Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:41901: Important: .NET 8.0 security, bug fix, and enhancement update

  • What: Security update for .NET 8.0 in Red Hat Enterprise Linux
  • Impact: Systems using .NET 8.0 need to apply the update
Read Full Article →

Red Hat Product Errata RHSA-2026:41901 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41901 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 (JIRA:RHEL-192464) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM dotnet8.0-8.0.129-1.el8_10.src.rpm SHA-256: 805d2ef008e07642ca1b979b8ed3db08842e5f2880aac075e4f5d69d993024e3 x86_64 aspnetcore-runtime-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: c725b8e0f2924745c5a0fe321b506a2eccc97ad850f4d8e204f0b058e4abd8fc aspnetcore-runtime-dbg-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: 282d3150632242538daa2ed1d7d3d38324455269f57834204e2f0e69bc424542 aspnetcore-targeting-pack-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: ea7c3f9c98e763d2f0724f50cf405bd0d708db92e688258780e4680f90d95529 dotnet-apphost-pack-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: f4c70e5a2be155b6d23a9e2bb79d673d5111f95310106da745134ede243a4761 dotnet-apphost-pack-8.0-debuginfo-8.0.29-1.el8_10.x86_64.rpm SHA-256: 9a6a3098405be07109e7634b17df40b96eaf6064814f22541ed033a7e421ccde dotnet-hostfxr-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: e4b2a81c37ac7264b74f3a6be075ebfaeea79d8d6f2a3dc365f550599c8740f3 dotnet-hostfxr-8.0-debuginfo-8.0.29-1.el8_10.x86_64.rpm SHA-256: 202f4209acfe43ea799a9a5a2a8404514da369ddaf5ca294c806d28ed195343a dotnet-runtime-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: a7929191c1ef926cf49e861b159439ad00b9275d77b5e6ca2c6c1b3f6401057c dotnet-runtime-8.0-debuginfo-8.0.29-1.el8_10.x86_64.rpm SHA-256: 42fbe2f5c5701bd93e2a049f412240b0690cb50000a6359aa9dcf4fb03073478 dotnet-runtime-dbg-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: bae4088a703e7cdffb8e684710d414955b95c2aed044acb97611cf0831bc12d8 dotnet-sdk-8.0-8.0.129-1.el8_10.x86_64.rpm SHA-256: 20b19569530d22f81d7c97f7bc5803c0e521c9ce812e682a52d468cef9f4f23a dotnet-sdk-8.0-debuginfo-8.0.129-1.el8_10.x86_64.rpm SHA-256: a8a34a0da4bffecbfefb8b256b975057cacbf1f79717dcfb68168132f895a659 dotnet-sdk-dbg-8.0-8.0.129-1.el8_10.x86_64.rpm SHA-256: 897bb097591127baca568e962e12ce98b4cb2a3324f291842d17e08b69764d55 dotnet-targeting-pack-8.0-8.0.29-1.el8_10.x86_64.rpm SHA-256: 12d89c73d06729db5ded762bdb80b24131e59c842181340943c16791c87e42fc dotnet-templates-8.0-8.0.129-1.el8_10.x86_64.rpm SHA-256: b0c1630907ce9e83cfa98f63a72626db6857c50455190803dda6a43c9c7cb661 dotnet8.0-debuginfo-8.0.129-1.el8_10.x86_64.rpm SHA-256: d25cbc045f999a9c2325167ac98d6f09e4d597246287593325ea1e9a142952dd dotnet8.0-debugsource-8.0.129-1.el8_10.x86_64.rpm SHA-256: 57bd50ea2cd6b74104917b22ee7a5aea83009017ff34a39746c6f090b130e41d Red Hat Enterprise Linux for IBM z Systems 8 SRPM dotnet8.0-8.0.129-1.el8_10.src.rpm SHA-256: 805d2ef008e07642ca1b979b8ed3db08842e5f2880aac075e4f5d69d993024e3 s390x aspnetcore-runtime-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 04d1fb119c6858fe0acf8071c1719131c269f81ed4d7840cdc2f2e9900f04b45 aspnetcore-runtime-dbg-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 9d37116beafef037646dbf8badfc0f2dce830786620d83abb075de00d0be16eb aspnetcore-targeting-pack-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 49dff2b748321745a131080dbf360f0dc34c477933d9a3557795e908c7f61477 dotnet-apphost-pack-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 352c46c3c9e185c70c3346dae080644adc85e258dad5bcd6b9e2b1be45220f79 dotnet-apphost-pack-8.0-debuginfo-8.0.29-1.el8_10.s390x.rpm SHA-256: 5bfd27e7e47c88f715bbf8672b1d41c836ff7f1dfd30548c984cfd7037db84d7 dotnet-hostfxr-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 82b8f7cbe3de8bbc961d4437c418bc89c79878e1c3dfbb24ae7d98c3432ffc8a dotnet-hostfxr-8.0-debuginfo-8.0.29-1.el8_10.s390x.rpm SHA-256: 37b2aecddfa42181f7fd7b9451d057142725c24410e7c005ae005554f71b544f dotnet-runtime-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 3eb8441e5ee733ec8ae4f7af3fe368aca9b3335a0d6a3a28f4ccd007fa2fdbe1 dotnet-runtime-8.0-debuginfo-8.0.29-1.el8_10.s390x.rpm SHA-256: 0e23546be8bf83bf4d1beb07d49beb0dd689fcab2037500e5b1ae8659e728575 dotnet-runtime-dbg-8.0-8.0.29-1.el8_10.s390x.rpm SHA-256: 8cb1f6e43cb9c6e425c7edc4b1a559d4ca8d38c0dd726b42758eb42e19072f36 dotnet-sdk-8.0-8.0.129-1.el8_10.s390x.rpm SHA-256: 89813fa20d88d749051f86fbc9bfea2d2c3b4043f56cd681c5a86683c20750c6 dotnet-sdk-8.0-debuginfo-8.0.129-1.el8_10.s390x.rpm SHA-256: 734d8d21a762052abd27dc0d0227b89d821b11918772e1ac00ae841822858494 dotnet-sdk-dbg-8.0-8.0.129-1.el8_10.s390x.rpm SHA-256: 03051823fe2fcd6ddeac93aac14ca915d8e6a1b1f86e1e0b0fb6f00f4f456706 dotnet-targeting-pack-8.0-8.0.29-1.el8_10.s390x.rpm SHA-

Share this article