Red Hat Product Errata RHSA-2026:24335 - Security Advisory Issued: 2026-06-08 Updated: 2026-06-08 RHSA-2026:24335 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.127 and .NET Runtime 8.0.27.Security Fix(es): serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization (CVE-2026-34043) dotnet: .NET: infinite loop allows an attacker to cause a denial of service (CVE-2026-42899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2453284 - CVE-2026-34043 serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization BZ - 2476605 - CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service CVEs CVE-2026-34043 CVE-2026-42899 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM dotnet8.0-8.0.127-1.el9_6.src.rpm SHA-256: 6d2935aa7cc51b36450f95f577630de195c7687fad1e9a1012416a0376281879 x86_64 aspnetcore-runtime-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 7b15c3b30e6019dfc08bfe8b1f0659c6d0a74fc4f836824834695441d0a1f09f aspnetcore-runtime-dbg-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: d8e456d82591c171b6a4dce42718d33c7f105f455e62444d22a9433407b8e08f aspnetcore-targeting-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 75d344c60fe25ba2ceb53e2f8f95ea51dae15406ccbb083f37ebbd70da61d7ae dotnet-apphost-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 44b26cad67d02b08c368a230d9065ee2cd032ef85f07396cecbcc8d7a19a6762 dotnet-apphost-pack-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: 641a4b7461fff8ab4dd084f8026d112de98f55018600ddb112a2b3002e5b859f dotnet-hostfxr-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: dd604c95401756455b4faea4f8f19b1e0692cfc354c995d7d3b1677311f9af71 dotnet-hostfxr-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: a2cabedf88eadad7acbd00b3c153e6aa820291c8b301381ac1e20155e839dba1 dotnet-runtime-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 2ca9a47f64decb94d89511e0271b317545cbbb8252f43ebb8207dd63fd0305c4 dotnet-runtime-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: 88d36afae565e26915325c966da8799fc0517c1c7f6bdd062435df4c73f4e225 dotnet-runtime-dbg-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 327297a7e1ac4dcf1793870a7cae823779de448750dfd7bc0e8d723f51794727 dotnet-sdk-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 8b00ffcccc8db0557ac067627b4a2b59fc4b0fa609adb3851998511ace5c75ef dotnet-sdk-8.0-debuginfo-8.0.127-1.el9_6.x86_64.rpm SHA-256: 42d0e4b9fe4e218c5553f9be9d100265f997404499ef2af260f255ca801ef9d3 dotnet-sdk-dbg-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 3151d2833d7f0820b723df18b470ae431d63b273faeb1f1b8092f09210a486a4 dotnet-targeting-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: e0d6a8fc9c37dc6fa6eae9857aa2b23103059e3749cf9b72c0ac7d7c4479306f dotnet-templates-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 8df5f11fb939a61b55e32e27c812bf0d328c3de5d204e7240efc67272eb793af dotnet8.0-debuginfo-8.0.127-1.el9_6.x86_64.rpm SHA-256: 1bf55d7f2a5e15b49093a103325104ecfc3750134f1db86298b66b8df1f622bb dotnet8.0-debugsource-8.0.127-1.el9_6.x86_64.rpm SHA-256: eb7f1435d736f6bfa80a2a79e8200d4b6a25cd3b03ff636f8f505a1c95c91fb2 Red Hat Enterprise Linux Server - AUS 9.6 SRPM dotnet8.0-8.0.127-1.el9_6.src.rpm SHA-256: 6d2935aa7cc51b36450f95f577630de195c7687fad1e9a1012416a0376281879 x86_64 aspnetcore-runtime-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 7b15c3b30e6019dfc08bfe8b1f0659c6d0a74fc4f836824834695441d0a1f09f aspnetcore-runtime-dbg-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: d8e456d82591c171b6a4dce42718d33c7f105f455e62444d22a9433407b8e08f aspnetcore-targeting-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 75d344c60fe25ba2ceb53e2f8f95ea51dae15406ccbb083f37ebbd70da61d7ae dotnet-apphost-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 44b26cad67d02b08c368a230d9065ee2cd032ef85f07396cecbcc8d7a19a6762 dotnet-apphost-pack-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: 641a4b7461fff8ab4dd084f8026d112de98f55018600ddb112a2b3002e5b859f dotnet-hostfxr-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: