Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:28227: Important: .NET 8.0 security update

  • What: Security update for .NET 8.0
  • Impact: Red Hat Enterprise Linux 9.4 systems
Read Full Article →

Red Hat Product Errata RHSA-2026:28227 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28227 - Security Advisory Overview Updated Packages Synopsis Important: .NET 8.0 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for .NET 8.0 is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.128 and .NET Runtime 8.0.28. Security Fix(es): dotnet: .NET: Local file tampering via link following vulnerability (CVE-2026-45491) dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption (CVE-2026-45591) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2487164 - CVE-2026-45491 dotnet: .NET: Local file tampering via link following vulnerability BZ - 2487224 - CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVEs CVE-2026-45491 CVE-2026-45591 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM dotnet8.0-8.0.128-1.el9_4.src.rpm SHA-256: de1fc7d57500fa8e3e748d94157e8af25ba3242b4365ed762d4ee43077975675 x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 6004eaab6c7698213841bfc5cf93526b0373b8e3a2e8df41c2e0c06274765f62 aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: c6ed88b028f85e0a9b78e134a234b2f7cc12b467a028504b70e5c0c03035e1c7 aspnetcore-targeting-pack-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: e5d57ce2dcea5821613a406be672fa6299faf172a50452df568b52cb1af15855 dotnet-apphost-pack-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 73b1df6f7cd11e96601bb0fdda8897f505f0fd65b9b4edcdcfa5696a013408f2 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 4dc92ac2e202dc67665df72fc6e137291de3c2e07f2505e1bff883bf44c22f32 dotnet-host-8.0.28-1.el9_4.x86_64.rpm SHA-256: f74e26ad6cbeaa6e1e4b503c726ae4026ce73c2c2696f397157a72608534ecfb dotnet-host-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 3ad0f5bebdc1c96e4625e78d02987b46411d2e52ee8d321f986ed76d11b3d3fa dotnet-hostfxr-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 16997a37031007b7cf6eb261ee4a0150e8c0ad10865201ac8f9e177de46e6620 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 1d9b162eb07293476bc6733ae9a55dfd68614241ef13fda0deebf12aceba5eb1 dotnet-runtime-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: e90788cb287094be471c4fc0156bd7c82a14515bd4a358f5a392cf18a72e3ea7 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 038567c90594e38b2563c75212a07791a69c2a728be6ea2e4dce2fdcf7fd5f75 dotnet-runtime-dbg-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: ef5ea436d22b27d773147a6d452f447c4ef7c7ed6ea64bfc7366c7e39f384e89 dotnet-sdk-8.0-8.0.128-1.el9_4.x86_64.rpm SHA-256: d00e7ef2fadd5e484606cd0ec4187be6687888b57b347fc8e5a6bad2ce41c1c1 dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_4.x86_64.rpm SHA-256: 161bfe492dae59ca3c725f934a58899297c2973d231ef3deed11e4c129f40251 dotnet-sdk-dbg-8.0-8.0.128-1.el9_4.x86_64.rpm SHA-256: edc2503605765d20b2b5cd971b17d5cb2cb99901ae5ab343b748500746b594a6 dotnet-targeting-pack-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 4fb2635c47a135b5f885efa2792592082593e022be579249e0e6536d33e405ba dotnet-templates-8.0-8.0.128-1.el9_4.x86_64.rpm SHA-256: a2ad5b2e8c4147dd2230e70541757ce5d83ad7ae46662181ce2cb505f1695dcc dotnet8.0-debuginfo-8.0.128-1.el9_4.x86_64.rpm SHA-256: 74004e47e072dfc08c9c9673eac2852d2a14ecb5b8ece46bf220d4c74d3a885a dotnet8.0-debugsource-8.0.128-1.el9_4.x86_64.rpm SHA-256: 531e093fd1c4ae735569a1216460e7ed4baf0dda70c4e16bfbe2157c4f8f4bb1 netstandard-targeting-pack-2.1-8.0.128-1.el9_4.x86_64.rpm SHA-256: 1aa0a667d64c5dad7701ef5bd7e4160d68d2fa7ef7a089405a0ba165c0d17d20 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM dotnet8.0-8.0.128-1.el9_4.src.rpm SHA-256: de1fc7d57500fa8e3e748d94157e8af25ba3242b4365ed762d4ee43077975675 ppc64le aspnetcore-runtime-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 173ecf9d37e8cdd082f2947973c3cb2911a133881ae16f854fa6482e10255f83 aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: a3514defe2795d0b9a640653fe244f8600ad7d7342fc6ca70dd53dadaed3ffd9 aspnetcore-targeting-pack-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: fd4530377e7f6d37408788f46641724aedb796369255b8236b5e333ab2575ead