Red Hat Product Errata RHSA-2026:25221 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25221 - Security Advisory Overview Updated Packages Synopsis Important: .NET 9.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 9.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.118 and .NET Runtime 9.0.17.Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM dotnet9.0-9.0.118-1.el9_8.src.rpm SHA-256: 4c29d7b155717cefa045590d4bde35ae8a6fe527e5c3eb0aa70d343815d7f157 x86_64 aspnetcore-runtime-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: da376ce932f074bc41f530ec7b7c2b3b63d851bfd80886837bba902095002e1e aspnetcore-runtime-dbg-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 0b1661fdfd6928d4ba68b9095b203e1ba92c432387a584f1e566b44ae86e632c aspnetcore-targeting-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 441ff635217f9063e8491eb3ded70185aa070d0a3956249cdd005f2d33083ab2 dotnet-apphost-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 448b6f1d01ef38334cd08fa3ecebff43d94712859ac7cb4a2ce7b19b6c36d5fc dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 5a625281f6322ba9e837299daf3558d139c8b7cb95f089e8fc7535201087b522 dotnet-hostfxr-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 614606631fcea218045204f0a29474a4de3dab0e8578995d5624b0b65878b79a dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 58e36860238cde9358bce96cb0912cb971df63bf9a0dbaf9c6a2846aeb29abbe dotnet-runtime-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: d0929c5e77321e437fa464b202adf49792c793e8260c494c3038a7d23104f9eb dotnet-runtime-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 488fa86822f7590297908f384ab7562fe0f1dae942ced898d1d14b84c2d572b6 dotnet-runtime-dbg-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: d047a7b701c6d9be900bf3a8e2791fd76f91e8109ca325a6d69c51b5aa92713e dotnet-sdk-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: 992e7f3ddcc23602a3455a94c757bea6e35548faeff5afe874322c5608afd04a dotnet-sdk-9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: a9a75e46efc6cb811e4f97ce8308cfff90f5f10121f7d71077c4367e5aa9c522 dotnet-sdk-aot-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: c5ae2147beb63b1b2640fb79efb8d79beb4e3ea89adc4a9a6544b8b3c00af7a1 dotnet-sdk-aot-9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: 0973d65eb61e1a1e89999304728cc8e67875221e8642f9a67919e4510ff4c348 dotnet-sdk-dbg-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: e54a8c51d2eba32e362588d31afe72c2dacfa0b028c12f892fb947da0e45d60d dotnet-targeting-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 6caead043864ae608b4151b0c81eba399117b549a57fabc2b3aea71878b47514 dotnet-templates-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: ac7443e111c142d486a09ec3b5483bf455c45ab4ea5c3d139fc1ab509b0541b3 dotnet9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: 2bb8e67eeedef0fe2f6b24f81198aa22e908ec9fb38fc038486970a72c55344b dotnet9.0-debugsource-9.0.118-1.el9_8.x86_64.rpm SHA-256: 89885c7c1db77e22811e967f7da04ae1c8743237ce5fbf287040ad961d8f1815 netstandard-targeting-pack-2.1-9.0.118-1.el9_8.x86_64.rpm SHA-256: ff786b01b20d393ba45d29248966d9539d1e0f75aff5e0b193af079a31882732 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM dotnet9.0-9.0.118-1.el9_8.src.rpm SHA-256: 4c29d7b155717cefa045590d4bde35ae8a6fe527e5c3eb0aa70d343815d7f157 x86_64 aspnetcore-runtime-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: da376ce932f074bc41f530ec7b7c2b3b63d851bfd80886837bba902095002e1e aspnetcore-runtime-dbg-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 0b1661fdfd6928d4ba68b9095b203e1ba92c432387a584f1e566b44ae86e632c aspnetcore-targeting-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 