{"id":"RLSA-2026:41899","summary":"Important: .NET 9.0 security, bug fix, and enhancement update","details":".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18.\n\nSecurity Fix(es):\n\n* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)\n\n* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)\n\n* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)\n\n* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)\n\n* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)\n\n* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)\n\n* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)\n\n* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)\n\n* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)\n\n* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)\n\n* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)\n\n* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)\n\n* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)\n\n* dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)\n\n* dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)\n\n* .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)\n\n* dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)\n\nBug Fix(es) and Enhancement(s):\n\n* Update .NET 9.0 to SDK 9.0.119 and Runtime 9.0.18 (JIRA:Rocky Linux-192469)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-07-23T06:30:08.094460487Z","published":"2026-07-23T06:01:27.843611Z","upstream":["CVE-2026-47300","CVE-2026-47302","CVE-2026-47303","CVE-2026-47304","CVE-2026-50524","CVE-2026-50525","CVE-2026-50526","CVE-2026-50527","CVE-2026-50528","CVE-2026-50646","CVE-2026-50648","CVE-2026-50649","CVE-2026-50650","CVE-2026-50651","CVE-2026-50659","CVE-2026-56170","CVE-2026-57108"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:41899"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499217"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500109"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500189"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500492"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500502"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500509"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500515"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500556"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500562"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500563"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500565"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500577"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500580"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500581"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500587"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500589"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500593"}],"affected":[{"package":{"name":"dotnet9.0","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/dotnet9.0?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:9.0.119-1.el8_10"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:41899.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}