotnet-runtime-9.0-debuginfo-9.0.17-1.el10_0.x86_64.rpm SHA-256: 499a57270efbba164993fe8248b01b252b942887b2588dc672cdbf96a69fdbfe dotnet-runtime-dbg-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: ff322f9e5f3d1171e6d332e43e4c0578c37d85e51b1e91ecd9703211ab3bf747 dotnet-sdk-9.0-9.0.118-1.el10_0.x86_64.rpm SHA-256: 4743f098bda4ed30b332219333abf69c920f37dbaeadb9f578f3cb1b40c4604d dotnet-sdk-9.0-debuginfo-9.0.118-1.el10_0.x86_64.rpm SHA-256: d94c4ee8417c80a14415e61178c4333f2eee7be0881367e18da9761e07f8b12a dotnet-sdk-aot-9.0-9.0.118-1.el10_0.x86_64.rpm SHA-256: 4b862ab1a234ab4c09798033b75c1d373a49ad443c18bae1f72f807310f678f6 dotnet-sdk-aot-9.0-debuginfo-9.0.118-1.el10_0.x86_64.rpm SHA-256: 925c8aa977c9091387362fee6326cecf6e284a8359aecea18a9354d43dab84c7 dotnet-sdk-dbg-9.0-9.0.118-1.el10_0.x86_64.rpm SHA-256: 665ef4d76c56d3d4c9c7bc5be34e649b2af460307a4f719cc500fb6eec9a308e dotnet-targeting-pack-9.0-9.0.17-1.el10_0.x86_64.rpm SHA-256: 2503d94eb9698d5f2588e45ceaf59a6d8f7bf4d678334bc46a4f3cac10df9e53 dotnet-templates-9.0-9.0.118-1.el10_0.x86_64.rpm SHA-256: 8d08742ca374a64423869da379172af6f40990337b096412d89d20292ab16d5f dotnet9.0-debugsource-9.0.118-1.el10_0.x86_64.rpm SHA-256: 20ad2dd93ce95e2bb0b079ee5927320cbe86cace1770069a08f5e5206d4095c7 netstandard-targeting-pack-2.1-9.0.118-1.el10_0.x86_64.rpm SHA-256: 28a1aeed2a1994cfe79d2f5162ed08ea5f160759e26b85940aa0703e855f46a1 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM dotnet9.0-9.0.118-1.el10_0.src.rpm SHA-256: 8ae7efb79c6fb0ef67253b929341d551806a4eb0d876c826f3ffe1db68e5eff9 s390x aspnetcore-runtime-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: 1fcd203ab2995b60379e840a9b838ce288f7ca1c4b277824e157564d48318a67 aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: 40cd6c50fa40f5d3ccb5dd93983dc114cb883a1b67e04cad2c6316c3f80efc2f aspnetcore-targeting-pack-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: d32fb284c3b65039b4bd141efb3001e58366445268754a66338bbc6447e8802e dotnet-apphost-pack-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: f0e6dc7c08263dcc45329f07ac1c7519db4ad95aa3128057afe80c77d03c637b dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_0.s390x.rpm SHA-256: 3563deb3d8159b6c7d22275432e3538fe0db853874f9db3ccd37a2bec4ccb3dc dotnet-host-9.0.17-1.el10_0.s390x.rpm SHA-256: 9fecf030033b0d3a9419a5873f52255f4773458c9d9e6741b39c21c1fba7890a dotnet-host-debuginfo-9.0.17-1.el10_0.s390x.rpm SHA-256: f5cd2cb7b5538370dfed8c85655415edf82d9a095feabb15213272c2390aa668 dotnet-hostfxr-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: cd3741398791e8ed5ffbe543df18086cf3282f6cd45858242d2d734c964e0954 dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_0.s390x.rpm SHA-256: ca2869f3e1cc352fd333a39fea41d062e8a1a35380a764cc7d56d221d174e166 dotnet-runtime-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: 4468bf0cc470baa81947a37fbd6168e93e1cfef151084ea0d805bd0d6c88acb0 dotnet-runtime-9.0-debuginfo-9.0.17-1.el10_0.s390x.rpm SHA-256: 0eb8c69c11ffd99e80def6e2581385555cebd2433c2f6cc020a2298ea4b1ab42 