Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25220: Important: .NET 8.0 security update

This security update addresses two vulnerabilities in .NET 8.0 for Red Hat Enterprise Linux 9: CVE-2026-45491 (CVSS 6.2), a local file tampering issue via link following, and CVE-2026-45591 (CVSS 7.5), a denial of service via uncontrolled resource consumption in ASP.NET Core. The fixed versions are .NET SDK 8.0.128 and .NET Runtime 8.0.28. Administrators should apply the update following Red Hat's standard procedures.
Read Full Article →

Red Hat Product Errata RHSA-2026:25220 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25220 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.128 and .NET Runtime 8.0.28.Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM dotnet8.0-8.0.128-1.el9_8.src.rpm SHA-256: 39a6c1ec9e77a8848cb2238703faa3f69244c958c28b74db571b67e7bd9c9552 x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: d53ac92427a79fcd6b3eb036096553b426f46e53ec9ac69be329df41babd365a aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: deed7ee563861cf1ada72022b8bfa2ba3dca89d29b261b3ee6c29fab2be8036e aspnetcore-targeting-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 5dbdb9c8ec41756fa31826b96dbd7bacd4b10dac60d6449c3822502e4fa6aa33 dotnet-apphost-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: e7540e6e06aa40db9f626218b7f0203119db2bacffd982e650930771889be759 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 081d10d61e0ff317de9bf886ad349e48b6afcd232e40528d00b24aa047442613 dotnet-hostfxr-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: b581c7e1caa47a60e7a8b39e3a62bbbe7d1ebca8db3e57ddc44601647142b040 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 77a0abae1640ba1ca7d0d90ad6b9ace426ec6ef9ee7aee3ee9a40009c8d074e8 dotnet-runtime-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 7e7c261e97cf03341841bda29315b17ab52ed26109413976ba3d20938d8c80f9 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 2f4952b81fc12fdab6adc6fa61e6db1ac6a828152547e64037aa4468c04be5f1 dotnet-runtime-dbg-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: e0c1785acd801ac70ac917a702fdce2675103847a05b34d35032d1a00062688d dotnet-sdk-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: e3ae22eb049527cd15e3158c47470a99d35b3369718feb551f6b249e852d98cd dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_8.x86_64.rpm SHA-256: 04c37df20a268c3ed970ea06bae104ffb822ed194fc9b191352c02facbad6dcc dotnet-sdk-dbg-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: a94f040a10d6576f5066ecbc1465cf024193c4016f72eed85e9900d4cee964f5 dotnet-targeting-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 02eb2ac101a9f166d026719eddcbf42b5676529b02bc9ba1f75d4722e1e688b1 dotnet-templates-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: 5362f3fd28a6c3481838a3bad1a6ab02c3dcfed2fc547ee517370d07320bc10c dotnet8.0-debuginfo-8.0.128-1.el9_8.x86_64.rpm SHA-256: ce08f3718f288d40bfeb25a4bf0eee068ec9a765150a9ebb2b44dd192ce3e9f6 dotnet8.0-debugsource-8.0.128-1.el9_8.x86_64.rpm SHA-256: b4b1dcee0cb647d3014a507da3fc0517e7e8224f5154be7fa1fc3ed2d4edda40 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM dotnet8.0-8.0.128-1.el9_8.src.rpm SHA-256: 39a6c1ec9e77a8848cb2238703faa3f69244c958c28b74db571b67e7bd9c9552 x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: d53ac92427a79fcd6b3eb036096553b426f46e53ec9ac69be329df41babd365a aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: deed7ee563861cf1ada72022b8bfa2ba3dca89d29b261b3ee6c29fab2be8036e aspnetcore-targeting-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 5dbdb9c8ec41756fa31826b96dbd7bacd4b10dac60d6449c3822502e4fa6aa33 