AlmaLinux alert ALSA-2026:41895 (.NET 9.0)
| From: | AlmaLinux Errata Notifications via Announce <announce@lists.almalinux.org> | |
| To: | announce@lists.almalinux.org | |
| Subject: | [Announce] [Security Advisory] ALSA-2026:41895: .NET 9.0 security, bug fix, and enhancement update (Important) | |
| Date: | Fri, 31 Jul 2026 16:20:21 +0000 | |
| Message-ID: | <0100019fb8fa0835-6d50e9ee-a3ea-4554-842c-fcd4cd64a462-000000@email.amazonses.com> | |
| Archive-link: | Article |
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 10 Type: Security Severity: Important Release date: 2026-07-31 Summary: .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): * dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) * dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) * ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) * ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) * ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) * dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) * dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) * dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) * dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) * dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) * dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) * dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) * dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) * .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) * dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) Bug Fix(es) and Enhancement(s): * Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 [almalinux-10.2.z] (JIRA:AlmaLinux-192473) * dotnet9.0: Reduce time to detect hanging builds during .NET RPM builds (c10s) [almalinux-10.2.z] (JIRA:AlmaLinux-192330) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-41895.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team _______________________________________________ Announce mailing list -- announce@lists.almalinux.org To unsubscribe send an email to announce-leave@lists.almalinux.org
