[Apollo] Advisories Statistics light light Login

RLSA-2026:41894

Security Mirrored from RHSA-2026:41894
Issued at: 2026-07-23
Updated at: 2026-07-23

Synopsis

Important: .NET 8.0 security, bug fix, and enhancement update



Description

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.

Security Fix(es):

* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)

* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)

* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)

* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)

* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)

* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)

* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)

* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)

* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)

* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)

* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)

* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)

* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)

* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)

* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)

* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)

* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

* Update .NET 8.0 to SDK 8.0.129 and Runtime 8.0.29 [rhel-9.8.z] (JIRA:Rocky Linux-192467)

* dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [rhel-9.8.z] (JIRA:Rocky Linux-192337)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2499217 2500109 2500189 2500492 2500502 2500509 2500515 2500556 2500562 2500563 2500565 2500577 2500580 2500581 2500587 2500589 2500593

CVEs

CVE-2026-47300 CVE-2026-47302 CVE-2026-47303 CVE-2026-47304 CVE-2026-50524 CVE-2026-50525 CVE-2026-50526 CVE-2026-50527 CVE-2026-50528 CVE-2026-50646 CVE-2026-50648 CVE-2026-50649 CVE-2026-50650 CVE-2026-50651 CVE-2026-50659 CVE-2026-56170 CVE-2026-57108

Affected packages

Rocky Linux 9 aarch64 - AppStream

aspnetcore-runtime-8.0-0:8.0.29-1.el9_8.aarch64.rpm aspnetcore-runtime-dbg-8.0-0:8.0.29-1.el9_8.aarch64.rpm aspnetcore-targeting-pack-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet8.0-0:8.0.129-1.el9_8.src.rpm dotnet8.0-debuginfo-0:8.0.129-1.el9_8.aarch64.rpm dotnet8.0-debugsource-0:8.0.129-1.el9_8.aarch64.rpm dotnet-apphost-pack-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet-apphost-pack-8.0-debuginfo-0:8.0.29-1.el9_8.aarch64.rpm dotnet-hostfxr-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet-hostfxr-8.0-debuginfo-0:8.0.29-1.el9_8.aarch64.rpm dotnet-runtime-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet-runtime-8.0-debuginfo-0:8.0.29-1.el9_8.aarch64.rpm dotnet-runtime-dbg-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet-sdk-8.0-0:8.0.129-1.el9_8.aarch64.rpm dotnet-sdk-8.0-debuginfo-0:8.0.129-1.el9_8.aarch64.rpm dotnet-sdk-dbg-8.0-0:8.0.129-1.el9_8.aarch64.rpm dotnet-targeting-pack-8.0-0:8.0.29-1.el9_8.aarch64.rpm dotnet-templates-8.0-0:8.0.129-1.el9_8.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

aspnetcore-runtime-8.0-0:8.0.29-1.el9_8.ppc64le.rpm aspnetcore-runtime-dbg-8.0-0:8.0.29-1.el9_8.ppc64le.rpm aspnetcore-targeting-pack-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet8.0-0:8.0.129-1.el9_8.src.rpm dotnet8.0-debuginfo-0:8.0.129-1.el9_8.ppc64le.rpm dotnet8.0-debugsource-0:8.0.129-1.el9_8.ppc64le.rpm dotnet-apphost-pack-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-apphost-pack-8.0-debuginfo-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-hostfxr-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-hostfxr-8.0-debuginfo-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-runtime-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-runtime-8.0-debuginfo-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-runtime-dbg-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-sdk-8.0-0:8.0.129-1.el9_8.ppc64le.rpm dotnet-sdk-8.0-debuginfo-0:8.0.129-1.el9_8.ppc64le.rpm dotnet-sdk-dbg-8.0-0:8.0.129-1.el9_8.ppc64le.rpm dotnet-targeting-pack-8.0-0:8.0.29-1.el9_8.ppc64le.rpm dotnet-templates-8.0-0:8.0.129-1.el9_8.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

aspnetcore-runtime-8.0-0:8.0.29-1.el9_8.s390x.rpm aspnetcore-runtime-dbg-8.0-0:8.0.29-1.el9_8.s390x.rpm aspnetcore-targeting-pack-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet8.0-0:8.0.129-1.el9_8.src.rpm dotnet8.0-debuginfo-0:8.0.129-1.el9_8.s390x.rpm dotnet8.0-debugsource-0:8.0.129-1.el9_8.s390x.rpm dotnet-apphost-pack-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet-apphost-pack-8.0-debuginfo-0:8.0.29-1.el9_8.s390x.rpm dotnet-hostfxr-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet-hostfxr-8.0-debuginfo-0:8.0.29-1.el9_8.s390x.rpm dotnet-runtime-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet-runtime-8.0-debuginfo-0:8.0.29-1.el9_8.s390x.rpm dotnet-runtime-dbg-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet-sdk-8.0-0:8.0.129-1.el9_8.s390x.rpm dotnet-sdk-8.0-debuginfo-0:8.0.129-1.el9_8.s390x.rpm dotnet-sdk-dbg-8.0-0:8.0.129-1.el9_8.s390x.rpm dotnet-targeting-pack-8.0-0:8.0.29-1.el9_8.s390x.rpm dotnet-templates-8.0-0:8.0.129-1.el9_8.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

aspnetcore-runtime-8.0-0:8.0.29-1.el9_8.x86_64.rpm aspnetcore-runtime-dbg-8.0-0:8.0.29-1.el9_8.x86_64.rpm aspnetcore-targeting-pack-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet8.0-0:8.0.129-1.el9_8.src.rpm dotnet8.0-debuginfo-0:8.0.129-1.el9_8.x86_64.rpm dotnet8.0-debugsource-0:8.0.129-1.el9_8.x86_64.rpm dotnet-apphost-pack-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet-apphost-pack-8.0-debuginfo-0:8.0.29-1.el9_8.x86_64.rpm dotnet-hostfxr-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet-hostfxr-8.0-debuginfo-0:8.0.29-1.el9_8.x86_64.rpm dotnet-runtime-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet-runtime-8.0-debuginfo-0:8.0.29-1.el9_8.x86_64.rpm dotnet-runtime-dbg-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet-sdk-8.0-0:8.0.129-1.el9_8.x86_64.rpm dotnet-sdk-8.0-debuginfo-0:8.0.129-1.el9_8.x86_64.rpm dotnet-sdk-dbg-8.0-0:8.0.129-1.el9_8.x86_64.rpm dotnet-targeting-pack-8.0-0:8.0.29-1.el9_8.x86_64.rpm dotnet-templates-8.0-0:8.0.129-1.el9_8.x86_64.rpm

Rocky Linux 9 aarch64 - CRB

dotnet-sdk-8.0-source-built-artifacts-0:8.0.129-1.el9_8.aarch64.rpm

Rocky Linux 9 ppc64le - CRB

dotnet-sdk-8.0-source-built-artifacts-0:8.0.129-1.el9_8.ppc64le.rpm

Rocky Linux 9 s390x - CRB

dotnet-sdk-8.0-source-built-artifacts-0:8.0.129-1.el9_8.s390x.rpm

Rocky Linux 9 x86_64 - CRB

dotnet-sdk-8.0-source-built-artifacts-0:8.0.129-1.el9_8.x86_64.rpm