dotnet-apphost-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: e7540e6e06aa40db9f626218b7f0203119db2bacffd982e650930771889be759 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 081d10d61e0ff317de9bf886ad349e48b6afcd232e40528d00b24aa047442613 dotnet-hostfxr-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: b581c7e1caa47a60e7a8b39e3a62bbbe7d1ebca8db3e57ddc44601647142b040 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 77a0abae1640ba1ca7d0d90ad6b9ace426ec6ef9ee7aee3ee9a40009c8d074e8 dotnet-runtime-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 7e7c261e97cf03341841bda29315b17ab52ed26109413976ba3d20938d8c80f9 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_8.x86_64.rpm SHA-256: 2f4952b81fc12fdab6adc6fa61e6db1ac6a828152547e64037aa4468c04be5f1 dotnet-runtime-dbg-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: e0c1785acd801ac70ac917a702fdce2675103847a05b34d35032d1a00062688d dotnet-sdk-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: e3ae22eb049527cd15e3158c47470a99d35b3369718feb551f6b249e852d98cd dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_8.x86_64.rpm SHA-256: 04c37df20a268c3ed970ea06bae104ffb822ed194fc9b191352c02facbad6dcc dotnet-sdk-dbg-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: a94f040a10d6576f5066ecbc1465cf024193c4016f72eed85e9900d4cee964f5 dotnet-targeting-pack-8.0-8.0.28-1.el9_8.x86_64.rpm SHA-256: 02eb2ac101a9f166d026719eddcbf42b5676529b02bc9ba1f75d4722e1e688b1 dotnet-templates-8.0-8.0.128-1.el9_8.x86_64.rpm SHA-256: 5362f3fd28a6c3481838a3bad1a6ab02c3dcfed2fc547ee517370d07320bc10c dotnet8.0-debuginfo-8.0.128-1.el9_8.x86_64.rpm SHA-256: ce08f3718f288d40bfeb25a4bf0eee068ec9a765150a9ebb2b44dd192ce3e9f6 dotnet8.0-debugsource-8.0.128-1.el9_8.x86_64.rpm SHA-256: b4b1dcee0cb647d3014a507da3fc0517e7e8224f5154be7fa1fc3ed2d4edda40 Red Hat Enterprise Linux for IBM z Systems 9 SRPM dotnet8.0-8.0.128-1.el9_8.src.rpm SHA-256: 39a6c1ec9e77a8848cb2238703faa3f69244c958c28b74db571b67e7bd9c9552 s390x aspnetcore-runtime-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: a65f1e30cea3c06682b0bfb3e030763566d914bfec9970d621e1a5e92b0388f2 aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: df74433dfa501cc5d782adb182bf5112b9b28bd93c61fd7c9af27549b7c215ad aspnetcore-targeting-pack-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: f0f2cb3d057896cb318959d170fd654b607b47b6a82eb87be0c12d8ac572fc5f dotnet-apphost-pack-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: 58a9697fae243d9ce4dcac40ab36db1ceb6f6fb1482b42a152e99ed7a3ad1dcd dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_8.s390x.rpm SHA-256: f8fd88291e6172a16abcf8194d3613393663e1849a65b27d7efb4984f383b26e dotnet-hostfxr-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: da1a39b6d1d17b7a65b933d4709ed5b71ae28d17e6ca5d6a7a167c6b5b419fc3 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_8.s390x.rpm SHA-256: 7ba5b03626929bff434ee4df8819a76f04f2d68978a35f04341567186faeb065 dotnet-runtime-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: 72bdb1ed780102605c7d3688b798112a6df2a73f816a9d12d510af1bc6ce8f70 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_8.s390x.rpm SHA-256: afcc16090868c31892776a60d3b311e9ff81b5be24619de4a81ba1967b9be74f dotnet-runtime-dbg-8.0-8.0.28-1.el9_8.s390x.rpm SHA-256: 6c86476e64a016725b429c5b87743328007b8d1b3d1695dae6766e9512cfa061 dotnet-sdk-8.0-8.0.128-1.el9_8.s390x.rpm SHA-256: 77a9fe3403231a782ef7ec2eb6043e98dc0fcf7368dce15de218b58ddd3f8b12 dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_8.s390x.rpm SHA-256: dc8d75be62727fa269948b505a0e6914d60a958192c5c045ae1704a068dc0b16 dotnet-sdk-dbg-8.0-8.0.128-1.el9_8.s390x.rpm SHA-256: 78c0733cde9344fbf7b9

Share this article