Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:25112: Important: .NET 9.0 security update

  • What: .NET 9.0 security update
  • Impact: Red Hat Enterprise Linux 10 users
Read Full Article →

Red Hat Product Errata RHSA-2026:25112 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:25112 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.118 and .NET Runtime 9.0.17.Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM dotnet9.0-9.0.118-1.el10_2.src.rpm SHA-256: 19962614a5ac88003e5e60717df1f1c5788c999ba77e8bcd389efbaac1531a3b x86_64 aspnetcore-runtime-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: a0fecfaf3ea3c28dbad022c8648face33bd9e1c52e133f37d764ce230e245f3f aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: c5536a94b6cdbe2c455a66c21b351f73e13d7175b0557e7edce72b2f98c98208 aspnetcore-targeting-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: e446cf5d36f9dc63e73230903b59ee52c6ca3aebfb7fdec20e5dd01796fa9c0c dotnet-apphost-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: dbe1022855ec249cad39f01a9fd9c8d2ed271d240c6611102e0362a5fc862401 dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: b80dc6b7d411ff0696a7c39e414ed5d72cf12a7c42244be35cb1c095cec15686 dotnet-hostfxr-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 492fd2b515c58c134f01c885d5ff3ab1a047e5b21377bce4a0b1fb48dae9a79d dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: 52231654d128cf7823a3574d6dbac58f544b21453be614c68cfa57ef592051a1 dotnet-runtime-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 35251b51914ea358e3ef936f3a417882d42e9ed442acce190e97dbe0e514fc1b dotnet-runtime-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: e3618c424061148896a60ab53860568fe31bd66028544f3106667290c6241e17 dotnet-runtime-dbg-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: bdddb696d6af8bb72710355d99ef159a9b06b1f024d4c65bbcba600a9578d4a4 dotnet-sdk-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 36b00b420c6038898fef144bdbc7301d454910480fc961015d05524e6fb7a970 dotnet-sdk-9.0-debuginfo-9.0.118-1.el10_2.x86_64.rpm SHA-256: b7c2dd2bb11c1223a4e65ef41573b92d2c5d256fffe6e74a051c59e527d0e167 dotnet-sdk-aot-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 21322659dfe81aad9850123f3051b807b88f35ec9e5690b0764f804a0eec86b9 dotnet-sdk-aot-9.0-debuginfo-9.0.118-1.el10_2.x86_64.rpm SHA-256: cf40470fd6dab56ba416e4c81f534259d7064b366dea9a477819357b29f5d761 dotnet-sdk-dbg-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 6a99a389f5dd38b198fdacffc11fdd008e467a84f0e95247c0fa07236d012561 dotnet-targeting-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 9807ad72f9f89bb4e64cf7439660a4fc32f4806ba43168de2cc382834fb3a097 dotnet-templates-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: e6be64f4d0e0cdcc4b11b8bb6be4c35a7892687f36c0bd552eca06a747f5c71c dotnet9.0-debugsource-9.0.118-1.el10_2.x86_64.rpm SHA-256: 8a7b921770472f665986df3005987c55aa8a23429ce3f07139677b1b33a7cc81 netstandard-targeting-pack-2.1-9.0.118-1.el10_2.x86_64.rpm SHA-256: 1c413785f0aa0f15bf508e505ef8077ba76fc896c6d96b9b2be35db45dbd4edf Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM dotnet9.0-9.0.118-1.el10_2.src.rpm SHA-256: 19962614a5ac88003e5e60717df1f1c5788c999ba77e8bcd389efbaac1531a3b x86_64 aspnetcore-runtime-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: a0fecfaf3ea3c28dbad022c8648face33bd9e1c52e133f37d764ce230e245f3f aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: c5536a94b6cdbe2c455a66c21b351f73e13d7175b0557e7edce72b2f98c98208 