Red Hat Product Errata RHSA-2026:28011 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28011 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.128 and .NET Runtime 8.0.28. Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM dotnet8.0-8.0.128-1.el9_6.src.rpm SHA-256: 8d9661b142ecf225d14ea9f484411708e05247a13e5afaf018a34a39861a00cc x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 4e471016a212f51b6ff9faf7ebe3bdca66b1020dff25e07aef40183bfe1cd16d aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 78e9680b86941f15ef7f7f0505aeba45c74a5ffa1757197455fc8ff5d443cdff aspnetcore-targeting-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 603346df42fd2705b10da636cd8b8d59fe64214f55eb7d8be2f1142b7ad4980d dotnet-apphost-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 16be71b26e420babe1cbdb4958232fd878510f689d4658cd8c70f8a84a69e068 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: ad14839b49d1a1de7ea97f9cf17fce918201beb858664bd40e5d5c8299f0fd40 dotnet-hostfxr-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 720318d0984653eaf23a48a583716bb50baca912891bc06f42982c237cf4e718 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: e0affb8ddf0b299069da6cc4c8453cc3217536256eb9abe877b29f8a298874a6 dotnet-runtime-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 4c8d8ab1b82dee5d5bddfa157b92262e293cbb57ac2dafc0a6b853b0766027d4 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: cc089412a258b9c7c5d8745ba98b5af6035547745fee96ec246687629a8f2cfe dotnet-runtime-dbg-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 422ee068c92c469d9f537aabe33e9430b5864c9a1c7f4f1ff375e15ca670b064 dotnet-sdk-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 2938cc564e0b60f5bb67a279aae264515e2b9ed847b65617be9f050cc404a34f dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_6.x86_64.rpm SHA-256: 221e0479116e78f13281929ba916985028dcc61add335f0ae1524dbef766d179 dotnet-sdk-dbg-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 8014ad43f67bcdece8c0981e996e9c46b4c3c8c9e08674f3854af5609a0fa061 dotnet-targeting-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 465e4088a9ec62f893088d356a202adc9ead99efc1e7896544c40a6a5d65455d dotnet-templates-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 498fb513a4a4d25006aaf0795f699cbfc874257e75efcf9a3c8a3a92fbbbbda3 dotnet8.0-debuginfo-8.0.128-1.el9_6.x86_64.rpm SHA-256: c780c9dc9e0fd035cb4b4a54cb51cba2d2cb2504d429763700872ab79dac42a3 dotnet8.0-debugsource-8.0.128-1.el9_6.x86_64.rpm SHA-256: ce8f82cac7cbcad2e2781a979dd35c74393e768c5d0fe4bf164c182fa001b23c Red Hat Enterprise Linux Server - AUS 9.6 SRPM dotnet8.0-8.0.128-1.el9_6.src.rpm SHA-256: 8d9661b142ecf225d14ea9f484411708e05247a13e5afaf018a34a39861a00cc x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 4e471016a212f51b6ff9faf7ebe3bdca66b1020dff25e07aef40183bfe1cd16d aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 78e9680b86941f15ef7f7f0505aeba45c74a5ffa1757197455fc8ff5d443cdff aspnetcore-targeting-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 603346df42fd2705b10da636cd8b8d59fe64214f55eb7d8be2f1142b7ad4980d dotnet-apphost-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 16be71b26e420babe1cbdb4958232fd878510f689d4658cd8c70f8a84a69e068 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: ad14839b49d1a1de7ea97f9cf17fce918201beb858664bd40e5d5c8299f0fd40 dotnet-hostfxr-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 720318d0984653eaf23a48a583716bb50baca912891bc06f42982c237cf4e718 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: e0affb8ddf0b299069da6cc4c8453cc3217536256eb9abe877b29f8a298874a6 dotnet-runtime-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 4c8d8ab1b82dee5d5bddfa157b92262e293cbb57ac2dafc0a6b853b0766027d4 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_6.x86_64.rpm