First published: Wed Jul 10 2024(Updated: )
It was discovered that .NET did not properly handle object deserialization. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-30105) Radek Zikmund discovered that .NET did not properly manage memory. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-35264) It was discovered that .NET did not properly parse X.509 Content and ObjectIdentifiers. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-38095)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/aspnetcore-runtime-8.0 | <8.0.7-0ubuntu1~24.04.1 | 8.0.7-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/dotnet-host-8.0 | <8.0.7-0ubuntu1~24.04.1 | 8.0.7-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/dotnet-hostfxr-8.0 | <8.0.7-0ubuntu1~24.04.1 | 8.0.7-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/dotnet-runtime-8.0 | <8.0.7-0ubuntu1~24.04.1 | 8.0.7-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/dotnet-sdk-8.0 | <8.0.107-0ubuntu1~24.04.1 | 8.0.107-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/dotnet8 | <8.0.107-8.0.7-0ubuntu1~24.04.1 | 8.0.107-8.0.7-0ubuntu1~24.04.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/aspnetcore-runtime-6.0 | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/aspnetcore-runtime-8.0 | <8.0.7-0ubuntu1~23.10.1 | 8.0.7-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-host | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-host-8.0 | <8.0.7-0ubuntu1~23.10.1 | 8.0.7-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-hostfxr-6.0 | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-hostfxr-8.0 | <8.0.7-0ubuntu1~23.10.1 | 8.0.7-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-runtime-6.0 | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-runtime-8.0 | <8.0.7-0ubuntu1~23.10.1 | 8.0.7-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-sdk-6.0 | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet-sdk-8.0 | <8.0.107-0ubuntu1~23.10.1 | 8.0.107-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet6 | <6.0.132-0ubuntu1~23.10.1 | 6.0.132-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/dotnet8 | <8.0.107-8.0.7-0ubuntu1~23.10.1 | 8.0.107-8.0.7-0ubuntu1~23.10.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/aspnetcore-runtime-6.0 | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/aspnetcore-runtime-8.0 | <8.0.7-0ubuntu1~22.04.1 | 8.0.7-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-host | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-host-8.0 | <8.0.7-0ubuntu1~22.04.1 | 8.0.7-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-hostfxr-6.0 | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-hostfxr-8.0 | <8.0.7-0ubuntu1~22.04.1 | 8.0.7-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-runtime-6.0 | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-runtime-8.0 | <8.0.7-0ubuntu1~22.04.1 | 8.0.7-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-sdk-6.0 | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet-sdk-8.0 | <8.0.107-0ubuntu1~22.04.1 | 8.0.107-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet6 | <6.0.132-0ubuntu1~22.04.1 | 6.0.132-0ubuntu1~22.04.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/dotnet8 | <8.0.107-8.0.7-0ubuntu1~22.04.1 | 8.0.107-8.0.7-0ubuntu1~22.04.1 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-6889-1 is high due to potential denial of service vulnerabilities found in .NET.
To fix USN-6889-1, update your affected packages to the recommended versions specified in the advisory.
USN-6889-1 affects multiple versions of .NET packages on Ubuntu 22.04 and 24.04.
USN-6889-1 does not currently indicate remote exploitation but can cause denial of service if exploited.
The issues in USN-6889-1 were discovered by researchers including Radek Zikmund.