RHSA-2026:58568: Important: .NET 8.0 security, bug fix, and enhancement update

Published Aug 24, 2026
·
Updated

.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.SDK version: 8.0.130Runtime version: 8.0.30Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.4.z] (JIRA:RHEL-192331) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Software

81 affected componentsFixes available
redhat/dotnet8.0<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/aspnetcore-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-host<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-host-debuginfo<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-sdk<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-sdk<8.0-debuginfo-8.0.130-1.el9_4
8.0-debuginfo-8.0.130-1.el9_4
redhat/dotnet-sdk-dbg<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-templates<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet8.0-debuginfo<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/dotnet8.0-debugsource<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/netstandard-targeting-pack<2.1-8.0.130-1.el9_4
2.1-8.0.130-1.el9_4
redhat/aspnetcore-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-host<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-host-debuginfo<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-sdk<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-sdk<8.0-debuginfo-8.0.130-1.el9_4
8.0-debuginfo-8.0.130-1.el9_4
redhat/dotnet-sdk-dbg<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-templates<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet8.0-debuginfo<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/dotnet8.0-debugsource<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/netstandard-targeting-pack<2.1-8.0.130-1.el9_4
2.1-8.0.130-1.el9_4
redhat/aspnetcore-runtime<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/aspnetcore-runtime-dbg<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/aspnetcore-targeting-pack<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-apphost-pack<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-apphost-pack<8.0-debuginfo-8.0.30-1.el9_4.aa
8.0-debuginfo-8.0.30-1.el9_4.aa
redhat/dotnet-host<8.0.30-1.el9_4.aa
8.0.30-1.el9_4.aa
redhat/dotnet-host-debuginfo<8.0.30-1.el9_4.aa
8.0.30-1.el9_4.aa
redhat/dotnet-hostfxr<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-hostfxr<8.0-debuginfo-8.0.30-1.el9_4.aa
8.0-debuginfo-8.0.30-1.el9_4.aa
redhat/dotnet-runtime<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-runtime<8.0-debuginfo-8.0.30-1.el9_4.aa
8.0-debuginfo-8.0.30-1.el9_4.aa
redhat/dotnet-runtime-dbg<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-sdk<8.0-8.0.130-1.el9_4.aa
8.0-8.0.130-1.el9_4.aa
redhat/dotnet-sdk<8.0-debuginfo-8.0.130-1.el9_4.aa
8.0-debuginfo-8.0.130-1.el9_4.aa
redhat/dotnet-sdk-dbg<8.0-8.0.130-1.el9_4.aa
8.0-8.0.130-1.el9_4.aa
redhat/dotnet-targeting-pack<8.0-8.0.30-1.el9_4.aa
8.0-8.0.30-1.el9_4.aa
redhat/dotnet-templates<8.0-8.0.130-1.el9_4.aa
8.0-8.0.130-1.el9_4.aa
redhat/dotnet8.0-debuginfo<8.0.130-1.el9_4.aa
8.0.130-1.el9_4.aa
redhat/dotnet8.0-debugsource<8.0.130-1.el9_4.aa
8.0.130-1.el9_4.aa
redhat/netstandard-targeting-pack<2.1-8.0.130-1.el9_4.aa
2.1-8.0.130-1.el9_4.aa
redhat/aspnetcore-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/aspnetcore-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-apphost-pack<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-host<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-host-debuginfo<8.0.30-1.el9_4
8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-hostfxr<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-runtime<8.0-debuginfo-8.0.30-1.el9_4
8.0-debuginfo-8.0.30-1.el9_4
redhat/dotnet-runtime-dbg<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-sdk<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-sdk<8.0-debuginfo-8.0.130-1.el9_4
8.0-debuginfo-8.0.130-1.el9_4
redhat/dotnet-sdk-dbg<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet-targeting-pack<8.0-8.0.30-1.el9_4
8.0-8.0.30-1.el9_4
redhat/dotnet-templates<8.0-8.0.130-1.el9_4
8.0-8.0.130-1.el9_4
redhat/dotnet8.0-debuginfo<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/dotnet8.0-debugsource<8.0.130-1.el9_4
8.0.130-1.el9_4
redhat/netstandard-targeting-pack<2.1-8.0.130-1.el9_4
2.1-8.0.130-1.el9_4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/dotnet8.0 to a version that resolves this vulnerability.

