First published: Tue Oct 10 2023(Updated: )
It was discovered that the .NET Kestrel web server did not properly handle HTTP/2 requests. A remote attacker could possibly use this issue to cause a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/aspnetcore-runtime-6.0 | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/aspnetcore-runtime-7.0 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-host | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-host-7.0 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-hostfxr-6.0 | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-hostfxr-7.0 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-runtime-6.0 | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-runtime-7.0 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-sdk-6.0 | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet-sdk-7.0 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet6 | <6.0.123-0ubuntu1~23.04.1 | 6.0.123-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/dotnet7 | <7.0.112-0ubuntu1~23.04.1 | 7.0.112-0ubuntu1~23.04.1 |
=23.04 | ||
All of | ||
ubuntu/aspnetcore-runtime-6.0 | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/aspnetcore-runtime-7.0 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-host | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-host-7.0 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-hostfxr-6.0 | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-hostfxr-7.0 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-runtime-6.0 | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-runtime-7.0 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-sdk-6.0 | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet-sdk-7.0 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet6 | <6.0.123-0ubuntu1~22.04.1 | 6.0.123-0ubuntu1~22.04.1 |
=22.04 | ||
All of | ||
ubuntu/dotnet7 | <7.0.112-0ubuntu1~22.04.1 | 7.0.112-0ubuntu1~22.04.1 |
=22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this .NET vulnerability is USN-6427-1.
The USN-6427-1 vulnerability is a denial of service vulnerability in the .NET Kestrel web server.
The affected software for the USN-6427-1 vulnerability includes aspnetcore-runtime-6.0, aspnetcore-runtime-7.0, dotnet-host, dotnet-host-7.0, dotnet-hostfxr-6.0, dotnet-hostfxr-7.0, dotnet-runtime-6.0, dotnet-runtime-7.0, dotnet-sdk-6.0, dotnet-sdk-7.0, dotnet6, and dotnet7.
This vulnerability can be exploited by a remote attacker sending malicious HTTP/2 requests to the .NET Kestrel web server.
To fix the USN-6427-1 vulnerability, update the affected software packages to the specified versions.