dotnet-apphost-pack-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 13cfac1caa349003a6da3c87fcf3a5690cf5642c006b246b194efd6a4f283ee6 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 8dbb7675f8f2a11c58b838f8909eb61d75668e404952b884bd42f9013aefab83 dotnet-host-8.0.28-1.el9_4.ppc64le.rpm SHA-256: a8d383d05640148273611d0c86aa1cba8242a13da5488e4308cba254d41d32ed dotnet-host-debuginfo-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 8297f33f47a8d9c6d263ba5bcfa939422710bd0da4b522efcbd57e64b2b9d6d6 dotnet-hostfxr-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 36e5669c52e26b1e1ca76e3d5c2e7521fae74d08f20f8d8d15ddba1ec1f7283a dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 6bacb79db253617a698594d56c8d159e4c9d08b2eba2ccaafbefb86f4b55779d dotnet-runtime-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: de15086c349824f5eed2a3df3af5ebbbedb4e33caeaca009fae886f678f85fbb dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 7a537f162a629510fe450f57536aeeaee76fdf36e661768d274354f307dfe549 dotnet-runtime-dbg-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: 508eb07b8e1150ec651d7c3eaf1bfa6dad3006f2cacc537ac0836617a6902238 dotnet-sdk-8.0-8.0.128-1.el9_4.ppc64le.rpm SHA-256: 6dace52767a1c0b11c5bd10e1a44cf8b1856da7312a862fbcafbe0efa006cc54 dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_4.ppc64le.rpm SHA-256: 6a71d1c89338fdd7b863df5edef8c04f9242026c998428ddfe776f4244d4b1be dotnet-sdk-dbg-8.0-8.0.128-1.el9_4.ppc64le.rpm SHA-256: e68951fca53b880c995dff3c61ae07af2ccbcb02bdc0bd42ce197bb9244ca161 dotnet-targeting-pack-8.0-8.0.28-1.el9_4.ppc64le.rpm SHA-256: f7849c616442bc6e72412b752ca5482c8605964193501c85f92a7aa3fd0df970 dotnet-templates-8.0-8.0.128-1.el9_4.ppc64le.rpm SHA-256: 541f936abf185c1bd0d29050b4c54616caf6e56af8b9e0f06860f83bbfe98808 dotnet8.0-debuginfo-8.0.128-1.el9_4.ppc64le.rpm SHA-256: d29d66c67b11833728561eb535197320962053cea4a56417b391428bf5ac3731 dotnet8.0-debugsource-8.0.128-1.el9_4.ppc64le.rpm SHA-256: dbc4be9f29191d34144f74b9c896915514ce5748cae9fd4faf7de0a1411d978b netstandard-targeting-pack-2.1-8.0.128-1.el9_4.ppc64le.rpm SHA-256: bd65dffff3a9e6722f75f19b174caa96c0680a7142a14cbca5526f9127213a2a Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM dotnet8.0-8.0.128-1.el9_4.src.rpm SHA-256: de1fc7d57500fa8e3e748d94157e8af25ba3242b4365ed762d4ee43077975675 x86_64 aspnetcore-runtime-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 6004eaab6c7698213841bfc5cf93526b0373b8e3a2e8df41c2e0c06274765f62 aspnetcore-runtime-dbg-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: c6ed88b028f85e0a9b78e134a234b2f7cc12b467a028504b70e5c0c03035e1c7 aspnetcore-targeting-pack-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: e5d57ce2dcea5821613a406be672fa6299faf172a50452df568b52cb1af15855 dotnet-apphost-pack-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 73b1df6f7cd11e96601bb0fdda8897f505f0fd65b9b4edcdcfa5696a013408f2 dotnet-apphost-pack-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 4dc92ac2e202dc67665df72fc6e137291de3c2e07f2505e1bff883bf44c22f32 dotnet-host-8.0.28-1.el9_4.x86_64.rpm SHA-256: f74e26ad6cbeaa6e1e4b503c726ae4026ce73c2c2696f397157a72608534ecfb dotnet-host-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 3ad0f5bebdc1c96e4625e78d02987b46411d2e52ee8d321f986ed76d11b3d3fa dotnet-hostfxr-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: 16997a37031007b7cf6eb261ee4a0150e8c0ad10865201ac8f9e177de46e6620 dotnet-hostfxr-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 1d9b162eb07293476bc6733ae9a55dfd68614241ef13fda0deebf12aceba5eb1 dotnet-runtime-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: e90788cb287094be471c4fc0156bd7c82a14515bd4a358f5a392cf18a72e3ea7 dotnet-runtime-8.0-debuginfo-8.0.28-1.el9_4.x86_64.rpm SHA-256: 038567c90594e38b2563c75212a07791a69c2a728be6ea2e4dce2fdcf7fd5f75 dotnet-runtime-dbg-8.0-8.0.28-1.el9_4.x86_64.rpm SHA-256: ef5ea436d22b27d773147a6d452f447c4ef7c7ed6ea64bfc7366c7e39f384e89 dotnet-sdk-8.0-8.0.128-1.el9_4.x86_64.rpm SHA-256: d00e7ef2fadd5e484606cd0ec4187be6687888b57b347fc8e5a6bad2ce41c1c1 dotnet-sdk-8.0-debuginfo-8.0.128-1.el9_4.x86_64.rpm SHA-256: 161bfe492dae59ca3c725f934a58899297c2973d231ef3deed11e4c129f40251 dotnet-sdk-dbg-8.0-8.0

Share this article