Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25115: Important: .NET 10.0 security update

This Important Red Hat security advisory addresses two vulnerabilities in .NET 10.0: a local file tampering issue via link following (CVE-2026-45491, CVSS 6.2 MEDIUM) and an ASP.NET Core denial of service via resource consumption (CVE-2026-45591, CVSS 7.5 HIGH). The fix requires updating to .NET SDK 10.0.109 and .NET Runtime 10.0.9, which are detailed in the advisory for multiple Red Hat Enterprise Linux 10 architectures and support streams.
Read Full Article →

Red Hat Product Errata RHSA-2026:25115 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:25115 - Security Advisory Overview Updated Packages Synopsis Important: .NET 10.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 10.0 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.109 and .NET Runtime 10.0.9.Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM dotnet10.0-10.0.109-1.el10_2.src.rpm SHA-256: 23613f0786102b6c7840be74420255cbdbac7dc014a2ade1b7d0642148735ab2 x86_64 aspnetcore-runtime-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: b04ce8282c8b0453ecf56712cfe045f5492c4ee8b88c1e14f520ae2c1777ecfe aspnetcore-runtime-dbg-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: bf7c49f97412e653cfd8f282fc6afa2174e505f782bf597b82ac2e810eebbcdc aspnetcore-targeting-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 8a17fd6d4aa6e10e9d17a433e062162b8d1f02bc7eb10c810d3e350a0794045d dotnet-apphost-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 6d96203cf6d49d7138cd5845f87741de72ada14e5317cbfa8fa6b424ee17d476 dotnet-apphost-pack-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 15b7a501153006f40dc5238ae98ff5ff44822bf305eb2ba9f2447b8f6f5ad63a dotnet-host-10.0.9-1.el10_2.x86_64.rpm SHA-256: 0d4f0594990c27adbca20c445276359a81af187c865e6fdee55e1614360f5b01 dotnet-host-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 71c81cf136028a2f6ae2386362a4239b9eb0f1b2d3bcb93e2d3490e4e00fbd12 dotnet-hostfxr-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 8f3bc9d1825d611c3fadcec300f3fffa8f7b4786d2b25dfe1a05725901ca75e7 dotnet-hostfxr-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 6e241b365021db53927adab02afb0d6033f0d5ace183ead78de1148e8ae4ebfe dotnet-runtime-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 83584f8747609c8e68966cc6e2753d0d5e1c45ee38891de635fec1b26afeb7ea dotnet-runtime-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 04ba21c4eceeded949116b58a2e1b44c7ac3e87b70c1eb521c1ac5fc54306782 dotnet-runtime-dbg-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 185193b856a011d780888a16842db97f854c474cd53682217eda535b389ff69a dotnet-sdk-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 1cc4cefb3c37ef2c33fb26b85b2a6db6c5a5b344b57b5e8810821c50c6c9891f dotnet-sdk-10.0-debuginfo-10.0.109-1.el10_2.x86_64.rpm SHA-256: 47ab00a1a87a38b2f94294b62d51e755cce1bea2fdf092b5babbb2fc941dee60 dotnet-sdk-aot-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: c983dc8f3850f01296410a950db918e2c82718ec1bce0f0694bb4707d7c36c63 dotnet-sdk-aot-10.0-debuginfo-10.0.109-1.el10_2.x86_64.rpm SHA-256: 400b244acac3433504b9ccfaaff5bfaba0bb5bd49dd14dce075cd7df0cab26c2 dotnet-sdk-dbg-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 86ffa8aa4acb234d2f3743879e52b65847a24feef946dd0efc05898b725fe53c dotnet-targeting-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 62ba4fd4dda044479d519e4b2f0a86b064d3572f0b7d7e0538ac4c6da3b093a4 dotnet-templates-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 9f7ce7abee48245cd8f412065fba00bf6bac5d193a684d342bb8ed5b64f41b8f dotnet10.0-debugsource-10.0.109-1.el10_2.x86_64.rpm SHA-256: d7b1f037020644971960a3ef15b633f7dd613f26c57d52db79b627411d40c0ed Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM dotnet10.0-10.0.109-1.el10_2.src.rpm SHA-256: 23613f0786102b6c7840be74420255cbdbac7dc014a2ade1b7d0642148735ab2 x86_64 aspnetcore-runtime-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: b04ce8282c8b0453ecf56712cfe045f5492c4ee8b88c1e14f520ae2c1777ecfe aspnetcore-runtime-dbg-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: bf7c49f97412e653cfd8f282fc6afa2174e505f782bf597b82ac2e810eebbcdc aspnetcore-targeting-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 8a17fd6d4aa6e10e9d17a433e062162b8d1f02bc7eb10c810d3e350a0794045d dotnet-apphost-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 6d96203cf6d49d7138cd5845f87741de72ada14e5317cbfa8fa6b424ee17d476 dotnet-apphost-pack-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 15b7a501153006f40dc5238ae98ff5ff44822bf305eb2ba9f2447b8f6f5ad63a dotnet-host-10.0.9-1.el10_2.x86_64.rpm SHA-256: 0d4f0594990c27adbca20c445276359a81af187c865e6fdee55e1614360f5b01 dotnet-host-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 71c81cf136028a2f6ae2386362a4239b9eb0f1b2d3bcb93e2d3490e4e00fbd12 dotnet-hostfxr-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 8f3bc9d1825d611c3fadcec300f3fffa8f7b4786d2b25dfe1a05725901ca75e7 dotnet-hostfxr-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 6e241b365021db53927adab02afb0d6033f0d5ace183ead78de1148e8ae4ebfe dotnet-runtime-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 83584f8747609c8e68966cc6e2753d0d5e1c45ee38891de635fec1b26afeb7ea dotnet-runtime-10.0-debuginfo-10.0.9-1.el10_2.x86_64.rpm SHA-256: 04ba21c4eceeded949116b58a2e1b44c7ac3e87b70c1eb521c1ac5fc54306782 dotnet-runtime-dbg-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 185193b856a011d780888a16842db97f854c474cd53682217eda535b389ff69a dotnet-sdk-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 1cc4cefb3c37ef2c33fb26b85b2a6db6c5a5b344b57b5e8810821c50c6c9891f dotnet-sdk-10.0-debuginfo-10.0.109-1.el10_2.x86_64.rpm SHA-256: 47ab00a1a87a38b2f94294b62d51e755cce1bea2fdf092b5babbb2fc941dee60 dotnet-sdk-aot-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: c983dc8f3850f01296410a950db918e2c82718ec1bce0f0694bb4707d7c36c63 dotnet-sdk-aot-10.0-debuginfo-10.0.109-1.el10_2.x86_64.rpm SHA-256: 400b244acac3433504b9ccfaaff5bfaba0bb5bd49dd14dce075cd7df0cab26c2 dotnet-sdk-dbg-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 86ffa8aa4acb234d2f3743879e52b65847a24feef946dd0efc05898b725fe53c dotnet-targeting-pack-10.0-10.0.9-1.el10_2.x86_64.rpm SHA-256: 62ba4fd4dda044479d519e4b2f0a86b064d3572f0b7d7e0538ac4c6da3b093a4 dotnet-templates-10.0-10.0.109-1.el10_2.x86_64.rpm SHA-256: 9f7ce7abee48245cd8f412065fba00bf6bac5d193a684d342bb8ed5b64f41b8f dotnet10.0-debugsource-10.0.109-1.el10_2.x86_64.rpm SHA-256: d7b1f037020644971960a3ef15b633f7dd613f26c57d52db79b627411d40c0ed Red Hat Enterprise Linux for IBM z Systems 10 SRPM dotnet10.0-10.0.109-1.el10_2.src.rpm SHA-256: 23613f0786102b6c7840be74420255cbdbac7dc014a2ade1b7d0642148735ab2 s390x aspnetcore-runtime-10.0-10.0.9-1.el10_2.s390x.rpm SHA-256: 84edd95131ef5e8bf9d864bc1a7596958894b1e86d620f30898378d99c603572 aspnetcore-runtime-dbg-10.0-10.0.9-1.el10_2.s390x.rpm SHA-256: 23456a688741520c6dd3a7195d3a7b8ac27569e1820128f2be48684c0061185a aspnetcore-targeting-pack-10.0-10.0.9-1.el10_2.s390x.rpm SHA-256: 02d2bbe056e9b63f45df662f69491d45e561194d78dd6158744a99464eda4e94 dotnet-apphost-pack-10.0-10.0.9-1.el10_2.s390x.rpm SHA-256: bd58868d819c43d0ea4d30c4ce0b8ccbe69a8643a19434548297fe59f4442789 dotnet-apphost-pack-10.0-debuginfo-10.0.9-1.el10_2.s390x.rpm SHA-256: d1b84423e47212a24c3f280eacea5da8f9ded0e93dc8fc0124b11bc4c464552b dotnet-host-10.0.9-1.el10_2.s390x.rpm SHA-256: cecf2f6e7a3c64ce1422fcb571e5fdd23f49db3c

Share this article