dd604c95401756455b4faea4f8f19b1e0692cfc354c995d7d3b1677311f9af71 dotnet-hostfxr-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: a2cabedf88eadad7acbd00b3c153e6aa820291c8b301381ac1e20155e839dba1 dotnet-runtime-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 2ca9a47f64decb94d89511e0271b317545cbbb8252f43ebb8207dd63fd0305c4 dotnet-runtime-8.0-debuginfo-8.0.27-1.el9_6.x86_64.rpm SHA-256: 88d36afae565e26915325c966da8799fc0517c1c7f6bdd062435df4c73f4e225 dotnet-runtime-dbg-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: 327297a7e1ac4dcf1793870a7cae823779de448750dfd7bc0e8d723f51794727 dotnet-sdk-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 8b00ffcccc8db0557ac067627b4a2b59fc4b0fa609adb3851998511ace5c75ef dotnet-sdk-8.0-debuginfo-8.0.127-1.el9_6.x86_64.rpm SHA-256: 42d0e4b9fe4e218c5553f9be9d100265f997404499ef2af260f255ca801ef9d3 dotnet-sdk-dbg-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 3151d2833d7f0820b723df18b470ae431d63b273faeb1f1b8092f09210a486a4 dotnet-targeting-pack-8.0-8.0.27-1.el9_6.x86_64.rpm SHA-256: e0d6a8fc9c37dc6fa6eae9857aa2b23103059e3749cf9b72c0ac7d7c4479306f dotnet-templates-8.0-8.0.127-1.el9_6.x86_64.rpm SHA-256: 8df5f11fb939a61b55e32e27c812bf0d328c3de5d204e7240efc67272eb793af dotnet8.0-debuginfo-8.0.127-1.el9_6.x86_64.rpm SHA-256: 1bf55d7f2a5e15b49093a103325104ecfc3750134f1db86298b66b8df1f622bb dotnet8.0-debugsource-8.0.127-1.el9_6.x86_64.rpm SHA-256: eb7f1435d736f6bfa80a2a79e8200d4b6a25cd3b03ff636f8f505a1c95c91fb2 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM dotnet8.0-8.0.127-1.el9_6.src.rpm SHA-256: 6d2935aa7cc51b36450f95f577630de195c7687fad1e9a1012416a0376281879 s390x aspnetcore-runtime-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: 2123ee8bbfac57c38bd28f3c6df4053558724c1eadb0d490dff9f6d7f66fce54 aspnetcore-runtime-dbg-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: d1663465d846b9217a7821e7caeaaeeb26bc167df98f3a84b7e60888ce476038 aspnetcore-targeting-pack-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: be3f2c2c806ec5c7ab63f906e35d9cfd37620952b2afb379367995d2f1f854fa dotnet-apphost-pack-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: d07f1529eb5973f34cc380aec5df4bcdd830b14cca6cfd424251fa32ed65b917 dotnet-apphost-pack-8.0-debuginfo-8.0.27-1.el9_6.s390x.rpm SHA-256: ad246b33c0c20d8050654cfeb5eb4cad01f7296001bf803db1d8512d7541b2bb dotnet-hostfxr-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: cd604dc832bff2c94ea21e42f94aeb5f1868553f21b8334b4b53a9cbfcf57b52 dotnet-hostfxr-8.0-debuginfo-8.0.27-1.el9_6.s390x.rpm SHA-256: b0865fa9bd64afd467ff46c07d90ed82279a8a99345dd19a08e9bc72bb3f9d72 dotnet-runtime-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: ef01fc0a33ebdb2be66e307eda968dbe9a05a2fd030ec4c61be26be778bf2f31 dotnet-runtime-8.0-debuginfo-8.0.27-1.el9_6.s390x.rpm SHA-256: 91fa082329ddc786814779d4008b9cdec74da04a0aca933dafc5e3dafdaff0b2 dotnet-runtime-dbg-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: 9a0b59f9b416421083e439c942bf7cee6b157a76fceec576125c0c53f8cb1117 dotnet-sdk-8.0-8.0.127-1.el9_6.s390x.rpm SHA-256: 6c1628cb81994bc96b7ac487d11631659136307d2ce586aa0ac6afdc6858b9be dotnet-sdk-8.0-debuginfo-8.0.127-1.el9_6.s390x.rpm SHA-256: 2660605c6a17677bbc6494cef40b3e48ee8a5a0e96dc729560de4c1646b830e1 dotnet-sdk-dbg-8.0-8.0.127-1.el9_6.s390x.rpm SHA-256: f9e2f862d0b85b7b95119c4300f5d2ac56788a14f6c5bb58f59fe9e2031b9898 dotnet-targeting-pack-8.0-8.0.27-1.el9_6.s390x.rpm SHA-256: 188cfeebc8ad8a06af9855fdb6dc9e9f2746b21d0d0133bbb8a31d81b499988a dotnet-templates-8.0-8.0.127-1.el9_6.s390x.rpm SHA-256: 273c01c
This Important Red Hat security update for .NET 8.0 addresses two vulnerabilities: CVE-2026-34043 (CVSS 5.9 MEDIUM) in the `serialize-javascript` component, which allows denial of service via a specially crafted array-like object, and CVE-2026-42899 (CVSS 7.5 HIGH) in .NET, where an infinite loop can be triggered to cause a denial of service. The .NET vulnerability affects versions 8.0.0 through 8.0.26, and the fix is provided by upgrading to .NET Runtime 8.0.27 and .NET SDK 8.0.127.