Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:41900: Important: .NET 10.0 security, bug fix, and enhancement update

This Red Hat security advisory addresses multiple Important-severity vulnerabilities in .NET 10.0 for RHEL 8, including denial-of-service flaws via HTTP/2 connection flooding (CVE-2026-50651, CVSS 7.5) and uncontrolled resource allocation, as well as privilege escalation and security feature bypass issues. According to NVD data, affected versions are .NET 10.0.0 through 10.0.5. The update provides fixes by upgrading the runtime to version 10.0.10 and the SDK to 10.0.110.
Read Full Article →

Red Hat Product Errata RHSA-2026:41900 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41900 - Security Advisory Overview Updated Packages Synopsis Important: .NET 10.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 10.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10. Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): Update .NET 10.0 to SDK 10.0.110 and Runtime 10.0.10 (JIRA:RHEL-192459) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM dotnet10.0-10.0.110-1.el8_10.src.rpm SHA-256: af961818ef0d531229ed6278c5e5b278592140650834cd5c75bb1ac5c82ae58c x86_64 aspnetcore-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: b36233a4c2ceada9854585337bac70162745bb6e891f60485e47cf024d447c29 aspnetcore-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: 0a32f54151760dba1f736c3ece7c25a8f4a8457d9e7e19c829d5728aecc0ed1f aspnetcore-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: c124e8fb6d2e882acba2116022ee8f02d368678ed6ae1cfbfac071f5bd30771e dotnet-10.0.110-1.el8_10.x86_64.rpm SHA-256: efe8220fabc024cfd22bda8dedd486d0876e6871b733adde34e48bfdf5134281 dotnet-apphost-pack-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: 045234591840cc4f09e178031828859803c83e3198ff57ca33a92d5545500008 dotnet-apphost-pack-10.0-debuginfo-10.0.10-1.el8_10.x86_64.rpm SHA-256: 215ee98b99367f18a4466917da76e72532ad5702cab55e466de8d140251aa4f2 dotnet-host-10.0.10-1.el8_10.x86_64.rpm SHA-256: eab2fe2b1734253ab816d71d04ebc503d2adcb12e0931f25a177bf56bdeb0002 dotnet-host-debuginfo-10.0.10-1.el8_10.x86_64.rpm SHA-256: cb4948e7dade9cce04e06af9cde9b216224e960cc5483dc10e26d771b5734d32 dotnet-hostfxr-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: cb0b78477761c6b582fd08297bd138a3ee18410acb58495348276bb24ba691ad dotnet-hostfxr-10.0-debuginfo-10.0.10-1.el8_10.x86_64.rpm SHA-256: 6ee34be9ce0580fb01f9316b70b3acd7eb22a96ea982447adbfd2454fa239f8b dotnet-runtime-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: 09e03ad8dbbd74da8f15bc1709e0d6f87c5de7f1f698db5adb8462f9ddba9708 dotnet-runtime-10.0-debuginfo-10.0.10-1.el8_10.x86_64.rpm SHA-256: d52b570b32682c2fafd280fe38f668d57d6ecbb5b1014936db315ecd4ef85570 dotnet-runtime-dbg-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: 2fc8041ee5ef58b815232d6af7cc3e81cb6802d323b3c85e73828f656f77cc34 dotnet-sdk-10.0-10.0.110-1.el8_10.x86_64.rpm SHA-256: 4a34c57cde425fa3686ab704c05e7969f18b172f220dfcb32690fbdfbddc9647 dotnet-sdk-10.0-debuginfo-10.0.110-1.el8_10.x86_64.rpm SHA-256: e69ebb1bd30503b07f87547863c126a0d88d663c12d26db4b6e839ff67fe1b38 dotnet-sdk-aot-10.0-10.0.110-1.el8_10.x86_64.rpm SHA-256: 27e892d0137bac5384ee5818d15da66b013162749cb6ae2790c1eccaa3c7df6c dotnet-sdk-aot-10.0-debuginfo-10.0.110-1.el8_10.x86_64.rpm SHA-256: 77bd5a85c8e0909b078b94554dba4a4a58838933ba9dea44bf570d965822e0bd dotnet-sdk-dbg-10.0-10.0.110-1.el8_10.x86_64.rpm SHA-256: 489389f67930a0170bfa012e20116c6034f433eb51c1e23d187d9bc71dc6fb7f dotnet-targeting-pack-10.0-10.0.10-1.el8_10.x86_64.rpm SHA-256: cfb41a6f5da32c1177b3516d1f44124203116bd2accbfb4a3a80e22ed3fbf654 dotnet-templates-10.0-10.0.110-1.el8_10.x86_64.rpm SHA-256: 418a571ad48e468c891f83cd345b8c50acd561dceff2b2114ed68b5f5696d333 dotnet10.0-debuginfo-10.0.110-1.el8_10.x86_64.rpm SHA-256: 360f156769bf98d64ba25c57492d78d90896875ed4c1c274a9105aa07d4e5be2 dotnet10.0-debugsource-10.0.110-1.el8_10.x86_64.rpm SHA-256: 55a40b95c0241c49e4ecb92a718a186b490b0bd74703ecc1cee9375f87026dc7 Red Hat Enterprise Linux for IBM z Systems 8 SRPM dotnet10.0-10.0.110-1.el8_10.src.rpm SHA-256: af961818ef0d531229ed6278c5e5b278592140650834cd5c75bb1ac5c82ae58c s390x aspnetcore-runtime-10.0-10.0.10-1.el8_10.s390x.rpm SHA-256: 5c54707993ee5f50defb4d877e014f783545fcfa88ff90ee87eb10a914a354d4 aspnetcore-runtime-dbg-10.0-10.0.10-1.el8_10.s390x.rpm SHA-256: 284a73b1ce66cef5cb0bc23878faf370e33f910d4f22b38f42f447a086b3606b aspnetcore-targeting-pack-10.0-10.0.10-1.el8_10.s390x.rpm SHA-256: 39f40273e758d248dc3e9a61b7d537b08abee9bc48eb63f22347b6a1f6da95d7 dotnet-10.0.110-1.el8_10.s390x.rpm SHA-256: f847c4c82361c6f27b57595e71d766e2f73459caad30147fc0a7c10001f174c3 dotnet-apphost-pack-10.0-10.0.10-1.el8_10.s390x.rpm SHA-256: e3b49f642c12a804abce1f12a8f2e2972e5ac6a20f4bd57a961fbfdf631eae92 dotnet-apphost-pack-10.0-debuginfo-10.0.10-1.el8_10.s390x.rpm SHA-256: 106c39cf7520447bae930fe97f751f2fb72323a22e8fc9809d8b0d5f7b441b3e dotnet-host-10.0.10-1.el8_10.s390x.rpm SHA-256: fc71dc59729c0a8f80cf04eab1a150923fc1b9232b11f609447c5273f0771c9b dotnet-host-debuginfo-10.0.10-1.el8_10.s390x.rpm SHA-256: 6ba6a0786ce5af0c7d737eb3527db218771452df3b0bc73b0f9fd5add4864b3e dotnet-hostfxr-10.0-10.0.10-1.el8

Share this article