Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2667 http://linux.oracle.com/errata/ELSA-2025-2667.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aspnetcore-runtime-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm aspnetcore-runtime-dbg-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm aspnetcore-targeting-pack-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-9.0.104-1.0.1.el8_10.x86_64.rpm dotnet-apphost-pack-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-host-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-hostfxr-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-runtime-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-runtime-dbg-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-9.0.104-1.0.1.el8_10.x86_64.rpm dotnet-sdk-aot-9.0-9.0.104-1.0.1.el8_10.x86_64.rpm dotnet-sdk-dbg-9.0-9.0.104-1.0.1.el8_10.x86_64.rpm dotnet-targeting-pack-9.0-9.0.3-1.0.1.el8_10.x86_64.rpm dotnet-templates-9.0-9.0.104-1.0.1.el8_10.x86_64.rpm netstandard-targeting-pack-2.1-9.0.104-1.0.1.el8_10.x86_64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.104-1.0.1.el8_10.x86_64.rpm aarch64: aspnetcore-runtime-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm aspnetcore-runtime-dbg-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm aspnetcore-targeting-pack-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-9.0.104-1.0.1.el8_10.aarch64.rpm dotnet-apphost-pack-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-host-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-hostfxr-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-runtime-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-runtime-dbg-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-9.0.104-1.0.1.el8_10.aarch64.rpm dotnet-sdk-aot-9.0-9.0.104-1.0.1.el8_10.aarch64.rpm dotnet-sdk-dbg-9.0-9.0.104-1.0.1.el8_10.aarch64.rpm dotnet-targeting-pack-9.0-9.0.3-1.0.1.el8_10.aarch64.rpm dotnet-templates-9.0-9.0.104-1.0.1.el8_10.aarch64.rpm netstandard-targeting-pack-2.1-9.0.104-1.0.1.el8_10.aarch64.rpm dotnet-sdk-9.0-source-built-artifacts-9.0.104-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//dotnet9.0-9.0.104-1.0.1.el8_10.src.rpm Related CVEs: CVE-2025-24070 Description of changes: [9.0.104-1.0.1] - Add support for Oracle Linux [9.0.104-1] - Update to .NET SDK 9.0.104 and Runtime 9.0.3 - Resolves:RHEL-81645 _______________________________________________ El-errata mailing list
Important: .NET 8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:0381", "synopsis": "Important: .NET 8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.112 and .NET Runtime 8.0.1.12.\n\nSecurity Fix(es):\n\n* dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)\n* dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)\n* dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):\n\n* dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)\n\n* dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)\n\n* dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2337893", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337893", "description": ""}, {"ticket": "2337926", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337926", "description": ""}, {"ticket":"2337927", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337927", "description": ""}], "cves": [{"name": "CVE-2025-21172", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21172", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-21173", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21173", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-21176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21176", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-13T20:34:26.141542Z", "rpms": {"Rocky Linux 8": {"nvras": ["aspnetcore-runtime-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet8.0-0:8.0.112-1.el8_10.src.rpm", "dotnet8.0-debuginfo-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet8.0-debuginfo-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet8.0-debugsource-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet8.0-debugsource-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.12-1.el8_10.x86_64.rpm","dotnet-runtime-8.0-debuginfo-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.112-1.el8_10.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.12-1.el8_10.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.12-1.el8_10.x86_64.rpm", "dotnet-templates-8.0-0:8.0.112-1.el8_10.aarch64.rpm", "dotnet-templates-8.0-0:8.0.112-1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Major patch for .NET 8.0 addresses significant security flaws in Rocky Linux 8, including the potential for remote code execution exploits.. Rocky Linux 8, .NET security, Remote Code Execution, security update. . Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:0382", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.102 and .NET Runtime 9.0.1.\n\nSecurity Fix(es):\n\n* dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)\n* dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)\n* dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)\n* dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):\n\n* dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)\n\n* dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)\n\n* dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)\n\n* dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2337893", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337893", "description": ""}, {"ticket":"2337926", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337926", "description": ""}, {"ticket": "2337927", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337927", "description": ""}, {"ticket": "2337958", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2337958", "description": ""}], "cves": [{"name": "CVE-2025-21171", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21171", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-21172", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21172", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-21173", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21173", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-21176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-21176", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-13T20:34:26.141542Z", "rpms": {"Rocky