Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25222: Important: .NET 10.0 security update

This security update addresses two vulnerabilities in .NET 10.0: CVE-2026-45491 (CVSS 6.2), a local file tampering issue via link following, and CVE-2026-45591 (CVSS 7.5), a denial of service in ASP.NET Core via uncontrolled resource consumption. The fixed versions are .NET SDK 10.0.109 and .NET Runtime 10.0.9, which remediate these issues for .NET 10.0 on Red Hat Enterprise Linux 9 and its extended support variants.
Read Full Article →

Red Hat Product Errata RHSA-2026:25222 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25222 - Security Advisory Overview Updated Packages Synopsis Important: .NET 10.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 10.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.109 and .NET Runtime 10.0.9.Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM dotnet10.0-10.0.109-1.el9_8.src.rpm SHA-256: 93ae729d04bdab062fb00bb661f81fd730526bc67df4a04ad64f088a1550ae67 x86_64 aspnetcore-runtime-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 2262f45b5fdffd03a71783bc401eade6f358616ba9a8bc64566b37293863d5d3 aspnetcore-runtime-dbg-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 212e833056eba20a0b8a5ee6c847a0ab395233772fcf6bde79386042dc9d2630 aspnetcore-targeting-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 535abdc2a521b043fd99ef002d371e707610c4ee0ac9a4ad859b756fc6a50385 dotnet-apphost-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 8e0d3186af8cb143c93081c7371b39befcd8a4eca25d5d860fe5471339b8c10d dotnet-apphost-pack-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 0eaa035207f49d7a1d39f9482a744f3bc969bd864d2a4dcd4d66195408bcddec dotnet-host-10.0.9-1.el9_8.x86_64.rpm SHA-256: 301f1b86102975b431173b35540873801cdb8f517913537fc70af1e3fe6ba60b dotnet-host-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 63f422181e94dee8817c16a92f23a48d196e69dbf49b0a9575a0a941183bc926 dotnet-hostfxr-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: e35b2d6a29607cd3ceb5d70a2ffd5f10814a9837571e31ab4d896dd37dfca7b2 dotnet-hostfxr-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 057154d4624382cee6fc774a334b319731bcae8034001faa41ae029985bfa246 dotnet-runtime-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: cb7879edd191935f292afe528fe02b041fd322c7f22c0be7a8f5ac92ce47f108 dotnet-runtime-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 2be33e85fb4d0c15301a89e4d2ffb9d464ffde6c583e5e5e559c8f268e3517ac dotnet-runtime-dbg-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 24c857d724274cc921edd443c07089fa8cf55fc167c7a623962dbf5ecd77fefa dotnet-sdk-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 29acb90cb0e23a9e9d58e2d7c8c445a8d9606f136b9a523bae949d5c18dd3c53 dotnet-sdk-10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: a32b43a0483999f1160d37544115be8f212268d7c9a1908bf1c9363b5340a0bc dotnet-sdk-aot-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 1f5ab3237dfeb777371e7f16b8fffe6226a7c33213a9da527fe0b6d166cae6a1 dotnet-sdk-aot-10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: 0d3d293b210bccefad5a1cb9af6b9d518ca6702602574e57d19fbf1d9e1816ce dotnet-sdk-dbg-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 9b4b29ac127b9c8dbcd6eca82418c73f0716d1a5f515aba0c7542c0bb3f5ef99 dotnet-targeting-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 9d8762641a3f754a095440f88235d36fad04e4b272a61411aba88f0940bf9028 dotnet-templates-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 8a65852420acbb0771332431d94cb74b51a8ae4eeb67a9b15dab9089c6cbc455 dotnet10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: 6e8c0833270ceb7306cb3fb838b3782cfa5ffa2fccf955b32ab781b0cb1e8247 dotnet10.0-debugsource-10.0.109-1.el9_8.x86_64.rpm