Red Hat Product Errata RHSA-2026:21754 - Security Advisory Issued: 2026-05-28 Updated: 2026-05-28 RHSA-2026:21754 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.117 and .NET Runtime 9.0.16.Security Fix(es): dotnet: .NET: infinite loop allows an attacker to cause a denial of service (CVE-2026-42899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2476605 - CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service CVEs CVE-2026-42899 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM dotnet9.0-9.0.117-1.el10_2.src.rpm SHA-256: 7a9f37834fad4205e21d2e32fe94b5bf7b5afbafdd3ec8e3d4446d32de68b12a x86_64 aspnetcore-runtime-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 5f8bbece054d78da5100ee7b90dc7cad58442e4ced818a76d19bd96a9ad2e1b5 aspnetcore-runtime-dbg-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 1cc410a30151ddd9dd330face4141388cbfdbb447ce1e800c429c413311daa4c aspnetcore-targeting-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 2b6bd9bbba37277cff1b9265cb8ef96bd336eb052f44bd6f4cdaa9178315ba08 dotnet-apphost-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 54829177cc8c6171602e65585f3d23d79318a51b329bf3c801cb547fd2df1458 dotnet-apphost-pack-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: 8a8daa2563822db0aa659e97fe284325a192d9de5dd2b7f731517c81b3d1157f dotnet-hostfxr-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 5a3d24c83fb88738230fa397499e90f038ed8ec7ec9ba6b8ae8feebdc39d464f dotnet-hostfxr-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: c2dee113ba8abbeb485266f96ba8d68314de87bec0ac19ea5f7f88527d85c7fb dotnet-runtime-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 8f567990bfd1d79ffb80fa530b6eff945b1cda7c308cae2b4c2765dff7bc6a99 dotnet-runtime-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: b083317d67537573352bc8b9364f197ed2b9c6035ba3b8b19965ab42ee7139f0 dotnet-runtime-dbg-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: e013c40ff1f347da8b2ba717c86c8b3907a7b1dfce860ef93fe59661d38687f8 dotnet-sdk-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: 2c762febd8dd9d9f465cb9e44bca9bc4358cf5e819d18caff46d604c0fc77fc6 dotnet-sdk-9.0-debuginfo-9.0.117-1.el10_2.x86_64.rpm SHA-256: 824602b58222f058ef06a39c559133db2b20fa824019dc5ee16daec7bdfb52d5 dotnet-sdk-aot-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: c1d49b5e51c5518d4563e9c38ae315cca9f4b5dbc10fd5a3f8673f1b08009061 dotnet-sdk-aot-9.0-debuginfo-9.0.117-1.el10_2.x86_64.rpm SHA-256: 9026568b19b28b0e1d81235f866439247d4d2c2227c0773cd1b2270ae88d6d7c dotnet-sdk-dbg-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: a66552184c11616acea88d71ce4cbe265ef2834ddf7ab3c5f2ecac4cb5fd4934 dotnet-targeting-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: c319b5f472e880bfbddd3a7b5fcda0a8fb0e899a04eadb03f6a01e9e50180efc dotnet-templates-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: 156f9a2112827cdb09261035607e658d4be65a66c3eb17f114e200ff13815ad5 dotnet9.0-debugsource-9.0.117-1.el10_2.x86_64.rpm SHA-256: 5e3f51747ca0559454f28f7908efe8c2057db5f19e04fa3b4a74f213b7706548 netstandard-targeting-pack-2.1-9.0.117-1.el10_2.x86_64.rpm SHA-256: 51ae4b3214436dbba5c57baa4bd8c3abfbeba3f53e2840e105ac9d123a5750f0 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM dotnet9.0-9.0.117-1.el10_2.src.rpm SHA-256: 7a9f37834fad4205e21d2e32fe94b5bf7b5afbafdd3ec8e3d4446d32de68b12a x86_64 aspnetcore-runtime-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 5f8bbece054d78da5100ee7b90dc7cad58442e4ced818a76d19bd96a9ad2e1b5 aspnetcore-runtime-dbg-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 1cc410a30151ddd9dd330face4141388cbfdbb447ce1e800c429c413311daa4c aspnetcore-targeting-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 2b6bd9bbba37277cff1b9265cb8ef96bd336eb052f44bd6f4cdaa9178315ba08 dotnet-apphost-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 