An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: .NET Core 3.1 on RHEL 7 security and bugfix update Advisory ID: RHSA-2022:6522-01 Product: .NET Core on Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:6522 Issue date: 2022-09-14 CVE Names: CVE-2022-38013 ==================================================================== 1. Summary: An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 3.1.423 and .NET Runtime 3.1.29. Security Fix(es): * dotnet: DenialOfService - ASP.NET Core MVC vulnerable to stack overflow via ModelStateDictionary recursion. (CVE-2022-38013) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2125124 - CVE-2022-38013 dotnet: DenialOfService - ASP.NET Core MVC vulnerable to stack overflow via ModelStateDictionary recursion. 6. Package List: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7): Source: rh-dotnet31-dotnet-3.1.423-1.el7_9.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-host-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-source-built-artifacts-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.423-1.el7_9.x86_64.rpm .NET Core on Red Hat Enterprise Linux Server (v.7): Source: rh-dotnet31-dotnet-3.1.423-1.el7_9.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-host-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-source-built-artifacts-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.423-1.el7_9.x86_64.rpm .NET Core on Red Hat Enterprise Linux Workstation (v. 7): Source: rh-dotnet31-dotnet-3.1.423-1.el7_9.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-host-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-source-built-artifacts-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.29-1.el7_9.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.423-1.el7_9.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.423-1.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2022-38013 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYyInutzjgjWX9erEAQjThg/+MKqPc3jlUrNqUAS1LZhSCO6m0uW0uHeX XWJwV1fejIn8e2zo/DigEzqjDtXMAB8hizNNJbZJcubq/3o51WM2MWJOl/At8yIm zoAYuPOu+DmKbfWvHWQs/FrUMB4zyNXqmLWOZ1D0A7jf8ua7CJxJOtAdmm78uBFz EblFEzpNykOMsfWCvJJJ//NivHPlxiaQsS6P5oBFzlErSwHKFzjNpmpiErw4SA1T Z5GZSTpSBTrLKfjS1ZGV1tVAXMifISZbZUqg4NAbra6Zf2gfkyYs2wsRyn3fJ+JH o0aVY76ANHu3g98hW/Ng3T0ET9edLGOTAz15X4VX5DuFBqHTQFoKOEaDF/nZsN// a3eFpGRr4AQ1w8q+dWE20gzlr7o1w65Q1ltdsgXfqxrehLn1ApXIiWlhyoCWXxiW kqvicwdOdjJDK56MeZnFu6CjCGZqnR61WuZjbPqBty/Rkl2rHej4KFL2Q7s0CbQU Dh4hFEov9ZL2Qx7pCzYrk9G2RB7ljWfw+9vE4UP2FEiwgCK5qKxbmlkQbggULQxQ A6YGpvj/KamjagCktrnRC3BWEw8O1ulJChqR5TnllKt9+yunpKVJaVfOyAJNOVi7 JHrYj9JN/v2H98dmzNstrgJNDD/ePy0HZARTi/gMc06pPZoncpE+vedXMEJsUplM uKQk6IAD4Go=WeAO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
dotnet3.1 bug fix update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:1992', 'synopsis': 'dotnet3.1 bug fix update', 'severity': 'UnknownSeverity', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.', 'description': '.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': [], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:1992:::RHBA-2021:1992'], 'references': [], 'publishedAt': '2021-07-22T18:19:55.253790Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet3.1-3.1.117-1.el8_4.rocky.2.src.rpm', 'dotnet3.1-debuginfo-3.1.117-1.el8_4.rocky.2.x86_64.rpm', 'dotnet3.1-debugsource-3.1.117-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-runtime-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-sdk-3.1-3.1.117-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.117-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.17-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-templates-3.1-3.1.117-1.el8_4.rocky.2.x86_64.rpm']}\. A new update for .NET Core 3.1 has been released, focusing on resolving issues noted in Rocky Linux, thereby improving the overall performance and dependability of the software.. Rocky Linux Bug Fix, .NET Core Update, Software Maintenance. . LinuxSecurity.com Team