SHA-256: f42474a7eaa5440bfb4faaab5f0e588ca1165db6695080dbc348b9f339866f7e Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM dotnet10.0-10.0.109-1.el9_8.src.rpm SHA-256: 93ae729d04bdab062fb00bb661f81fd730526bc67df4a04ad64f088a1550ae67 x86_64 aspnetcore-runtime-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 2262f45b5fdffd03a71783bc401eade6f358616ba9a8bc64566b37293863d5d3 aspnetcore-runtime-dbg-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 212e833056eba20a0b8a5ee6c847a0ab395233772fcf6bde79386042dc9d2630 aspnetcore-targeting-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 535abdc2a521b043fd99ef002d371e707610c4ee0ac9a4ad859b756fc6a50385 dotnet-apphost-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 8e0d3186af8cb143c93081c7371b39befcd8a4eca25d5d860fe5471339b8c10d dotnet-apphost-pack-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 0eaa035207f49d7a1d39f9482a744f3bc969bd864d2a4dcd4d66195408bcddec dotnet-host-10.0.9-1.el9_8.x86_64.rpm SHA-256: 301f1b86102975b431173b35540873801cdb8f517913537fc70af1e3fe6ba60b dotnet-host-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 63f422181e94dee8817c16a92f23a48d196e69dbf49b0a9575a0a941183bc926 dotnet-hostfxr-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: e35b2d6a29607cd3ceb5d70a2ffd5f10814a9837571e31ab4d896dd37dfca7b2 dotnet-hostfxr-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 057154d4624382cee6fc774a334b319731bcae8034001faa41ae029985bfa246 dotnet-runtime-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: cb7879edd191935f292afe528fe02b041fd322c7f22c0be7a8f5ac92ce47f108 dotnet-runtime-10.0-debuginfo-10.0.9-1.el9_8.x86_64.rpm SHA-256: 2be33e85fb4d0c15301a89e4d2ffb9d464ffde6c583e5e5e559c8f268e3517ac dotnet-runtime-dbg-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 24c857d724274cc921edd443c07089fa8cf55fc167c7a623962dbf5ecd77fefa dotnet-sdk-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 29acb90cb0e23a9e9d58e2d7c8c445a8d9606f136b9a523bae949d5c18dd3c53 dotnet-sdk-10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: a32b43a0483999f1160d37544115be8f212268d7c9a1908bf1c9363b5340a0bc dotnet-sdk-aot-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 1f5ab3237dfeb777371e7f16b8fffe6226a7c33213a9da527fe0b6d166cae6a1 dotnet-sdk-aot-10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: 0d3d293b210bccefad5a1cb9af6b9d518ca6702602574e57d19fbf1d9e1816ce dotnet-sdk-dbg-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 9b4b29ac127b9c8dbcd6eca82418c73f0716d1a5f515aba0c7542c0bb3f5ef99 dotnet-targeting-pack-10.0-10.0.9-1.el9_8.x86_64.rpm SHA-256: 9d8762641a3f754a095440f88235d36fad04e4b272a61411aba88f0940bf9028 dotnet-templates-10.0-10.0.109-1.el9_8.x86_64.rpm SHA-256: 8a65852420acbb0771332431d94cb74b51a8ae4eeb67a9b15dab9089c6cbc455 dotnet10.0-debuginfo-10.0.109-1.el9_8.x86_64.rpm SHA-256: 6e8c0833270ceb7306cb3fb838b3782cfa5ffa2fccf955b32ab781b0cb1e8247 dotnet10.0-debugsource-10.0.109-1.el9_8.x86_64.rpm SHA-256: f42474a7eaa5440bfb4faaab5f0e588ca1165db6695080dbc348b9f339866f7e Red Hat Enterprise Linux for IBM z Systems 9 SRPM dotnet10.0-10.0.109-1.el9_8.src.rpm SHA-256: 93ae729d04bdab062fb00bb661f81fd730526bc67df4a04ad64f088a1550ae67 s390x aspnetcore-runtime-10.0-10.0.9-1.el9_8.s390x.rpm SHA-256: 2db82867658fac9fcfda99fc253dc156375676a8b4d1d3e28eee1a0197f25139 aspnetcore-runtime-dbg-10.0-10.0.9-1.el9_8.s390x.rpm SHA-256: 09aa911cbb08e20bdd719c1d5c79e1bd75e80e10a4a2dabcab86af7ba7d909a7 aspnetcore-targeting-pack-10.0-10.0.9-1.el9_8.s390x.rpm SHA-256: c4e9e412189dd2d90b3292f5a5ab7982b9868c1c767e42385bea8977eadbc184 dotnet-apphost-pack-10.0-10.0.9-1.el9_8.s390x.rpm SHA-256: 3acaab56256bdcd498ecb16eabf4288d61d9bc9517dedfc784aa1bc8d10be6cd dotnet-apphost-pack-10.0-d

Share this article