    Fixed in 8.0.130-1.el9_4
  2. Upgrade

    Upgrade redhat/aspnetcore-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  3. Upgrade

    Upgrade redhat/aspnetcore-runtime-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  4. Upgrade

    Upgrade redhat/aspnetcore-targeting-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  5. Upgrade

    Upgrade redhat/dotnet-apphost-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  6. Upgrade

    Upgrade redhat/dotnet-apphost-pack to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4
  7. Upgrade

    Upgrade redhat/dotnet-host to a version that resolves this vulnerability.

    Fixed in 8.0.30-1.el9_4
  8. Upgrade

    Upgrade redhat/dotnet-host-debuginfo to a version that resolves this vulnerability.

    Fixed in 8.0.30-1.el9_4
  9. Upgrade

    Upgrade redhat/dotnet-hostfxr to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  10. Upgrade

    Upgrade redhat/dotnet-hostfxr to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4
  11. Upgrade

    Upgrade redhat/dotnet-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  12. Upgrade

    Upgrade redhat/dotnet-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4
  13. Upgrade

    Upgrade redhat/dotnet-runtime-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  14. Upgrade

    Upgrade redhat/dotnet-sdk to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4
  15. Upgrade

    Upgrade redhat/dotnet-sdk to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.130-1.el9_4
  16. Upgrade

    Upgrade redhat/dotnet-sdk-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4
  17. Upgrade

    Upgrade redhat/dotnet-targeting-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4
  18. Upgrade

    Upgrade redhat/dotnet-templates to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4
  19. Upgrade

    Upgrade redhat/dotnet8.0-debuginfo to a version that resolves this vulnerability.

    Fixed in 8.0.130-1.el9_4
  20. Upgrade

    Upgrade redhat/dotnet8.0-debugsource to a version that resolves this vulnerability.

    Fixed in 8.0.130-1.el9_4
  21. Upgrade

    Upgrade redhat/netstandard-targeting-pack to a version that resolves this vulnerability.

    Fixed in 2.1-8.0.130-1.el9_4
  22. Upgrade

    Upgrade redhat/aspnetcore-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  23. Upgrade

    Upgrade redhat/aspnetcore-runtime-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  24. Upgrade

    Upgrade redhat/aspnetcore-targeting-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  25. Upgrade

    Upgrade redhat/dotnet-apphost-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  26. Upgrade

    Upgrade redhat/dotnet-apphost-pack to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa
  27. Upgrade

    Upgrade redhat/dotnet-host to a version that resolves this vulnerability.

    Fixed in 8.0.30-1.el9_4.aa
  28. Upgrade

    Upgrade redhat/dotnet-host-debuginfo to a version that resolves this vulnerability.

    Fixed in 8.0.30-1.el9_4.aa
  29. Upgrade

    Upgrade redhat/dotnet-hostfxr to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  30. Upgrade

    Upgrade redhat/dotnet-hostfxr to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa
  31. Upgrade

    Upgrade redhat/dotnet-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  32. Upgrade

    Upgrade redhat/dotnet-runtime to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa
  33. Upgrade

    Upgrade redhat/dotnet-runtime-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  34. Upgrade

    Upgrade redhat/dotnet-sdk to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4.aa
  35. Upgrade

    Upgrade redhat/dotnet-sdk to a version that resolves this vulnerability.

    Fixed in 8.0-debuginfo-8.0.130-1.el9_4.aa
  36. Upgrade

    Upgrade redhat/dotnet-sdk-dbg to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4.aa
  37. Upgrade

    Upgrade redhat/dotnet-targeting-pack to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.30-1.el9_4.aa
  38. Upgrade

    Upgrade redhat/dotnet-templates to a version that resolves this vulnerability.