Linux 8": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet9.0-0:9.0.102-1.el8_10.src.rpm", "dotnet9.0-debuginfo-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet9.0-debugsource-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.1-1.el8_10.aarch64.rpm","dotnet-apphost-pack-9.0-debuginfo-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-host-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-host-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-host-debuginfo-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-host-debuginfo-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.102-1.el8_10.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.1-1.el8_10.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.1-1.el8_10.x86_64.rpm", "dotnet-templates-9.0-0:9.0.102-1.el8_10.aarch64.rpm", "dotnet-templates-9.0-0:9.0.102-1.el8_10.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.102-1.el8_10.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.102-1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Recent .NET 9.0 updates focus on security improvements, especially for Rocky Linux users, addressing remote code execution threats effectively in applications.. dotnet security update, Rocky Linux advisory, .NET 9.0 update, security patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7867 http://linux.oracle.com/errata/ELSA-2024-7867.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm aspnetcore-targeting-pack-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm dotnet-apphost-pack-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm dotnet-hostfxr-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm dotnet-runtime-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm dotnet-sdk-6.0-6.0.135-1.0.1.el9_4.x86_64.rpm dotnet-targeting-pack-6.0-6.0.35-1.0.1.el9_4.x86_64.rpm dotnet-templates-6.0-6.0.135-1.0.1.el9_4.x86_64.rpm dotnet-sdk-6.0-source-built-artifacts-6.0.135-1.0.1.el9_4.x86_64.rpm aarch64: aspnetcore-runtime-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm aspnetcore-targeting-pack-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm dotnet-apphost-pack-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm dotnet-hostfxr-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm dotnet-runtime-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm dotnet-sdk-6.0-6.0.135-1.0.1.el9_4.aarch64.rpm dotnet-targeting-pack-6.0-6.0.35-1.0.1.el9_4.aarch64.rpm dotnet-templates-6.0-6.0.135-1.0.1.el9_4.aarch64.rpm dotnet-sdk-6.0-source-built-artifacts-6.0.135-1.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//dotnet6.0-6.0.135-1.0.1.el9_4.src.rpm Related CVEs: CVE-2024-43483 CVE-2024-43484 CVE-2024-43485 Description of changes: [6.0.135-1.0.1] - Add support for Oracle Linux [6.0.135-1] - Update to .NET SDK 6.0.135 and Runtime 6.0.35 - Resolves: RHEL-60798 [6.0.134-1] - Update to .NET SDK 6.0.134 and Runtime 6.0.34 - Resolves: RHEL-56683 _______________________________________________ El-errata mailing list
Important: dotnet8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4450", "synopsis": "Important: dotnet8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.\n\nSecurity Fix(es):\n\n* dotnet: DoS in System.Text.Json (CVE-2024-30105)\n\n* dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264)\n\n* dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2295320", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295320", "description": ""}, {"ticket": "2295321", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295321", "description": ""}, {"ticket": "2295323", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295323", "description": ""}], "cves": [{"name": "CVE-2024-30105", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-30105", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35264", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35264", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-38095","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-38095", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-07-15T12:18:41.969053Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "aspnetcore-runtime-8.0-0:8.0.7-1.el9_4.s390x.rpm", "aspnetcore-runtime-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el9_4.s390x.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el9_4.s390x.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet8.0-0:8.0.107-1.el9_4.src.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-host-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-host-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-host-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-host-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el9_4.x86_64.rpm","dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el9_4.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el9_4.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el9_4.ppc64le.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el9_4.s390x.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el9_4.x86_64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el9_4.aarch64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el9_4.ppc64le.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el9_4.s390x.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el9_4.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el9_4.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el9_4.ppc64le.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el9_4.s390x.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el9_4.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el9_4.