Important: .NET Core 3.1 security and bugfix update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:827', 'synopsis': 'Important: .NET Core 3.1 security and bugfix update', 'severity': 'Important', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': '.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\nNew versions of .NET that address security vulnerabilities are now available. The updated versions are .NET SDK 3.1.417 and .NET Runtime 3.1.23.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1879225', '2061847', '2061854'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-24464.json:::CVE-2022-24464', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-24512.json:::CVE-2022-24512'], 'references': [], 'publishedAt': '2022-03-11T02:20:26.239792Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.23-1.el8_5.x86_64.rpm', 'aspnetcore-runtime-5.0-5.0.15-1.el8_5.x86_64.rpm', 'aspnetcore-runtime-6.0-6.0.3-4.el8_5.aarch64.rpm', 'aspnetcore-runtime-6.0-6.0.3-4.el8_5.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.23-1.el8_5.x86_64.rpm', 'aspnetcore-targeting-pack-5.0-5.0.15-1.el8_5.x86_64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.3-4.el8_5.aarch64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-6.0.103-4.el8_5.x86_64.rpm', 'dotnet3.1-3.1.417-1.el8_5.src.rpm', 'dotnet3.1-debuginfo-3.1.417-1.el8_5.x86_64.rpm','dotnet5.0-5.0.212-1.el8_5.src.rpm', 'dotnet5.0-debuginfo-5.0.212-1.el8_5.x86_64.rpm', 'dotnet5.0-debugsource-5.0.212-1.el8_5.x86_64.rpm', 'dotnet6.0-6.0.103-4.el8_5.src.rpm', 'dotnet6.0-debuginfo-6.0.103-4.el8_5.aarch64.rpm', 'dotnet6.0-debuginfo-6.0.103-4.el8_5.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-apphost-pack-5.0-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-apphost-pack-5.0-debuginfo-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-apphost-pack-6.0-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-apphost-pack-6.0-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-host-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-host-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-host-debuginfo-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-host-debuginfo-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-hostfxr-5.0-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-hostfxr-5.0-debuginfo-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-hostfxr-6.0-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-hostfxr-6.0-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-runtime-3.1-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-runtime-5.0-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-runtime-5.0-debuginfo-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-runtime-6.0-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-runtime-6.0-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-sdk-3.1-3.1.417-1.el8_5.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.417-1.el8_5.x86_64.rpm', 'dotnet-sdk-3.1-source-built-artifacts-3.1.417-1.el8_5.x86_64.rpm', 'dotnet-sdk-5.0-5.0.212-1.el8_5.x86_64.rpm', 'dotnet-sdk-5.0-debuginfo-5.0.212-1.el8_5.x86_64.rpm','dotnet-sdk-5.0-source-built-artifacts-5.0.212-1.el8_5.x86_64.rpm', 'dotnet-sdk-6.0-6.0.103-4.el8_5.aarch64.rpm', 'dotnet-sdk-6.0-6.0.103-4.el8_5.x86_64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.103-4.el8_5.aarch64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.103-4.el8_5.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.23-1.el8_5.x86_64.rpm', 'dotnet-targeting-pack-5.0-5.0.15-1.el8_5.x86_64.rpm', 'dotnet-targeting-pack-6.0-6.0.3-4.el8_5.aarch64.rpm', 'dotnet-targeting-pack-6.0-6.0.3-4.el8_5.x86_64.rpm', 'dotnet-templates-3.1-3.1.417-1.el8_5.x86_64.rpm', 'dotnet-templates-5.0-5.0.212-1.el8_5.x86_64.rpm', 'dotnet-templates-6.0-6.0.103-4.el8_5.aarch64.rpm', 'dotnet-templates-6.0-6.0.103-4.el8_5.x86_64.rpm', 'netstandard-targeting-pack-2.1-6.0.103-4.el8_5.aarch64.rpm', 'netstandard-targeting-pack-2.1-6.0.103-4.el8_5.x86_64.rpm']}\. New patch for .NET Core 3.1 focusing on critical security vulnerabilities released for Rocky Linux 8 setups. Keep your systems safe!. dotnet Core Update, Rocky Linux Security, Bugfix Advisory. . Severity: Important. LinuxSecurity.com Team
