- What: Security update for .NET 9.0 in Red Hat Enterprise Linux
- Impact: Applications using .NET may be vulnerable
Red Hat Product Errata RHSA-2026:58570 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58570 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. SDK version: 9.0.120 Runtime version: 9.0.19 Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet9.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.6.z] (JIRA:RHEL-192335) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500589 - CVE-2026-50659 .NET: .NET: Network Spoofing Vulnerability BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation BZ - 2512175 - CVE-2026-62899 .NET: .NET Core: .NET Security Feature Bypass Vulnerability BZ - 2512179 - CVE-2026-62900 .NET: .NET Information Disclosure Vulnerability BZ - 2512180 - CVE-2026-62901 .NET: .NET Denial of Service Vulnerability BZ - 2512185 - CVE-2026-62909 .NET: .NET Elevation of Privilege Vulnerability CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 CVE-2026-62899 CVE-2026-62900 CVE-2026-62901 CVE-2026-62909 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM dotnet9.0-9.0.120-1.el9_6.src.rpm SHA-256: 00917f41c3ff3646fa968b2430ada347ff3cc905cce9edd65f714ecd67c73455 x86_64 aspnetcore-runtime-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 48e7abc1fb46489dd219fbaf352de0e809f95cd8dbedbc3d8c5bd842f5ae3307 aspnetcore-runtime-dbg-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 18760da31e95474faa3843c84173ca3805cdc1f47121725673d94c81af3c3dbb aspnetcore-targeting-pack-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: e19f9b024b3fc282aba563a4ea5cc5a2995f26b8e5f2001228027fb9d0fe6524 dotnet-apphost-pack-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 305ff3d50cee70b7e374286e2a9f051d2cc1d932eb784922537a81410bfcc271 dotnet-apphost-pack-9.0-debuginfo-9.0.19-1.el9_6.x86_64.rpm SHA-256: c5983ebe6b5687bd79ea5e5dce8d806bbcee24c7d65e2bae8f8e5514db3539da dotnet-host-9.0.19-1.el9_6.x86_64.rpm SHA-256: 079c83b4bb23602d29dc5c3c07f84d2645de7b8cdafc671029282a35cc316c09 dotnet-host-debuginfo-9.0.19-1.el9_6.x86_64.rpm SHA-256: 192852ca627420dd4430d27262321efe33b74eadf6563050b766660cbe75bf91 dotnet-hostfxr-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 3eabd81353450268250d16b754ec2712bd81e7e4aef6064313efb325b0727f15 dotnet-hostfxr-9.0-debuginfo-9.0.19-1.el9_6.x86_64.rpm SHA-256: 41b202da41ac6357182b5810876d56da9746910f56abda08df611caf0432e915 dotnet-runtime-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 188b359a0be3b5ec4b950f76455f66b6e4e224fe1222670b794b1539edc2bf1f dotnet-runtime-9.0-debuginfo-9.0.19-1.el9_6.x86_64.rpm SHA-256: 158eddb66c17bcb34c8ee8e8e3e282c65ded923b6c99c69bbb587006790c5ff5 dotnet-runtime-dbg-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: c9de230b953f90523364f6704da1208280a2be2e871f9a936d7834278060c70d dotnet-sdk-9.0-9.0.120-1.el9_6.x86_64.rpm SHA-256: a81963f9497433c0bb89629581dcda8c20c7141c7ec33f5c65dedd9bbe13f9d3 dotnet-sdk-9.0-debuginfo-9.0.120-1.el9_6.x86_64.rpm SHA-256: 7efd445523f80c964b175cf49dbbc5882a54bfaad34e52a5a3ca6bbbe52c6878 dotnet-sdk-aot-9.0-9.0.120-1.el9_6.x86_64.rpm SHA-256: 8be72db104a53b9962994ed5ce46f9898cc5e83d68623b4395f3d43aabdece59 dotnet-sdk-aot-9.0-debuginfo-9.0.120-1.el9_6.x86_64.rpm SHA-256: 46641ce6bc2379ff109c6f48b05071ecce85f5e7e1fff1012728fbbd9a060d53 dotnet-sdk-dbg-9.0-9.0.120-1.el9_6.x86_64.rpm SHA-256: 27a48327856f89489bbefec55cf49d34f954771aaa167cfb85293b4cf3325798 dotnet-targeting-pack-9.0-9.0.19-1.el9_6.x86_64.rpm SHA-256: 9db71d38b21ca237f55d0c95e6fd16b4b97f72db855ac1151bd9586cc3c85aac dotnet-templates-9.0-9.0.120-1.el9_6.x86_64.rpm SHA-256: d4918700719c8d38875c1158f23e9422db25a67036144af2e5b08b5e2686b60e dotnet9.0-debuginfo-9.0.120-1.el9_6.x86_64.rpm SHA-256: 15fb52a01103c3ebeb506abd1f