RHSA-2026:58568: Important: .NET 8.0 security, bug fix, and enhancement update
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.SDK version: 8.0.130Runtime version: 8.0.30Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.4.z] (JIRA:RHEL-192331) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dotnet8.0to a version that resolves this vulnerability.Fixed in 8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/aspnetcore-runtimeto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/aspnetcore-runtime-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/aspnetcore-targeting-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-apphost-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-apphost-packto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-hostto a version that resolves this vulnerability.Fixed in 8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-host-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-hostfxrto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-hostfxrto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-runtimeto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-runtimeto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-runtime-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-sdkto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-sdkto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-sdk-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-targeting-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4 - Upgrade
Upgrade
redhat/dotnet-templatesto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/dotnet8.0-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/dotnet8.0-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/netstandard-targeting-packto a version that resolves this vulnerability.Fixed in 2.1-8.0.130-1.el9_4 - Upgrade
Upgrade
redhat/aspnetcore-runtimeto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/aspnetcore-runtime-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/aspnetcore-targeting-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-apphost-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-apphost-packto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-hostto a version that resolves this vulnerability.Fixed in 8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-host-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-hostfxrto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-hostfxrto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-runtimeto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-runtimeto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-runtime-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-sdkto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-sdkto a version that resolves this vulnerability.Fixed in 8.0-debuginfo-8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-sdk-dbgto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-targeting-packto a version that resolves this vulnerability.Fixed in 8.0-8.0.30-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet-templatesto a version that resolves this vulnerability.Fixed in 8.0-8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet8.0-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/dotnet8.0-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.130-1.el9_4.aa - Upgrade
Upgrade
redhat/netstandard-targeting-packto a version that resolves this vulnerability.Fixed in 2.1-8.0.130-1.el9_4.aa - Upgrade
Upgrade
.NET SDKto a version that resolves this vulnerability.Fixed in 8.0.130 - Upgrade
Upgrade
.NET Runtimeto a version that resolves this vulnerability.Fixed in 8.0.30 - Upgrade
Upgrade
dotnet: SocketsHttpHandler Http2Connectionto a version that resolves this vulnerability.Patch CVE-2026-50651 - Upgrade
Upgrade
.NET Core / .NETto a version that resolves this vulnerability.Patch CVE-2026-62899 - Upgrade
Upgrade
.NETto a version that resolves this vulnerability.Patch CVE-2026-62901 - Upgrade
Upgrade
.NETto a version that resolves this vulnerability.Patch CVE-2026-62909 - Upgrade
Upgrade
.NETto a version that resolves this vulnerability.Patch CVE-2026-62900 - Upgrade
Upgrade
.NETto a version that resolves this vulnerability.Patch CVE-2026-50659 - Upgrade
Upgrade
ASP.NET Coreto a version that resolves this vulnerability.Patch CVE-2026-56170 - Upgrade
Upgrade
ASP.NET Coreto a version that resolves this vulnerability.Patch CVE-2026-47303 - Upgrade
Upgrade
ASP.NET Coreto a version that resolves this vulnerability.Patch CVE-2026-47300 - Upgrade
Upgrade
dotnet: .NET Coreto a version that resolves this vulnerability.Patch CVE-2026-57108 - Upgrade
Upgrade
dotnet: .NET Frameworkto a version that resolves this vulnerability.Patch CVE-2026-50524 - Upgrade
Upgrade
dotnet: .NET Frameworkto a version that resolves this vulnerability.Patch CVE-2026-50527 - Upgrade
Upgrade
dotnet: .NET Frameworkto a version that resolves this vulnerability.Patch CVE-2026-50646 - Upgrade
Upgrade
dotnet: .NET Frameworkto a version that resolves this vulnerability.Patch CVE-2026-50650 - Upgrade
Upgrade
dotnet: .NET Frameworkto a version that resolves this vulnerability.Patch CVE-2026-50648 - Upgrade
Upgrade
dotnetto a version that resolves this vulnerability.Patch CVE-2026-47304 - Upgrade
Upgrade
dotnet: .NETto a version that resolves this vulnerability.Patch CVE-2026-50525 - Upgrade
Upgrade
dotnetto a version that resolves this vulnerability.Patch CVE-2026-47302 - Upgrade
Upgrade
dotnetto a version that resolves this vulnerability.Patch CVE-2026-50649 - Upgrade
Upgrade
dotnetto a version that resolves this vulnerability.Patch CVE-2026-50526 - Upgrade
Upgrade
dotnetto a version that resolves this vulnerability.Patch CVE-2026-50528 - Upgrade
Upgrade
dotnet8.0 (RHEL RPM builds)to a version that resolves this vulnerability.Patch JIRA:RHEL-192331