Important: .NET Core 3.1 security and bugfix update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:2352', 'synopsis': 'Important: .NET Core 3.1 security and bugfix update', 'severity': 'Important', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': '.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 3.1.116 and .NET Runtime 3.1.16.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1966990'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-31957.json:::CVE-2021-31957'], 'references': [], 'publishedAt': '2021-07-22T03:27:08.553442Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'aspnetcore-runtime-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'aspnetcore-targeting-pack-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-5.0.204-1.el8_4.rocky.x86_64.rpm', 'dotnet3.1-3.1.116-1.el8_4.rocky.2.src.rpm', 'dotnet3.1-debuginfo-3.1.116-1.el8_4.rocky.2.x86_64.rpm', 'dotnet3.1-debugsource-3.1.116-1.el8_4.rocky.2.x86_64.rpm', 'dotnet5.0-5.0.204-1.el8_4.rocky.src.rpm', 'dotnet5.0-debuginfo-5.0.204-1.el8_4.rocky.x86_64.rpm', 'dotnet5.0-debugsource-5.0.204-1.el8_4.rocky.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm','dotnet-apphost-pack-3.1-debuginfo-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-apphost-pack-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-apphost-pack-5.0-debuginfo-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-host-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-host-debuginfo-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-hostfxr-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-hostfxr-5.0-debuginfo-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-runtime-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-runtime-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-runtime-5.0-debuginfo-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-sdk-3.1-3.1.116-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.116-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-sdk-5.0-5.0.204-1.el8_4.rocky.x86_64.rpm', 'dotnet-sdk-5.0-debuginfo-5.0.204-1.el8_4.rocky.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.16-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-targeting-pack-5.0-5.0.7-1.el8_4.rocky.x86_64.rpm', 'dotnet-templates-3.1-3.1.116-1.el8_4.rocky.2.x86_64.rpm', 'dotnet-templates-5.0-5.0.204-1.el8_4.rocky.x86_64.rpm', 'netstandard-targeting-pack-2.1-5.0.204-1.el8_4.rocky.x86_64.rpm']}\. Explore the vital .NET Core 3.1 security and bugfix enhancement released for Fedora OS to ensure the safety of systems.. dotnet Security Update, Rocky Linux Security, .NET Core Updates. . Severity: Important. LinuxSecurity.com Team
Important: .NET Core 3.1 security and bugfix update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:3142', 'synopsis': 'Important: .NET Core 3.1 security and bugfix update', 'severity': 'Important', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': '.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\nNew versions of .NET that address security vulnerabilities are now available. The updated versions are .NET SDK 3.1.118 and .NET Runtime 3.1.18.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1990286', '1990295', '1990300'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-26423.json:::CVE-2021-26423', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-34485.json:::CVE-2021-34485', 'Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-34532.json:::CVE-2021-34532'], 'references': [], 'publishedAt': '2021-08-12T20:59:59.370365Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'aspnetcore-runtime-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'aspnetcore-runtime-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'aspnetcore-targeting-pack-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-2.1.525-1.el8_4.rocky.src.rpm', 'dotnet-5.0.206-1.el8_4.rocky.1.x86_64.rpm','dotnet3.1-3.1.118-1.el8_4.rocky.1.src.rpm', 'dotnet3.1-3.1.118-1.el8.rocky.1.src.rpm', 'dotnet3.1-debuginfo-3.1.118-1.el8_4.rocky.1.x86_64.rpm', 'dotnet3.1-debuginfo-3.1.118-1.el8.rocky.1.x86_64.rpm', 'dotnet3.1-debugsource-3.1.118-1.el8_4.rocky.1.x86_64.rpm', 'dotnet3.1-debugsource-3.1.118-1.el8.rocky.1.x86_64.rpm', 'dotnet5.0-5.0.206-1.el8_4.rocky.1.src.rpm', 'dotnet5.0-debuginfo-5.0.206-1.el8_4.rocky.1.x86_64.rpm', 'dotnet5.0-debugsource-5.0.206-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-5.0-debuginfo-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-debuginfo-2.1.525-1.el8_4.rocky.x86_64.rpm', 'dotnet-debugsource-2.1.525-1.el8_4.rocky.x86_64.rpm', 'dotnet-host-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-host-debuginfo-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-host-fxr-2.1-2.1.29-1.el8_4.rocky.x86_64.rpm', 'dotnet-host-fxr-2.1-debuginfo-2.1.29-1.el8_4.rocky.