SHA-256: cc089412a258b9c7c5d8745ba98b5af6035547745fee96ec246687629a8f2cfe dotnet-runtime-dbg-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 422ee068c92c469d9f537aabe33e9430b5864c9a1c7f4f1ff375e15ca670b064 dotnet-sdk-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 2938cc564e0b60f5bb67a279aae264515e2b9ed847b65617be9f050cc404a34f dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_6.x86_64.rpm SHA-256: 221e0479116e78f13281929ba916985028dcc61add335f0ae1524dbef766d179 dotnet-sdk-dbg-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 8014ad43f67bcdece8c0981e996e9c46b4c3c8c9e08674f3854af5609a0fa061 dotnet-targeting-pack-8.0-8.0.28-1.el9_6.x86_64.rpm SHA-256: 465e4088a9ec62f893088d356a202adc9ead99efc1e7896544c40a6a5d65455d dotnet-templates-8.0-8.0.128-1.el9_6.x86_64.rpm SHA-256: 498fb513a4a4d25006aaf0795f699cbfc874257e75efcf9a3c8a3a92fbbbbda3 dotnet8.0-debuginfo-8.0.128-1.el9_6.x86_64.rpm SHA-256: c780c9dc9e0fd035cb4b4a54cb51cba2d2cb2504d429763700872ab79dac42a3 dotnet8.0-debugsource-8.0.128-1.el9_6.x86_64.rpm SHA-256: ce8f82cac7cbcad2e2781a979dd35c74393e768c5d0fe4bf164c182fa001b23c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM dotnet8.0-8.0.128-1.el9_6.src.rpm SHA-256: 8d9661b142ecf225d14ea9f484411708e05247a13e5afaf018a34a39861a00cc s390x aspnetcore-runtime-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: c8a1bb6c563fcf6e316ff6ba04044acdba867a5085019057374b25b801fa7c8b aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: ca57ff95b479f7ccc168beeaaec61208fde1a86fa8a069815bab7538c4b6f9cf aspnetcore-targeting-pack-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: 744d12dd4dfa2f66a8eaf6a0c742891582d728b321cc8d6ecb5d179d7c477870 dotnet-apphost-pack-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: cab0694ffbd830fb00adb6c623ea2e9641718082ab1a5e0d3dfaee58c2fb7507 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_6.s390x.rpm SHA-256: d5a461ac55d738256b62e0f3a60c078efd0768e6ee68b7ad3d2c22de51a06f6e dotnet-hostfxr-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: a8851524b09c485338c3d15b1954aa8e650021daf82f4196d74153d089a1cf8e dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_6.s390x.rpm SHA-256: d2eb83379e97300ab18b011ad4fb1ba51dcfd62ef6b0f115c8d884af693ef87a dotnet-runtime-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: 700655c8be8f4a613fe802e1e8b2372f35206c28e0e0fe3f90761b572e88f386 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_6.s390x.rpm SHA-256: cb531b0d855573bf7a7c322c76c623ee8597ac599509fbe7cf972bda51cec427 dotnet-runtime-dbg-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: 632b40342935b17b2f1a4016255ffd4042a52e8a49fb2a7244e95d101f34bd1e dotnet-sdk-8.0-8.0.128-1.el9_6.s390x.rpm SHA-256: 7d50332c3073e9694003e37281e1c9f862fb2d6e2bad1e5e46341a4009a24949 dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_6.s390x.rpm SHA-256: 8ccce0292f0a0861a7aa6995c03dd1fef830dcfa2caf7a779277eb6c2790d33e dotnet-sdk-dbg-8.0-8.0.128-1.el9_6.s390x.rpm SHA-256: d2d343dca8a254f0cd3b01fe0191f241230e7e563137b547af59feb445ae7c13 dotnet-targeting-pack-8.0-8.0.28-1.el9_6.s390x.rpm SHA-256: 4c64e9442a761ff8d03198c4a3e5f66a911b1be9e863569d1578acad13f7cd32 dotnet-templates-8.0-8.0.128-1.el9_6.s390x.rpm SHA-256: 944c48427ccbeed8fd4bbbd2c581449d8120b7bad9e7d9403eee23e3f89c5195 dotnet8.0-debuginfo-8.0.128-1.el9
This security update addresses two vulnerabilities in .NET 8.0: CVE-2026-45491 (CVSS 6.2), a local file tampering issue via link following, and CVE-2026-45591 (CVSS 7.5), an ASP.NET Core denial of service via resource consumption. Affected versions are .NET 8.0.0 through 8.0.27, ASP.NET Core 8.0.0 through 8.0.27, and Visual Studio 2026 18.6.0 through 18.6.2. The fix requires updating to .NET SDK/Runtime 8.0.28, ASP.NET Core 8.0.28, and Visual Studio 2026 18.6.3.