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el9_4.ppc64le.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el9_4.s390x.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el9_4.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el9_4.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el9_4.ppc64le.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el9_4.s390x.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el9_4.x86_64.rpm","dotnet-templates-8.0-0:8.0.107-1.el9_4.aarch64.rpm", "dotnet-templates-8.0-0:8.0.107-1.el9_4.ppc64le.rpm", "dotnet-templates-8.0-0:8.0.107-1.el9_4.s390x.rpm", "dotnet-templates-8.0-0:8.0.107-1.el9_4.x86_64.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el9_4.aarch64.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el9_4.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el9_4.s390x.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crucial dotnet8.0 security patch for Rocky Linux 9 tackles DoS vulnerabilities with vital fixes.. dotnet update, Rocky Linux 9, security warning, DoS mitigation. . Severity: Important. LinuxSecurity.com Team
Important: dotnet8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4451", "synopsis": "Important: dotnet8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.\n\nSecurity Fix(es):\n\n* dotnet: DoS in System.Text.Json (CVE-2024-30105)\n\n* dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264)\n\n* dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2295320", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295320", "description": ""}, {"ticket": "2295321", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295321", "description": ""}, {"ticket": "2295323", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295323", "description": ""}], "cves": [{"name": "CVE-2024-30105", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-30105", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35264", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35264", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-38095","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-38095", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-07-15T12:17:49.133583Z", "rpms": {"Rocky Linux 8": {"nvras": ["dotnet-host-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-host-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-host-debuginfo-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el8_10.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet8.0-0:8.0.107-1.el8_10.src.rpm", "dotnet8.0-debuginfo-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet8.0-debuginfo-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet8.0-debugsource-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet8.0-debugsource-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.107-1.el8_10.x86_64.rpm","dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.107-1.el8_10.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el8_10.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.7-1.el8_10.x86_64.rpm", "dotnet-templates-8.0-0:8.0.107-1.el8_10.aarch64.rpm", "dotnet-templates-8.0-0:8.0.107-1.el8_10.x86_64.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el8_10.aarch64.rpm", "netstandard-targeting-pack-2.1-0:8.0.107-1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crucial security patch for dotnet 8.0 on Rocky Linux tackling severe vulnerabilities associated with Denial of Service (DoS) threats.. dotnet security, DoS vulnerabilities, Rocky Linux advisory, ASP.NET security updates. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4450 http://linux.oracle.com/errata/ELSA-2024-4450.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-apphost-pack-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-host-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-hostfxr-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-runtime-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-sdk-8.0-8.0.107-1.0.1.el9_4.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.107-1.0.1.el9_4.x86_64.rpm dotnet-targeting-pack-8.0-8.0.7-1.0.1.el9_4.x86_64.rpm dotnet-templates-8.0-8.0.107-1.0.1.el9_4.x86_64.rpm netstandard-targeting-pack-2.1-8.0.107-1.0.1.el9_4.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.107-1.0.1.el9_4.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-apphost-pack-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-host-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-hostfxr-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-runtime-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-sdk-8.0-8.0.107-1.0.1.el9_4.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.107-1.0.1.el9_4.aarch64.rpm dotnet-targeting-pack-8.0-8.0.7-1.0.1.el9_4.aarch64.rpm dotnet-templates-8.0-8.0.107-1.0.1.el9_4.aarch64.rpm netstandard-targeting-pack-2.1-8.0.107-1.0.1.el9_4.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.107-1.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//dotnet8.0-8.0.107-1.0.1.el9_4.src.rpm Related CVEs: CVE-2024-30105 CVE-2024-35264 CVE-2024-38095 Description of changes: [8.0.107-1.0.1] - Add support for OracleLinux [8.0.107-1] - Update to .NET SDK 8.0.107 and Runtime 8.0.7 - Resolves: RHEL-45324 _______________________________________________ El-errata mailing list
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-8420247612 2024-04-10 04:04:22.640628 -------------------------------------------------------------------------------- Name : dotnet7.0 Product : Fedora 39 Version : 7.0.117 Release : 1.fc39 URL : https://github.com/dotnet/ Summary : .NET Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: This is the March 2024 update for .NET 7. Release Notes: notes/7.0/7.0.17/7.0.17.md -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 30 2024 Omair Majid - 7.0.117-1 - Update to .NET SDK 7.0.117 and Runtime 7.0.17 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-8420247612' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.