441ff635217f9063e8491eb3ded70185aa070d0a3956249cdd005f2d33083ab2 dotnet-apphost-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 448b6f1d01ef38334cd08fa3ecebff43d94712859ac7cb4a2ce7b19b6c36d5fc dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 5a625281f6322ba9e837299daf3558d139c8b7cb95f089e8fc7535201087b522 dotnet-hostfxr-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 614606631fcea218045204f0a29474a4de3dab0e8578995d5624b0b65878b79a dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 58e36860238cde9358bce96cb0912cb971df63bf9a0dbaf9c6a2846aeb29abbe dotnet-runtime-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: d0929c5e77321e437fa464b202adf49792c793e8260c494c3038a7d23104f9eb dotnet-runtime-9.0-debuginfo-9.0.17-1.el9_8.x86_64.rpm SHA-256: 488fa86822f7590297908f384ab7562fe0f1dae942ced898d1d14b84c2d572b6 dotnet-runtime-dbg-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: d047a7b701c6d9be900bf3a8e2791fd76f91e8109ca325a6d69c51b5aa92713e dotnet-sdk-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: 992e7f3ddcc23602a3455a94c757bea6e35548faeff5afe874322c5608afd04a dotnet-sdk-9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: a9a75e46efc6cb811e4f97ce8308cfff90f5f10121f7d71077c4367e5aa9c522 dotnet-sdk-aot-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: c5ae2147beb63b1b2640fb79efb8d79beb4e3ea89adc4a9a6544b8b3c00af7a1 dotnet-sdk-aot-9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: 0973d65eb61e1a1e89999304728cc8e67875221e8642f9a67919e4510ff4c348 dotnet-sdk-dbg-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: e54a8c51d2eba32e362588d31afe72c2dacfa0b028c12f892fb947da0e45d60d dotnet-targeting-pack-9.0-9.0.17-1.el9_8.x86_64.rpm SHA-256: 6caead043864ae608b4151b0c81eba399117b549a57fabc2b3aea71878b47514 dotnet-templates-9.0-9.0.118-1.el9_8.x86_64.rpm SHA-256: ac7443e111c142d486a09ec3b5483bf455c45ab4ea5c3d139fc1ab509b0541b3 dotnet9.0-debuginfo-9.0.118-1.el9_8.x86_64.rpm SHA-256: 2bb8e67eeedef0fe2f6b24f81198aa22e908ec9fb38fc038486970a72c55344b dotnet9.0-debugsource-9.0.118-1.el9_8.x86_64.rpm SHA-256: 89885c7c1db77e22811e967f7da04ae1c8743237ce5fbf287040ad961d8f1815 netstandard-targeting-pack-2.1-9.0.118-1.el9_8.x86_64.rpm SHA-256: ff786b01b20d393ba45d29248966d9539d1e0f75aff5e0b193af079a31882732 Red Hat Enterprise Linux for IBM z Systems 9 SRPM dotnet9.0-9.0.118-1.el9_8.src.rpm SHA-256: 4c29d7b155717cefa045590d4bde35ae8a6fe527e5c3eb0aa70d343815d7f157 s390x aspnetcore-runtime-9.0-9.0.17-1.el9_8.s390x.rpm SHA-256: 5b610a03f0794954683b4bd7f45ec5f50150cb5c789924c53f8e77761f073aeb aspnetcore-runtime-dbg-9.0-9.0.17-1.el9_8.s390x.rpm SHA-256: f30878d691c450d929a5e6cf5dbe9361ac7297ad899e12ea5d9a13f59b3821ab aspnetcore-targeting-pack-9.0-9.0.17-1.el9_8.s390x.rpm SHA-256: 4b66f6d877ce95edb6ec2509d69daedb55aa8506986c5ec6853638848b4124f0 dotnet-apphost-pack-9.0-9.0.17-1.el9_8.s390x.rpm SHA-256: a581bdbea7448f82d714b37ac5e6e19fb70623db6f029e34252f8502d74edcea dotnet-apphost-pack-9.0-debuginfo-9.0.17-1.el9_8.s390x.rpm SHA-256: 5fb0245217ce16a9648bf5362d6a52ee26e0106709e2641c08fadcf33c0fbb20 dotnet-hostfxr-9.0-9.0.17-1.el9_8.s390x.rpm SHA-256: 5eb1594b845847d8cce352dc75aec42b8aa8746409de5cba13bcf0b212aefa06 dotnet-hostfxr-9.0-debuginfo-9.0.17-1.el9_8.s3
This security update addresses two vulnerabilities in .NET 9.0 on RHEL 9: a local file tampering via link following flaw (CVE-2026-45491, CVSS 6.2 MEDIUM) and an ASP.NET Core denial of service via resource consumption (CVE-2026-45591, CVSS 7.5 HIGH). The fix is contained in .NET SDK 9.0.118 and .NET Runtime 9.0.17. Red Hat has rated this update as Important and it applies to multiple architectures and support streams of Red Hat Enterprise Linux 9.