    Fixed in 8.0-8.0.130-1.el9_4.aa
  39. Upgrade

    Upgrade redhat/dotnet8.0-debuginfo to a version that resolves this vulnerability.

    Fixed in 8.0.130-1.el9_4.aa
  40. Upgrade

    Upgrade redhat/dotnet8.0-debugsource to a version that resolves this vulnerability.

    Fixed in 8.0.130-1.el9_4.aa
  41. Upgrade

    Upgrade redhat/netstandard-targeting-pack to a version that resolves this vulnerability.

    Fixed in 2.1-8.0.130-1.el9_4.aa
  42. Upgrade

    Upgrade .NET SDK to a version that resolves this vulnerability.

    Fixed in 8.0.130
  43. Upgrade

    Upgrade .NET Runtime to a version that resolves this vulnerability.

    Fixed in 8.0.30
  44. Upgrade

    Upgrade dotnet: SocketsHttpHandler Http2Connection to a version that resolves this vulnerability.

    Patch CVE-2026-50651
  45. Upgrade

    Upgrade .NET Core / .NET to a version that resolves this vulnerability.

    Patch CVE-2026-62899
  46. Upgrade

    Upgrade .NET to a version that resolves this vulnerability.

    Patch CVE-2026-62901
  47. Upgrade

    Upgrade .NET to a version that resolves this vulnerability.

    Patch CVE-2026-62909
  48. Upgrade

    Upgrade .NET to a version that resolves this vulnerability.

    Patch CVE-2026-62900
  49. Upgrade

    Upgrade .NET to a version that resolves this vulnerability.

    Patch CVE-2026-50659
  50. Upgrade

    Upgrade ASP.NET Core to a version that resolves this vulnerability.

    Patch CVE-2026-56170
  51. Upgrade

    Upgrade ASP.NET Core to a version that resolves this vulnerability.

    Patch CVE-2026-47303
  52. Upgrade

    Upgrade ASP.NET Core to a version that resolves this vulnerability.

    Patch CVE-2026-47300
  53. Upgrade

    Upgrade dotnet: .NET Core to a version that resolves this vulnerability.

    Patch CVE-2026-57108
  54. Upgrade

    Upgrade dotnet: .NET Framework to a version that resolves this vulnerability.

    Patch CVE-2026-50524
  55. Upgrade

    Upgrade dotnet: .NET Framework to a version that resolves this vulnerability.

    Patch CVE-2026-50527
  56. Upgrade

    Upgrade dotnet: .NET Framework to a version that resolves this vulnerability.

    Patch CVE-2026-50646
  57. Upgrade

    Upgrade dotnet: .NET Framework to a version that resolves this vulnerability.

    Patch CVE-2026-50650
  58. Upgrade

    Upgrade dotnet: .NET Framework to a version that resolves this vulnerability.

    Patch CVE-2026-50648
  59. Upgrade

    Upgrade dotnet to a version that resolves this vulnerability.

    Patch CVE-2026-47304
  60. Upgrade

    Upgrade dotnet: .NET to a version that resolves this vulnerability.

    Patch CVE-2026-50525
  61. Upgrade

    Upgrade dotnet to a version that resolves this vulnerability.

    Patch CVE-2026-47302
  62. Upgrade

    Upgrade dotnet to a version that resolves this vulnerability.

    Patch CVE-2026-50649
  63. Upgrade

    Upgrade dotnet to a version that resolves this vulnerability.

    Patch CVE-2026-50526
  64. Upgrade

    Upgrade dotnet to a version that resolves this vulnerability.

    Patch CVE-2026-50528
  65. Upgrade

    Upgrade dotnet8.0 (RHEL RPM builds) to a version that resolves this vulnerability.

    Patch JIRA:RHEL-192331

Event History

Aug 24, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203