USN-7058-1: .NET vulnerabilities
Brennan Conroy discovered that the .NET Kestrel web server did not properly handle closing HTTP/3 streams under certain circumstances. An attacker could possibly use this issue to achieve remote code execution. This vulnerability only impacted .NET8. (CVE-2024-38229) It was discovered that .NET components designed to process malicious input were susceptible to hash flooding attacks. An attacker could possibly use this issue to cause a denial of service, resulting in a crash. (CVE-2024-43483) It was discovered that the .NET System.IO.Packaging namespace did not properly process SortedList data structures. An attacker could possibly use this issue to cause a denial of service, resulting in a crash. (CVE-2024-43484) It was discovered that .NET did not properly handle the deserialization of of certain JSON properties. An attacker could possibly use this issue to cause a denial of service, resulting in a crash. (CVE-2024-43485)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7058-1?
The severity of USN-7058-1 is high, as it allows potential remote code execution.
How do I fix USN-7058-1?
To fix USN-7058-1, update to the patched versions of the affected packages available for your Ubuntu version.
What versions are affected by USN-7058-1?
USN-7058-1 affects .NET 8 and the associated packages on Ubuntu 22.04 and 24.04.
Who discovered the vulnerability in USN-7058-1?
The vulnerability in USN-7058-1 was discovered by Brennan Conroy.
What type of vulnerability is addressed in USN-7058-1?
USN-7058-1 addresses a vulnerability in the .NET Kestrel web server related to handling HTTP/3 streams.