aspnetcore-targeting-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: e446cf5d36f9dc63e73230903b59ee52c6ca3aebfb7fdec20e5dd01796fa9c0c dotnet-apphost-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: dbe1022855ec249cad39f01a9fd9c8d2ed271d240c6611102e0362a5fc862401 dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: b80dc6b7d411ff0696a7c39e414ed5d72cf12a7c42244be35cb1c095cec15686 dotnet-hostfxr-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 492fd2b515c58c134f01c885d5ff3ab1a047e5b21377bce4a0b1fb48dae9a79d dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: 52231654d128cf7823a3574d6dbac58f544b21453be614c68cfa57ef592051a1 dotnet-runtime-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 35251b51914ea358e3ef936f3a417882d42e9ed442acce190e97dbe0e514fc1b dotnet-runtime-9.0-debuginfo-9.0.17-1.el10_2.x86_64.rpm SHA-256: e3618c424061148896a60ab53860568fe31bd66028544f3106667290c6241e17 dotnet-runtime-dbg-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: bdddb696d6af8bb72710355d99ef159a9b06b1f024d4c65bbcba600a9578d4a4 dotnet-sdk-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 36b00b420c6038898fef144bdbc7301d454910480fc961015d05524e6fb7a970 dotnet-sdk-9.0-debuginfo-9.0.118-1.el10_2.x86_64.rpm SHA-256: b7c2dd2bb11c1223a4e65ef41573b92d2c5d256fffe6e74a051c59e527d0e167 dotnet-sdk-aot-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 21322659dfe81aad9850123f3051b807b88f35ec9e5690b0764f804a0eec86b9 dotnet-sdk-aot-9.0-debuginfo-9.0.118-1.el10_2.x86_64.rpm SHA-256: cf40470fd6dab56ba416e4c81f534259d7064b366dea9a477819357b29f5d761 dotnet-sdk-dbg-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: 6a99a389f5dd38b198fdacffc11fdd008e467a84f0e95247c0fa07236d012561 dotnet-targeting-pack-9.0-9.0.17-1.el10_2.x86_64.rpm SHA-256: 9807ad72f9f89bb4e64cf7439660a4fc32f4806ba43168de2cc382834fb3a097 dotnet-templates-9.0-9.0.118-1.el10_2.x86_64.rpm SHA-256: e6be64f4d0e0cdcc4b11b8bb6be4c35a7892687f36c0bd552eca06a747f5c71c dotnet9.0-debugsource-9.0.118-1.el10_2.x86_64.rpm SHA-256: 8a7b921770472f665986df3005987c55aa8a23429ce3f07139677b1b33a7cc81 netstandard-targeting-pack-2.1-9.0.118-1.el10_2.x86_64.rpm SHA-256: 1c413785f0aa0f15bf508e505ef8077ba76fc896c6d96b9b2be35db45dbd4edf Red Hat Enterprise Linux for IBM z Systems 10 SRPM dotnet9.0-9.0.118-1.el10_2.src.rpm SHA-256: 19962614a5ac88003e5e60717df1f1c5788c999ba77e8bcd389efbaac1531a3b s390x aspnetcore-runtime-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 09dcb8f0020985272cc5227515f099a2c242541f665b2a61d5a641d4e830a733 aspnetcore-runtime-dbg-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 45a16342612c174872ee94822191df5a6dcf370001b05655bd093957f14a975d aspnetcore-targeting-pack-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 78a25590ce96d3709d7b0f1c7db0978ba18ac923c8e48e39ead9ee995c329afc dotnet-apphost-pack-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 878974c4457a19bfe69e9ccb4e35948b4450db761d120dc33096a2d303168eb7 dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el10_2.s390x.rpm SHA-256: d7b3a93236b5e3674f73adf84dd8d354f7485fa7e112c1d66184a82ae747050d dotnet-hostfxr-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 96e8f471100653578a14307f29b10edd03623211565a85dab3812a6db2327f43 dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el10_2.s390x.rpm SHA-256: 8029de48fdf7a2b44145fdbcd4b11b449d24bf7e8adcd161d0dd3c4628c14a1e dotnet-runtime-9.0-9.0.17-1.el10_2.s390x.rpm SHA-256: 8d4f753b51f25918972682618c7d5c412a6d08c7c649f64121a2b5d

Share this article