{"schema_version": "1.7.0", "id": "RLSA-2026:41894", "modified": "2026-07-23T06:09:42.612264Z", "published": "2026-07-23T06:04:47.296368Z", "upstream": ["CVE-2026-47300", "CVE-2026-47302", "CVE-2026-47303", "CVE-2026-47304", "CVE-2026-50524", "CVE-2026-50525", "CVE-2026-50526", "CVE-2026-50527", "CVE-2026-50528", "CVE-2026-50646", "CVE-2026-50648", "CVE-2026-50649", "CVE-2026-50650", "CVE-2026-50651", "CVE-2026-50659", "CVE-2026-56170", "CVE-2026-57108"], "summary": "Important: .NET 8.0 security, bug fix, and enhancement update", "details": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.\n\nSecurity Fix(es):\n\n* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)\n\n* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)\n\n* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)\n\n* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)\n\n* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)\n\n* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)\n\n* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)\n\n* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)\n\n* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)\n\n* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)\n\n* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)\n\n* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)\n\n* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)\n\n* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)\n\n* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)\n\n* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)\n\n* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)\n\nBug Fix(es) and Enhancement(s):\n\n* Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 [rhel-9.8.z] (JIRA:Rocky Linux-192467)\n\n* dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:Rocky Linux-192337)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:9", "name": "dotnet8.0", "purl": "pkg:rpm/rocky-linux/dotnet8.0?distro=rocky-linux-9&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:8.0.129-1.el9_8"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:41894"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499217"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500109"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500189"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500492"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500502"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500509"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500515"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500556"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500562"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500563"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500565"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500577"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500580"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500581"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500587"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500589"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500593"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}