Red Hat Product Errata RHSA-2026:41899 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41899 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 (JIRA:RHEL-192469) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM dotnet9.0-9.0.119-1.el8_10.src.rpm SHA-256: dccccba83912f759832c39968602979e8bb2e3de0151fd2d6c25a5a01ef2ba0d x86_64 aspnetcore-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: 549be337d87bbb0d44b672842f68981669658c9227e1459a2dfd81d570de8063 aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: a493b399b7e978492a8904f46ba8ac1ea6571009ebbe7845c68a75bac2ed2113 aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: a401d8928b4ac9c92fffbc6c751276c0fecc91743c66953315d9913e17625f57 dotnet-apphost-pack-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: a57a538bf1823923e3f9666d138b52cf8ba072bf13d281236c3af559666e4a6e dotnet-apphost-pack-9.0-debuginfo-9.0.18-1.el8_10.x86_64.rpm SHA-256: 84a94e49d98a23d8d2117de0ded3abd47a90914e317ee0dbd854a6638c5adfbe dotnet-hostfxr-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: f916a2b3c0a6058efa29ae88e438213de0cc2184de0c7d507dc9d4c8f8592c41 dotnet-hostfxr-9.0-debuginfo-9.0.18-1.el8_10.x86_64.rpm SHA-256: 9c33298f78dd22bc8563a564d1d51245f1f7d181ace524e433a3f0a922db04f2 dotnet-runtime-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: 2e45c09e9c90b98ae915d5616bf36142e141c4389324ea5751e171768274cf22 dotnet-runtime-9.0-debuginfo-9.0.18-1.el8_10.x86_64.rpm SHA-256: 9ca50ee4184049591009aa560a03bdf02afedd373bca0fe52d337ba981476ba3 dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: f6ef664036b34241acabdbc5f47b188debca34db6ed31cab86c07b66df0056b6 dotnet-sdk-9.0-9.0.119-1.el8_10.x86_64.rpm SHA-256: c8b9aab789979fa58c86b3fe029d1896fd668d7d8b8bf2791d59e625ff8c05a5 dotnet-sdk-9.0-debuginfo-9.0.119-1.el8_10.x86_64.rpm SHA-256: 1494d1b9b8da10d6eb2da5f5604b2bf4bf958f5825206dd18d3e03918f941a81 dotnet-sdk-aot-9.0-9.0.119-1.el8_10.x86_64.rpm SHA-256: bc4f08231bcf2c1738200f12ef846cfcba0b6bd845d3f46d37f2c159475f93ef dotnet-sdk-aot-9.0-debuginfo-9.0.119-1.el8_10.x86_64.rpm SHA-256: 97f851e86561c4132e70c7a95c0f31dd1a3daae343b13e6f2f9e9113f55390b2 dotnet-sdk-dbg-9.0-9.0.119-1.el8_10.x86_64.rpm SHA-256: a2326e30df6c99acfb9d0e03aa2e8316cada02a16cea1cf34ff61a40d2f210d8 dotnet-targeting-pack-9.0-9.0.18-1.el8_10.x86_64.rpm SHA-256: 95f77be447b5008373b5f6139c3fc595d0b721dce212a0b9685c36c03cb415b4 dotnet-templates-9.0-9.0.119-1.el8_10.x86_64.rpm SHA-256: 0f794b0c7bd910ef1c56b833635ba82d8ca80c083abd87dde0ebb3dbdf26dde1 dotnet9.0-debuginfo-9.0.119-1.el8_10.x86_64.rpm SHA-256: 303121c497782fe365f4dda8e76ae6710fe8f3e3cc828087bae57f273e03915a dotnet9.0-debugsource-9.0.119-1.el8_10.x86_64.rpm SHA-256: 9c2651a5b8ac0aa985c648dbc5fe2e461fd6f13fd28a39f4e90e04ea9bf65ead netstandard-targeting-pack-2.1-9.0.119-1.el8_10.x86_64.rpm SHA-256: 083864ddd64272b29ae53a35dee8e7d73a969c22e4c090c39c6a85d3d4a4d133 Red Hat Enterprise Linux for IBM z Systems 8 SRPM dotnet9.0-9.0.119-1.el8_10.src.rpm SHA-256: dccccba83912f759832c39968602979e8bb2e3de0151fd2d6c25a5a01ef2ba0d s390x aspnetcore-runtime-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: 4ca628ec71e674cd3d63535f6ec6565c78d3dacf18faf83e13da6d7888ec8485 aspnetcore-runtime-dbg-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: c26773a0b60f3a1eb1caef20e664fa6b3a691dc0e232dba6eb1949ed192315fc aspnetcore-targeting-pack-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: c177e98644b9a546c80726e6b929bfefcc9cbde053e779082d7b1db2524ed1f7 dotnet-apphost-pack-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: 7e0ceffb0762b8bbe93540a46d686d9600f648e120f5a6cd8b8512bca241ecd8 dotnet-apphost-pack-9.0-debuginfo-9.0.18-1.el8_10.s390x.rpm SHA-256: 328d849ac6ded9a4b4fd10b8a31721d982430ce0b09aea4093cc122f7753673b dotnet-hostfxr-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: 3efeb106a0c8ada248ab346ef7abbc42a8e8a9dcfd0732f1a6ed7373268dca0e dotnet-hostfxr-9.0-debuginfo-9.0.18-1.el8_10.s390x.rpm SHA-256: 69482e3336b6adf699d3c64ac6daf4b3c3e9d6f29ab76babf213ea3c721e7d42 dotnet-runtime-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: 61153ba4ab2c14fa7738664f6c4744b1ef761947d996e55eedb379f3ffdb4796 dotnet-runtime-9.0-debuginfo-9.0.18-1.el8_10.s390x.rpm SHA-256: 7bf8d83c4bac5bc66acaee35a58607996691d68231a20d2b8f2f8340ac4d59f7 dotnet-runtime-dbg-9.0-9.0.18-1.el8_10.s390x.rpm SHA-256: ade4f709a3eabc170166736990dd5bbffda16e4624df907424b3d2385a621c3f dotnet-sdk-9.0-9.0.119-1.el8_10.s
This Red Hat security advisory addresses multiple vulnerabilities in .NET 9.0 for RHEL 8, including Denial of Service (e.g., via HTTP/2 flood, uncontrolled resource allocation), Privilege Escalation (via authentication bypass), and Local Code Execution (via deserialization). The update is rated Important and patches these flaws by updating to .NET SDK 9.0.119 and Runtime 9.0.18. Affected versions are .NET 9.0.0 through 9.0.17, as confirmed by NVD data for CVEs like CVE-2026-50651 (CVSS 7.5 High).