dotnet-runtime-dbg-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: 0c5e11779abc16d311856030f1b22efbd552c6fca6631df7127c734ff9556651 dotnet-sdk-9.0-9.0.118-1.el10_0.s390x.rpm SHA-256: db11b34413691d5de93639b8f14b3867e18ab0e7000016ecd2f2da89d778463f dotnet-sdk-9.0-debuginfo-9.0.118-1.el10_0.s390x.rpm SHA-256: 422c0e080a988489fddae7e13531fcf75b61ab564fb067fcf06d5f9c0b7cbf75 dotnet-sdk-dbg-9.0-9.0.118-1.el10_0.s390x.rpm SHA-256: 3531e06497dbd907d331968e838358916200f82a57f4192dcdb0b689ae3ffe30 dotnet-targeting-pack-9.0-9.0.17-1.el10_0.s390x.rpm SHA-256: ee57021b944a8b0b57d6a5db757e2bb480e3fe61dbda82a1587c4199e7488aa7 dotnet-templates-9.0-9.0.118-1.el10_0.s390x.rpm SHA-256: c63be80914e4948b3ae6cbf04e91d142c4bd68018c0ab05cf8c26d4a16b0f96a dotnet9.0-debugsource-9.0.118-1.el10_0.s390x.rpm SHA-256: a6492d42b9702a6d5267677f1aacbd25869b43bf66c60e96d5ec807454c5789d netstandard-targeting-pack-2.1-9.0.118-1.el10_0.s390x.rpm SHA-256: 67ae9514c420bbdb3fc10dee796a19ac70f51091e0bf7c1b46c92cfbf86d120b Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM dotnet9.0-9.0.118-1.el10_0.src.rpm SHA-256: 8ae7efb79c6fb0ef67253b929341d551806a4eb0d876c826f3ffe1db68e5eff9 ppc64le aspnetcore-runtime-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 7a7accf009d1844c14cc9f59c2d29ac1d26336b50f3abe76e1f0ab02578387a4 aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 29250799aeb24f7e6c1db905f9b9fb571c35ff6b629f327b77fe5cd9e435af71 aspnetcore-targeting-pack-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 40195f88ebda17b35e41e2f8f5f7ce987597221eecc6dbb6baedc30d153687fd dotnet-apphost-pack-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: a59d6f86c451c68613fbda910c7155fca85bdfd725e391424b1737a71e2e02b5 dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 16dc88bbbc6ad24a17950e9b363b3d4f16596dea137e3e2847d323de2f1cc37a dotnet-host-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 8ab5388e6a3bfbffe46f2a214883db4237c8b6590974a6a976d11597fe274ea5 dotnet-host-debuginfo-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 0e15f8071d5655aa50d8656b081490374d71c6c54ce946b354fefa09e6833279 dotnet-hostfxr-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: c384ca663ab2b61a74e2fbba309b534177656b808fabdb2ed7723ee0249cc5bc dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_0.ppc64le.rpm SHA-256: bc66f6de654d647c54a4f03a1e55b463b6389c47903fbc83643b8cdf58a75342 dotnet-runtime-9.0-9.0.17-1.el10_0.ppc64le.rpm SHA-256: bb757a934de22ea627ff3b51bab757a115249b96860bd278ce86587da57fe4ac dotnet-runtime-9.0-debuginfo-9.0.17-1.el10_0.ppc64le.rpm SHA-256: 21316453a34af5efe2fc7f718fec6dd0884f3ad63224b0adfbb574d5052816ca dotnet-runtime-dbg-9.0-9.0.17-1.el10_0.ppc64le.r
This Red Hat security advisory addresses two Important vulnerabilities in .NET 9.0 for RHEL 10.0 EUS: a local file tampering via link following flaw (CVE-2026-45491) and an ASP.NET Core denial of service via resource consumption (CVE-2026-45591). The vulnerabilities are fixed in .NET SDK 9.0.118 and .NET Runtime 9.0.17. Administrators should apply the update via the referenced Red Hat channels.