The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7571 http://linux.oracle.com/errata/ELSA-2025-7571.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aspnetcore-runtime-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm aspnetcore-runtime-dbg-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm aspnetcore-targeting-pack-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-9.0.106-1.0.1.el8_10.x86_64.rpm dotnet-apphost-pack-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-host-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-hostfxr-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-runtime-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-runtime-dbg-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-9.0.106-1.0.1.el8_10.x86_64.rpm dotnet-sdk-aot-9.0-9.0.106-1.0.1.el8_10.x86_64.rpm dotnet-sdk-dbg-9.0-9.0.106-1.0.1.el8_10.x86_64.rpm dotnet-targeting-pack-9.0-9.0.5-1.0.1.el8_10.x86_64.rpm dotnet-templates-9.0-9.0.106-1.0.1.el8_10.x86_64.rpm netstandard-targeting-pack-2.1-9.0.106-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.106-1.0.1.el8_10.x86_64.rpm aarch64: aspnetcore-runtime-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm aspnetcore-runtime-dbg-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm aspnetcore-targeting-pack-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-9.0.106-1.0.1.el8_10.aarch64.rpm dotnet-apphost-pack-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-host-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-hostfxr-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-runtime-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-runtime-dbg-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-9.0.106-1.0.1.el8_10.aarch64.rpm dotnet-sdk-aot-9.0-9.0.106-1.0.1.el8_10.aarch64.rpm dotnet-sdk-dbg-9.0-9.0.106-1.0.1.el8_10.aarch64.rpm dotnet-targeting-pack-9.0-9.0.5-1.0.1.el8_10.aarch64.rpm dotnet-templates-9.0-9.0.106-1.0.1.el8_10.aarch64.rpm netstandard-targeting-pack-2.1-9.0.106-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.106-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//dotnet9.0-9.0.106-1.0.1.el8_10.src.rpm Related CVEs: CVE-2025-26646 Description of changes: [9.0.106-1.0.1] - Add support for Oracle Linux [9.0.106-1] - Update to .NET SDK 9.0.106 and Runtime 9.0.5 - Resolves: RHEL-89451 [9.0.105-2] - Update to .NETSDK 9.0.105 and Runtime 9.0.4 - Resolves: RHEL-85279 _______________________________________________ El-errata mailing list
Several security issues were fixed in .NET.. ========================================================================== Ubuntu Security Notice USN-6773-1 May 16, 2024 dotnet7, dotnet8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in .NET. Software Description: - dotnet8: .NET CLI tools and runtime - dotnet7: .NET CLI tools and runtime Details: It was discovered that .NET did not properly handle memory in it's Double Parse routine. An attacker could possibly use this issue to achieve remote code execution. (CVE-2024-30045) It was discovered that .NET did not properly handle the usage of a shared resource. An attacker could possibly use this to cause a dead-lock condition, resulting in a denial of service. (CVE-2024-30046) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS aspnetcore-runtime-8.0 8.0.5-0ubuntu1~24.04.1 dotnet-host-8.0 8.0.5-0ubuntu1~24.04.1 dotnet-hostfxr-8.0 8.0.5-0ubuntu1~24.04.1 dotnet-runtime-8.0 8.0.5-0ubuntu1~24.04.1 dotnet-sdk-8.0 8.0.105-0ubuntu1~24.04.1 dotnet8 8.0.105-8.0.5-0ubuntu1~24.04.1 Ubuntu 23.10 aspnetcore-runtime-7.0 7.0.119-0ubuntu1~23.10.1 