First published: Tue Feb 06 2024(Updated: )
.NET Denial of Service Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=8.0.0<=8.0.1 | 8.0.2 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=7.0.0<=7.0.15 | 7.0.16 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | <=6.0.26 | 6.0.27 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | <=6.0.26 | 6.0.27 |
ubuntu/dotnet6 | <6.0.127-0ubuntu1~22.04.1 | 6.0.127-0ubuntu1~22.04.1 |
ubuntu/dotnet6 | <6.0.127-0ubuntu1~23.10.1 | 6.0.127-0ubuntu1~23.10.1 |
ubuntu/dotnet6 | <6.0.27 | 6.0.27 |
ubuntu/dotnet7 | <7.0.116-0ubuntu1~22.04.1 | 7.0.116-0ubuntu1~22.04.1 |
ubuntu/dotnet7 | <7.0.116-0ubuntu1~23.10.1 | 7.0.116-0ubuntu1~23.10.1 |
ubuntu/dotnet7 | <7.0.16 | 7.0.16 |
ubuntu/dotnet8 | <8.0.102-8.0.2-0ubuntu1~22.04.1 | 8.0.102-8.0.2-0ubuntu1~22.04.1 |
ubuntu/dotnet8 | <8.0.102-8.0.2-0ubuntu1~23.10.1 | 8.0.102-8.0.2-0ubuntu1~23.10.1 |
ubuntu/dotnet8 | <8.0.2 | 8.0.2 |
Visual Studio Community 2022 | =17.4 | |
Visual Studio Community 2022 | =17.8 | |
ASP.NET Core | =7.0 | |
ASP.NET Core | =8.0 | |
ASP.NET Core | =6.0 | |
ASP.NET Core | >=6.0.0<6.0.27 | |
ASP.NET Core | >=7.0.0<7.0.16 | |
ASP.NET Core | >=8.0.0<8.0.2 | |
Visual Studio Community 2022 | >=17.4.0<17.4.16 | |
Visual Studio Community 2022 | >=17.6.0<17.6.12 | |
Visual Studio Community 2022 | >=17.8.0<17.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21386 has been classified as a Denial of Service vulnerability.
To fix CVE-2024-21386, update to the patched versions of ASP.NET Core or Visual Studio as specified in the advisory.
CVE-2024-21386 affects ASP.NET Core versions 6.0, 7.0, and 8.0, as well as specific versions of Visual Studio 2022.
It is advisable to assume there may be exploit possibilities, hence immediate patching is recommended.
CVE-2024-21386 impacts multiple platforms including Windows, Linux, and macOS environments using affected versions.