RHSA-2026:58568HighCVSS 8.8

Red Hat Security Advisory: .NET 8.0 security, bug fix, and enhancement update

Published
August 24, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2026-47300 — ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm CVE-2026-47302 — dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation CVE-2026-47303 — ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass CVE-2026-47304 — dotnet: .NET Security Feature Bypass Vulnerability CVE-2026-50524 — dotnet: .NET Framework: Denial of Service via improper input validation CVE-2026-50525 — dotnet: .NET: Denial of Service due to uncontrolled resource allocation CVE-2026-50526 — dotnet: .NET: Local tampering via improper link resolution CVE-2026-50527 — dotnet: .NET Framework: Denial of Service via network-based buffer overflow CVE-2026-50528 — dotnet: .NET: Security feature bypass due to incorrect authorization CVE-2026-50646 — dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure CVE-2026-50648 — dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation CVE-2026-50649 — dotnet: .NET: Local code execution via deserialization of untrusted data CVE-2026-50650 — dotnet: .NET Framework: Privilege escalation via code injection CVE-2026-50651 — dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM CVE-2026-50659 — .NET: .NET: Network Spoofing Vulnerability CVE-2026-56170 — ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation CVE-2026-57108 — dotnet: .NET Core: Denial of Service via type confusion CVE-2026-62899 — .NET: .NET Core: .NET Security Feature Bypass Vulnerability CVE-2026-62900 — .NET: .NET Information Disclosure Vulnerability CVE-2026-62901 — .NET: .NET Denial of Service Vulnerability CVE-2026-62909 — .NET: .NET Elevation of Privilege Vulnerability

🎯 Affected products82

  • Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-8.0-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-8.0-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-8.0-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-8.0-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-dbg-8.0-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-dbg-8.0-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-dbg-8.0-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-runtime-dbg-8.0-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-targeting-pack-8.0-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-targeting-pack-8.0-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-targeting-pack-8.0-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • aspnetcore-targeting-pack-8.0-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-debuginfo-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-debuginfo-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-debuginfo-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-apphost-pack-8.0-debuginfo-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-debuginfo-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-debuginfo-0:8.0.30-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-debuginfo-0:8.0.30-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-host-debuginfo-0:8.0.30-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • dotnet-hostfxr-8.0-0:8.0.30-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • +52 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (24)