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-hostfxr-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-hostfxr-5.0-debuginfo-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-2.1-2.1.29-1.el8_4.rocky.x86_64.rpm', 'dotnet-runtime-2.1-debuginfo-2.1.29-1.el8_4.rocky.x86_64.rpm', 'dotnet-runtime-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-runtime-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-5.0-debuginfo-5.0.9-1.el8_4.rocky.1.x86_64.rpm','dotnet-sdk-2.1-2.1.525-1.el8_4.rocky.x86_64.rpm', 'dotnet-sdk-2.1.5xx-2.1.525-1.el8_4.rocky.x86_64.rpm', 'dotnet-sdk-2.1.5xx-debuginfo-2.1.525-1.el8_4.rocky.x86_64.rpm', 'dotnet-sdk-3.1-3.1.118-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-sdk-3.1-3.1.118-1.el8.rocky.1.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.118-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.118-1.el8.rocky.1.x86_64.rpm', 'dotnet-sdk-5.0-5.0.206-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-sdk-5.0-debuginfo-5.0.206-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.18-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.18-1.el8.rocky.1.x86_64.rpm', 'dotnet-targeting-pack-5.0-5.0.9-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-templates-3.1-3.1.118-1.el8_4.rocky.1.x86_64.rpm', 'dotnet-templates-3.1-3.1.118-1.el8.rocky.1.x86_64.rpm', 'dotnet-templates-5.0-5.0.206-1.el8_4.rocky.1.x86_64.rpm', 'netstandard-targeting-pack-2.1-5.0.206-1.el8_4.rocky.1.x86_64.rpm']}\. Significant patch released for .NET Core 3.1 on Rocky Linux targeting urgent vulnerabilities and defects.. Dotnet Core Update, Rocky Linux Security, Software Bug Fixes. . Severity: Important. LinuxSecurity.com Team
Important: .NET Core 3.1 security, bug fix, and enhancement update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:2202', 'synopsis': 'Important: .NET Core 3.1 security, bug fix, and enhancement update', 'severity': 'Important', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': '.NET Core is a managed-software framework. It implements a subset of the .NET\nframework APIs and several new APIs, and it includes a CLR implementation.\nNew versions of .NET Core that address a security vulnerability are now available. The updated versions are .NET Core SDK 3.1.419 and .NET Core Runtime 3.1.25.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2083647', '2083649', '2083650'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-29117.json:::CVE-2022-29117'], 'references': [], 'publishedAt': '2022-05-18T19:33:16.948468Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.25-1.el8_6.x86_64.rpm', 'aspnetcore-runtime-5.0-5.0.17-1.el8_6.x86_64.rpm', 'aspnetcore-runtime-6.0-6.0.5-1.el8_6.aarch64.rpm', 'aspnetcore-runtime-6.0-6.0.5-1.el8_6.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.25-1.el8_6.x86_64.rpm', 'aspnetcore-targeting-pack-5.0-5.0.17-1.el8_6.x86_64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.5-1.el8_6.aarch64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-6.0.105-1.el8_6.x86_64.rpm', 'dotnet3.1-3.1.419-1.el8_6.src.rpm', 'dotnet3.1-debuginfo-3.1.419-1.el8_6.x86_64.rpm', 'dotnet5.0-5.0.214-1.el8_6.src.rpm','dotnet5.0-debuginfo-5.0.214-1.el8_6.x86_64.rpm', 'dotnet5.0-debugsource-5.0.214-1.el8_6.x86_64.rpm', 'dotnet6.0-6.0.105-1.el8_6.src.rpm', 'dotnet6.0-debuginfo-6.0.105-1.el8_6.aarch64.rpm', 'dotnet6.0-debuginfo-6.0.105-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-5.0-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-5.0-debuginfo-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-6.0-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-apphost-pack-6.0-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-host-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-host-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-host-debuginfo-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-host-debuginfo-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-5.0-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-5.0-debuginfo-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-6.0-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-hostfxr-6.0-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-runtime-3.1-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-runtime-5.0-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-runtime-5.0-debuginfo-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-runtime-6.0-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-runtime-6.0-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-3.1.419-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.419-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-source-built-artifacts-3.1.419-1.el8_6.x86_64.rpm', 