54829177cc8c6171602e65585f3d23d79318a51b329bf3c801cb547fd2df1458 dotnet-apphost-pack-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: 8a8daa2563822db0aa659e97fe284325a192d9de5dd2b7f731517c81b3d1157f dotnet-hostfxr-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 5a3d24c83fb88738230fa397499e90f038ed8ec7ec9ba6b8ae8feebdc39d464f dotnet-hostfxr-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: c2dee113ba8abbeb485266f96ba8d68314de87bec0ac19ea5f7f88527d85c7fb dotnet-runtime-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: 8f567990bfd1d79ffb80fa530b6eff945b1cda7c308cae2b4c2765dff7bc6a99 dotnet-runtime-9.0-debuginfo-9.0.16-1.el10_2.x86_64.rpm SHA-256: b083317d67537573352bc8b9364f197ed2b9c6035ba3b8b19965ab42ee7139f0 dotnet-runtime-dbg-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: e013c40ff1f347da8b2ba717c86c8b3907a7b1dfce860ef93fe59661d38687f8 dotnet-sdk-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: 2c762febd8dd9d9f465cb9e44bca9bc4358cf5e819d18caff46d604c0fc77fc6 dotnet-sdk-9.0-debuginfo-9.0.117-1.el10_2.x86_64.rpm SHA-256: 824602b58222f058ef06a39c559133db2b20fa824019dc5ee16daec7bdfb52d5 dotnet-sdk-aot-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: c1d49b5e51c5518d4563e9c38ae315cca9f4b5dbc10fd5a3f8673f1b08009061 dotnet-sdk-aot-9.0-debuginfo-9.0.117-1.el10_2.x86_64.rpm SHA-256: 9026568b19b28b0e1d81235f866439247d4d2c2227c0773cd1b2270ae88d6d7c dotnet-sdk-dbg-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: a66552184c11616acea88d71ce4cbe265ef2834ddf7ab3c5f2ecac4cb5fd4934 dotnet-targeting-pack-9.0-9.0.16-1.el10_2.x86_64.rpm SHA-256: c319b5f472e880bfbddd3a7b5fcda0a8fb0e899a04eadb03f6a01e9e50180efc dotnet-templates-9.0-9.0.117-1.el10_2.x86_64.rpm SHA-256: 156f9a2112827cdb09261035607e658d4be65a66c3eb17f114e200ff13815ad5 dotnet9.0-debugsource-9.0.117-1.el10_2.x86_64.rpm SHA-256: 5e3f51747ca0559454f28f7908efe8c2057db5f19e04fa3b4a74f213b7706548 netstandard-targeting-pack-2.1-9.0.117-1.el10_2.x86_64.rpm SHA-256: 51ae4b3214436dbba5c57baa4bd8c3abfbeba3f53e2840e105ac9d123a5750f0 Red Hat Enterprise Linux for IBM z Systems 10 SRPM dotnet9.0-9.0.117-1.el10_2.src.rpm SHA-256: 7a9f37834fad4205e21d2e32fe94b5bf7b5afbafdd3ec8e3d4446d32de68b12a s390x aspnetcore-runtime-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: fa8a751f7f4518efda349d646e945cc127992bfb42d6130b78e9627d2a21fc74 aspnetcore-runtime-dbg-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: 6c630a7219723e6871c97bc15517e87d70ddf203847f14447cfaa0343c96a074 aspnetcore-targeting-pack-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: 14d59d67f074053868adf6a6123adbec7992600e3d895aeb928488e0f7d95875 dotnet-apphost-pack-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: f05bda62c5934b2ebbc38b8212dc02c53f952ed08eb97b9e54faea1a35b3e96a dotnet-apphost-pack-9.0-debuginfo-9.0.16-1.el10_2.s390x.rpm SHA-256: e63b2ecefb202dec742f8810dae0942f99e58d98515bc3920b40ae36994bd8eb dotnet-hostfxr-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: 3027a3965e1266211bfa7bfe432f49a8bfc7d541cb5ea9b0a07c2e7b1e54781b dotnet-hostfxr-9.0-debuginfo-9.0.16-1.el10_2.s390x.rpm SHA-256: e711a91b60a95671cd9448595a8d9dff03fd905d3ef805a9d87aaeeebcd0bd46 dotnet-runtime-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: 1e002bfbb09a83de9fea9aff79bf59ac5d24c78a6bd8a1340ee5b5fd6cf3aa89 dotnet-runtime-9.0-debuginfo-9.0.16-1.el10_2.s390x.rpm SHA-256: 22a2cd604dc4e79c5d8b0fc3ab88d3548d144fb0f9959493e7ecbd1b0b7d7f49 dotnet-runtime-dbg-9.0-9.0.16-1.el10_2.s390x.rpm SHA-256: 8821d
A vulnerability in .NET (CVE-2026-42899, CVSS 7.5 HIGH) allows an attacker to cause a denial of service via an infinite loop. Affected versions are .NET 8.0.0 through 8.0.26, .NET 9.0.0 through 9.0.15, and .NET 10.0.0 through 10.0.7. The fix requires upgrading to .NET 8.0.27, .NET 9.0.16, or .NET 10.0.8, respectively.