{"id":"ALSA-2026:41897","summary":"Important: .NET 10.0 security, bug fix, and enhancement update","details":".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.  \n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10.  \n\nSecurity Fix(es):  \n\n  * dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)\n  * dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)\n  * ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)\n  * ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)\n  * ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)\n  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)\n  * dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)\n  * dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)\n  * dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)\n  * dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)\n  * dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)\n  * dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)\n  * dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)\n  * dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)\n  * .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)\n  * dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)\n\n\nBug Fix(es) and Enhancement(s):  \n\n  * Update .NET 10.0 to SDK 10.0.110 and Runtime 10.0.10 [almalinux-10.2.z] (JIRA:AlmaLinux-192463)\n  * dotnet10.0: Reduce time to detect hanging builds during .NET RPM builds (c10s) [almalinux-10.2.z] (JIRA:AlmaLinux-192326)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-07-31T15:59:58.804120311Z","published":"2026-07-20T00:00:00Z","related":["CVE-2026-47300","CVE-2026-47302","CVE-2026-47303","CVE-2026-47304","CVE-2026-50524","CVE-2026-50526","CVE-2026-50527","CVE-2026-50528","CVE-2026-50646","CVE-2026-50648","CVE-2026-50649","CVE-2026-50650","CVE-2026-50651","CVE-2026-50659","CVE-2026-56170","CVE-2026-57108"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41897"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47300"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47302"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47303"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47304"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50524"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50526"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50527"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50528"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50646"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50648"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50649"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50650"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50651"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-50659"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-56170"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-57108"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2499217"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500109"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500189"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500492"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500502"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500509"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500515"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500556"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500562"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500563"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500565"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500577"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500581"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500587"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2500593"},{"type":"ADVISORY","url":"https://errata.almalinux.org/10/ALSA-2026-41897.html"}],"affected":[{"package":{"name":"aspnetcore-runtime-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/aspnetcore-runtime-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"aspnetcore-runtime-dbg-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/aspnetcore-runtime-dbg-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"aspnetcore-targeting-pack-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/aspnetcore-targeting-pack-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-apphost-pack-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-apphost-pack-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-host","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-host"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-hostfxr-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-hostfxr-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-runtime-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-runtime-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-runtime-dbg-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-runtime-dbg-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-sdk-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-sdk-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.110-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-sdk-10.0-source-built-artifacts","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-sdk-10.0-source-built-artifacts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.110-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-sdk-aot-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-sdk-aot-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.110-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-sdk-dbg-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-sdk-dbg-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.110-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-targeting-pack-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-targeting-pack-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.10-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}},{"package":{"name":"dotnet-templates-10.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/dotnet-templates-10.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.110-1.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:41897.json"}}],"schema_version":"1.7.5"}