- What: Security update for .NET 8.0 in Red Hat Enterprise Linux
- Impact: Applications using .NET may be vulnerable
Red Hat Product Errata RHSA-2026:58569 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58569 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. SDK version: 8.0.130 Runtime version: 8.0.30 Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.6.z] (JIRA:RHEL-192334) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2499217 - CVE-2026-50651 dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM BZ - 2500109 - CVE-2026-57108 dotnet: .NET Core: Denial of Service via type confusion BZ - 2500189 - CVE-2026-56170 ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation BZ - 2500492 - CVE-2026-47300 ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm BZ - 2500502 - CVE-2026-47303 ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass BZ - 2500509 - CVE-2026-47304 dotnet: .NET Security Feature Bypass Vulnerability BZ - 2500515 - CVE-2026-47302 dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation BZ - 2500556 - CVE-2026-50650 dotnet: .NET Framework: Privilege escalation via code injection BZ - 2500562 - CVE-2026-50528 dotnet: .NET: Security feature bypass due to incorrect authorization BZ - 2500563 - CVE-2026-50649 dotnet: .NET: Local code execution via deserialization of untrusted data BZ - 2500565 - CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution BZ - 2500577 - CVE-2026-50646 dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure BZ - 2500580 - CVE-2026-50525 dotnet: .NET: Denial of Service due to uncontrolled resource allocation BZ - 2500581 - CVE-2026-50527 dotnet: .NET Framework: Denial of Service via network-based buffer overflow BZ - 2500587 - CVE-2026-50648 dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation BZ - 2500589 - CVE-2026-50659 .NET: .NET: Network Spoofing Vulnerability BZ - 2500593 - CVE-2026-50524 dotnet: .NET Framework: Denial of Service via improper input validation BZ - 2512175 - CVE-2026-62899 .NET: .NET Core: .NET Security Feature Bypass Vulnerability BZ - 2512179 - CVE-2026-62900 .NET: .NET Information Disclosure Vulnerability BZ - 2512180 - CVE-2026-62901 .NET: .NET Denial of Service Vulnerability BZ - 2512185 - CVE-2026-62909 .NET: .NET Elevation of Privilege Vulnerability CVEs CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108 CVE-2026-62899 CVE-2026-62900 CVE-2026-62901 CVE-2026-62909 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM dotnet8.0-8.0.130-1.el9_6.src.rpm SHA-256: eeb55e8dc65bbe950e4a0b8143f61d4269ecf86c0f496d57b5cd1043483d124f x86_64 aspnetcore-runtime-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 2fd241c9b3d43d091091bea6ae97cacfe2b39e15b22a232d8f5fc5d7c81a9b37 aspnetcore-runtime-dbg-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 1db638cf74b08a33a64d3b6d0d9fc384efe72b2e865e48c973c088dc8928e9ba aspnetcore-targeting-pack-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 4d1601058f04221e372222aa4ffbc615dc5f009895b1120a388245f6c6f20127 dotnet-apphost-pack-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: d6e699a2bdf6b75fec6342a9fa95e9ed7fc5d1c09697501d253fa27cf7a67329 dotnet-apphost-pack-8.0-debuginfo-8.0.30-1.el9_6.x86_64.rpm SHA-256: c286cd7c19dcb265eed518bb63dacd789be2065c3b4f62cdb7c8bf312311007f dotnet-hostfxr-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 5deb1f26214c30c3575b5a9dc197801988067337060d51663135e6767129473d dotnet-hostfxr-8.0-debuginfo-8.0.30-1.el9_6.x86_64.rpm SHA-256: 41531041a504e9e0b6619ded9ffbef0a69fc619f3a5ebeaeccec36e69ef6269b dotnet-runtime-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: eb77e02ae9291af22ef074f380266fdbcf8f1f1ad21a2fd25dc5b515b8631398 dotnet-runtime-8.0-debuginfo-8.0.30-1.el9_6.x86_64.rpm SHA-256: 71057a2017c8ccaf33306903e1178f21bb3c2bb746efee7f467aae2fecc4e778 dotnet-runtime-dbg-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 1927cc93f8e33040c5018a81db8532b71075b452ede4bc42521331fddbb36689 dotnet-sdk-8.0-8.0.130-1.el9_6.x86_64.rpm SHA-256: 35d26204d31f715b122d400b1b841b4e43b7e69a3a5a347f074765ec5a462850 dotnet-sdk-8.0-debuginfo-8.0.130-1.el9_6.x86_64.rpm SHA-256: 9df8212d576660f54d7cce5a617fbe9bae0c65fa13e752a9f0746a5956b2e11a dotnet-sdk-dbg-8.0-8.0.130-1.el9_6.x86_64.rpm SHA-256: 7097da784a5009c2abfba16e37635b1659ba011268cde96510e830d45efe6c6e dotnet-targeting-pack-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 2c5f9464f1317e427897e0f9fe19bce252e1e04c6262c9b9bbec66b7f04f6e65 dotnet-templates-8.0-8.0.130-1.el9_6.x86_64.rpm SHA-256: 3e4d7eb676624a68b1aad09192651792e8ca409fd5dba84f36329ef8ed30c1a0 dotnet8.0-debuginfo-8.0.130-1.el9_6.x86_64.rpm SHA-256: 00fcf3bbfc95bef28c6dd5f241e09f6d024cd49fd589b7e8cc3c3980b7f09efc dotnet8.0-debugsource-8.0.130-1.el9_6.x86_64.rpm SHA-256: 845cb4c4baf4363365a28303617350ce2ca7c6d5e6d361b9c753f12bc7b59a65 Red Hat Enterprise Linux Server - AUS 9.6 SRPM dotnet8.0-8.0.130-1.el9_6.src.rpm SHA-256: eeb55e8dc65bbe950e4a0b8143f61d4269ecf86c0f496d57b5cd1043483d124f x86_64 aspnetcore-runtime-8.0-8.0.30-1.el9_6.x86_64.rpm SHA-256: 2fd241c9b3d43d091091bea6ae97cacfe2b39e15b22a232d8f5fc5d7c81a9b37 aspnetcore-runtime-dbg-8.0-8.0.30-1.e