aspnetcore-runtime-8.0 8.0.5-0ubuntu1~23.10.1 dotnet-host-7.0 7.0.119-0ubuntu1~23.10.1 dotnet-host-8.0 8.0.5-0ubuntu1~23.10.1 dotnet-hostfxr-7.0 7.0.119-0ubuntu1~23.10.1 dotnet-hostfxr-8.0 8.0.5-0ubuntu1~23.10.1 dotnet-runtime-7.0 7.0.119-0ubuntu1~23.10.1 dotnet-runtime-8.0 8.0.5-0ubuntu1~23.10.1 dotnet-sdk-7.0 7.0.119-0ubuntu1~23.10.1 dotnet-sdk-8.0 8.0.105-0ubuntu1~23.10.1 dotnet7 7.0.119-0ubuntu1~23.10.1 dotnet8 8.0.105-8.0.5-0ubuntu1~23.10.1 Ubuntu 22.04 LTS aspnetcore-runtime-7.0 7.0.119-0ubuntu1~22.04.1 aspnetcore-runtime-8.0 8.0.5-0ubuntu1~22.04.1 dotnet-host-7.0 7.0.119-0ubuntu1~22.04.1 dotnet-host-8.0 8.0.5-0ubuntu1~22.04.1 dotnet-hostfxr-7.0 7.0.119-0ubuntu1~22.04.1 dotnet-hostfxr-8.0 8.0.5-0ubuntu1~22.04.1 dotnet-runtime-7.0 7.0.119-0ubuntu1~22.04.1 dotnet-runtime-8.0 8.0.5-0ubuntu1~22.04.1 dotnet-sdk-7.0 7.0.119-0ubuntu1~22.04.1 dotnet-sdk-8.0 8.0.105-0ubuntu1~22.04.1 dotnet7 7.0.119-0ubuntu1~22.04.1 dotnet8 8.0.105-8.0.5-0ubuntu1~22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6773-1 CVE-2024-30045, CVE-2024-30046 Package Information: https://launchpad.net/ubuntu/+source/dotnet8/8.0.105-8.0.5-0ubuntu1~24.04.1 https://launchpad.net/ubuntu/+source/dotnet7/7.0.119-0ubuntu1~23.10.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.105-8.0.5-0ubuntu1~23.10.1 https://launchpad.net/ubuntu/+source/dotnet7/7.0.119-0ubuntu1~22.04.1 https://launchpad.net/ubuntu/+source/dotnet8/8.0.105-8.0.5-0ubuntu1~22.04.1 . Uncover essential enhancements in .NET aimed at reducing vulnerabilities to remote execution and denial of service threats on Ubuntu systems. Ensure your security is robust now!. dotnet vulnerability update, remoteexecution mitigation, denial of service fixes, Ubuntu security patches. . Severity: Critical. LinuxSecurity.com Team
dotnet5.0 bugfix update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:2944', 'synopsis': 'dotnet5.0 bugfix update', 'severity': 'UnknownSeverity', 'topic': 'An update for .NET 5.0 is now available for Rocky Linux.', 'description': '.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': [], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:2944:::RHBA-2021:2944'], 'references': [], 'publishedAt': '2021-08-03T03:39:33.330581Z', 'rpms': ['aspnetcore-runtime-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'aspnetcore-targeting-pack-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'dotnet5.0-5.0.205-2.el8_4.rocky.1.src.rpm', 'dotnet5.0-debuginfo-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'dotnet5.0-debugsource-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-apphost-pack-5.0-debuginfo-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-host-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-host-debuginfo-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-hostfxr-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-hostfxr-5.0-debuginfo-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-runtime-5.0-debuginfo-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-sdk-5.0-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-sdk-5.0-debuginfo-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-targeting-pack-5.0-5.0.8-2.el8_4.rocky.1.x86_64.rpm', 'dotnet-templates-5.0-5.0.205-2.el8_4.rocky.1.x86_64.rpm', 'netstandard-targeting-pack-2.1-5.0.205-2.el8_4.rocky.1.x86_64.rpm']}\. The latest update for .NET 5.0 has been released for Rocky Linux, aiming to enhance functionality and resolve existing issues.. Rocky Linux Update,.Net Bugfix,Managed Software Framework. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.