- What: Security update for .NET 9.0 in Red Hat Enterprise Linux
- Impact: Systems using .NET 9.0 need to apply the update
Red Hat Product Errata RHSA-2026:41896 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41896 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 [rhel-9.8.z] (JIRA:RHEL-192472) dotnet9.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:RHEL-192338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM dotnet9.0-9.0.119-1.el9_8.src.rpm SHA-256: 0c3dd3b9c0cf5170837b6538142850fb639822295bfa2f4585b5137820d259a2 x86_64 aspnetcore-runtime-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: 4cd2c6bf59b36dece9422a279c3983d5547fab98a0a5227f766a0dc05066b885 aspnetcore-runtime-dbg-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: d6204f2202173f461a972e7b7266c3520a7bda858e88cb991c170639261c1b6f aspnetcore-targeting-pack-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: 768abaa88c6e8d1f44735bd15989a7f46a0711863d91c0896d42e3b3eff9b42e dotnet-apphost-pack-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: 62e5afaa02177ba607e4beb3c91a855615cea4e88beecfe134cf1eeb3fb1f8cd dotnet-apphost-pack-9.0-debuginfo-9.0.18-1.el9_8.x86_64.rpm SHA-256: 977d71a21c9b80ca9f1e65782d0c23dab5f5b40c84fc76be61ce326d59a22b6b dotnet-hostfxr-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: cbf3a10fc0f4f8f256fbfb9bd82fe08797d8a2af53363b8a1b4a5168de280b44 dotnet-hostfxr-9.0-debuginfo-9.0.18-1.el9_8.x86_64.rpm SHA-256: d87bf574dcb16f89982942c893e86bdafd9ebd1b77105726d792caad31357c9a dotnet-runtime-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: 18ee70cf3525d18d385224b8b37159046416219cad70d722199cbc0749b4ddda dotnet-runtime-9.0-debuginfo-9.0.18-1.el9_8.x86_64.rpm SHA-256: 02217031a43d5bb28ab73b9a7c84a12f7768fc9339ab0c53fe2cba47cc9d3adc dotnet-runtime-dbg-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: db60811a5f8508dca4cbfecab40e7e28d76092c092c5e37da401463dcb878b9a dotnet-sdk-9.0-9.0.119-1.el9_8.x86_64.rpm SHA-256: a6521585484611a6cb9aa33a4cea6982810272fb055952c92d511e13745ebd25 dotnet-sdk-9.0-debuginfo-9.0.119-1.el9_8.x86_64.rpm SHA-256: fc66399b6b069e135ae8850e0c488051ca42a1116089411625a973b142631003 dotnet-sdk-aot-9.0-9.0.119-1.el9_8.x86_64.rpm SHA-256: 731d3603416f633067c67170cadc51dc6b22988a3b8214987ad56e0553cbd2c2 dotnet-sdk-aot-9.0-debuginfo-9.0.119-1.el9_8.x86_64.rpm SHA-256: bfa976539f675b3b11365a41b107f343167484b9543a6d5f1a4d7d7662b3c957 dotnet-sdk-dbg-9.0-9.0.119-1.el9_8.x86_64.rpm SHA-256: 5926e256a8e16410706c7f55bde1ffe068034469721c9637c28f89d3ce7d9f8c dotnet-targeting-pack-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: ed2d840bdb96f98955896fcf9e094af43aa4d1685e8b6df6adb278755ae0cdd7 dotnet-templates-9.0-9.0.119-1.el9_8.x86_64.rpm SHA-256: 9a3ca60fdadf8bbf437c917279904be3fc2ad18d36638eb4decd61f1734a1697 dotnet9.0-debuginfo-9.0.119-1.el9_8.x86_64.rpm SHA-256: 51299b2bc1e4672c8c176e5df39e1e1b6b98ed2e6353496ed5e375c3a4647a19 dotnet9.0-debugsource-9.0.119-1.el9_8.x86_64.rpm SHA-256: 5d8e2e85df211ac9eb1133993a54d743b244b397bfbc37cba5936a86657d3438 netstandard-targeting-pack-2.1-9.0.119-1.el9_8.x86_64.rpm SHA-256: 5531f3dd1b085bda5f6bc502b8b2b772c749fa575d9c485682533b8377359b98 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM dotnet9.0-9.0.119-1.el9_8.src.rpm SHA-256: 0c3dd3b9c0cf5170837b6538142850fb639822295bfa2f4585b5137820d259a2 x86_64 aspnetcore-runtime-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: 4cd2c6bf59b36dece9422a279c3983d5547fab98a0a5227f766a0dc05066b885 aspnetcore-runtime-dbg-9.0-9.0.18-1.el9_8.x86_64.rpm SHA-256: d6204f220217