'dotnet-sdk-5.0-5.0.214-1.el8_6.x86_64.rpm', 'dotnet-sdk-5.0-debuginfo-5.0.214-1.el8_6.x86_64.rpm','dotnet-sdk-5.0-source-built-artifacts-5.0.214-1.el8_6.x86_64.rpm', 'dotnet-sdk-6.0-6.0.105-1.el8_6.aarch64.rpm', 'dotnet-sdk-6.0-6.0.105-1.el8_6.x86_64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.105-1.el8_6.aarch64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.105-1.el8_6.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.25-1.el8_6.x86_64.rpm', 'dotnet-targeting-pack-5.0-5.0.17-1.el8_6.x86_64.rpm', 'dotnet-targeting-pack-6.0-6.0.5-1.el8_6.aarch64.rpm', 'dotnet-targeting-pack-6.0-6.0.5-1.el8_6.x86_64.rpm', 'dotnet-templates-3.1-3.1.419-1.el8_6.x86_64.rpm', 'dotnet-templates-5.0-5.0.214-1.el8_6.x86_64.rpm', 'dotnet-templates-6.0-6.0.105-1.el8_6.aarch64.rpm', 'dotnet-templates-6.0-6.0.105-1.el8_6.x86_64.rpm', 'netstandard-targeting-pack-2.1-6.0.105-1.el8_6.aarch64.rpm', 'netstandard-targeting-pack-2.1-6.0.105-1.el8_6.x86_64.rpm']}\. The latest .NET Core 3.1 update brings critical security improvements, bug resolutions, and performance upgrades, specifically benefiting users of Rocky Linux.. dotnet Core Update, Rocky Linux Security, Important Fixes. . Severity: Important. LinuxSecurity.com Team
.NET Core 3.1 bugfix update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:3817', 'synopsis': '.NET Core 3.1 bugfix update', 'severity': 'UnknownSeverity', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux.', 'description': '.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': [], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:3817:::RHBA-2021:3817'], 'references': [], 'publishedAt': '2021-10-13T06:46:27.116679Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet3.1-3.1.120-1.el8_4.rocky.0.src.rpm', 'dotnet3.1-debuginfo-3.1.120-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-runtime-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-sdk-3.1-3.1.120-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.120-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.20-1.el8_4.rocky.0.x86_64.rpm', 'dotnet-templates-3.1-3.1.120-1.el8_4.rocky.0.x86_64.rpm']}\. Patch issued for .NET Core 3.1 on Alpine Linux, fixing several potential bugs to enhance overall efficiency.. Rocky Linux Update,.NET Core Bugfix,Software Performance Fix. . LinuxSecurity.com Team
This is the June 2022 monthly update for .NET Core 3.1. It updates the SDK to version 3.1.420 and Runtime to 3.1.26 It includes fixes for CVE-2022-30184 Upstream release notes for .NET Core 3.1.26: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.26/3.1.26.md. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-cd37732349 2022-07-07 01:17:17.341232 --------------------------------------------------------------------------------Name : dotnet3.1 Product : Fedora 35 Version : 3.1.420 Release : 1.fc35 URL : https://github.com/dotnet/ Summary : .NET Core Runtime and SDK Description : .NET Core is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET Core contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. --------------------------------------------------------------------------------Update Information: This is the June 2022 monthly update for .NET Core 3.1. It updates the SDK to version 3.1.420 and Runtime to 3.1.26 It includes fixes for CVE-2022-30184 Upstream release notes for .NET Core 3.1.26: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.26/3.1.26.md --------------------------------------------------------------------------------ChangeLog: * Sat Jun 25 2022 Omair Majid - 3.1.420-1 - Update to .NET SDK 3.1.420 and Runtime 3.1.26 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-cd37732349' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.