- What: Security update for .NET 8.0 in Red Hat Enterprise Linux
- Impact: Systems using .NET 8.0 need to apply the update
Red Hat Product Errata RHSA-2026:41894 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41894 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 [rhel-9.8.z] (JIRA:RHEL-192467) dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:RHEL-192337) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM dotnet8.0-8.0.129-1.el9_8.src.rpm SHA-256: f089d2b4857eba712c5c4f97cd7ef8f5f7f0b1eb23c24458df3907f1015f1db0 x86_64 aspnetcore-runtime-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: d6ac0d2f3dcbee0c1bc0b5c837909bf931d84b80532b8bc764a8c6be9f7f8075 aspnetcore-runtime-dbg-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: 17f3b797b45859d71ed7db3d547a537147d7e08806e630c8082740c1322e942f aspnetcore-targeting-pack-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: efbfd9703d837466b383e949cd495be11c169b7ca0fc96d83dd556bb1a8cc232 dotnet-apphost-pack-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: 501293db8acd69f4835b1f91c6c28dc2f9a6ce7a0df88e9dc7d728f2edb6c9ea dotnet-apphost-pack-8.0-debuginfo-8.0.29-1.el9_8.x86_64.rpm SHA-256: 8da37f35dde6b50f5a1da0ce1f5d6c98fede001867d5d5b390bbb10fe972fac4 dotnet-hostfxr-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: 9df8a7bc4c82458ec31341f71dd505d387b86fc5d2e2aa5f4d67892538f3f316 dotnet-hostfxr-8.0-debuginfo-8.0.29-1.el9_8.x86_64.rpm SHA-256: 00b9e47dbf30abebd2a9aa1dc51cd0be1577ef06e8f19d7832c7f885b548bc91 dotnet-runtime-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: f67b9fd5c6b2bea25e07908918bedabab021df11a856e1a8793f11c948658ae1 dotnet-runtime-8.0-debuginfo-8.0.29-1.el9_8.x86_64.rpm SHA-256: 1d17c7d2209a01af8298fa28fbb371aea8d74b4971ff04f60870e4b17665a01f dotnet-runtime-dbg-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: ccb79a872b900d131a14f7f766e1c27b745fd8601a43f04f2248841e6c9e9182 dotnet-sdk-8.0-8.0.129-1.el9_8.x86_64.rpm SHA-256: d21ed84747eb8fea976f7ba6229c853a81e8336f8d5424d2b6b0e89dc49448a2 dotnet-sdk-8.0-debuginfo-8.0.129-1.el9_8.x86_64.rpm SHA-256: de3898759e444c942cbff26b79e17e3c0848f934e394858a4ae68eae063f1a16 dotnet-sdk-dbg-8.0-8.0.129-1.el9_8.x86_64.rpm SHA-256: a332ec218d816fcb967600ca3ae29a5c16ff1a4d7da8f41027340604fa0a662b dotnet-targeting-pack-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: e410ec7f475d65e0d47c37d1ba5abb60351ef88a0802d7d9992c7642657d4ce9 dotnet-templates-8.0-8.0.129-1.el9_8.x86_64.rpm SHA-256: f50f1cc8ed613d87271951726f6bd5968fb276c6d3ccc71a64e20a3435936cbf dotnet8.0-debuginfo-8.0.129-1.el9_8.x86_64.rpm SHA-256: 264b0b5d38eb345de204fbeff3f3382bf4dde498869d63d5be2f3a9bedca7ca6 dotnet8.0-debugsource-8.0.129-1.el9_8.x86_64.rpm SHA-256: e069e17865e99129c25385412fc3204c834f0d7fcad3b885624e5a1bdf96f232 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM dotnet8.0-8.0.129-1.el9_8.src.rpm SHA-256: f089d2b4857eba712c5c4f97cd7ef8f5f7f0b1eb23c24458df3907f1015f1db0 x86_64 aspnetcore-runtime-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: d6ac0d2f3dcbee0c1bc0b5c837909bf931d84b80532b8bc764a8c6be9f7f8075 aspnetcore-runtime-dbg-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: 17f3b797b45859d71ed7db3d547a537147d7e08806e630c8082740c1322e942f aspnetcore-targeting-pack-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: efbfd9703d837466b383e949cd495be11c169b7ca0fc96d83dd556bb1a8cc232 dotnet-apphost-pack-8.0-8.0.29-1.el9_8.x86_64.rpm SHA-256: 501293db8acd69f4835b1f91c6c28dc2f9a6ce7a0df88e9dc7d728f2edb6c9ea dotnet-apphost-pack-8.0-debuginfo-8.0.29-1.el9_8.x86_64.rpm SHA-256: 8da37f