Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
217

Oracle Linux 8 ELSA-2024-3345 Critical .NET 8.0 Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-3345 http://linux.oracle.com/errata/ELSA-2024-3345.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-8.0.105-1.0.1.el8_10.x86_64.rpm dotnet-apphost-pack-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-host-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-hostfxr-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-runtime-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-sdk-8.0-8.0.105-1.0.1.el8_10.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.105-1.0.1.el8_10.x86_64.rpm dotnet-targeting-pack-8.0-8.0.5-1.0.1.el8_10.x86_64.rpm dotnet-templates-8.0-8.0.105-1.0.1.el8_10.x86_64.rpm netstandard-targeting-pack-2.1-8.0.105-1.0.1.el8_10.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.105-1.0.1.el8_10.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-8.0.105-1.0.1.el8_10.aarch64.rpm dotnet-apphost-pack-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-host-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-hostfxr-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-runtime-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-sdk-8.0-8.0.105-1.0.1.el8_10.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.105-1.0.1.el8_10.aarch64.rpm dotnet-targeting-pack-8.0-8.0.5-1.0.1.el8_10.aarch64.rpm dotnet-templates-8.0-8.0.105-1.0.1.el8_10.aarch64.rpm netstandard-targeting-pack-2.1-8.0.105-1.0.1.el8_10.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.105-1.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//dotnet8.0-8.0.105-1.0.1.el8_10.src.rpm RelatedCVEs: CVE-2024-30045 CVE-2024-30046 Description of changes: [8.0.105-1.0.1] - Add support for Oracle Linux [8.0.105-1] - Update to .NET SDK 8.0.105 and Runtime 8.0.5 - Resolves: RHEL-35316 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2024-3345 resolves critical vulnerabilities present in .NET 8.0 packages, enhancing system integrity.. Oracle Linux Update, Security Advisory, .NET Security Patch, Oracle Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 30, 2024 Critical Oracle
217

Oracle Linux 8 ELSA-2022-6912 Moderate: .NET Core 3.1 Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6912 https://linux.oracle.com/errata/ELSA-2022-6912.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm aspnetcore-targeting-pack-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm dotnet-apphost-pack-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm dotnet-hostfxr-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm dotnet-runtime-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm dotnet-sdk-3.1-3.1.424-1.0.1.el8_6.x86_64.rpm dotnet-targeting-pack-3.1-3.1.30-1.0.1.el8_6.x86_64.rpm dotnet-templates-3.1-3.1.424-1.0.1.el8_6.x86_64.rpm dotnet-sdk-3.1-source-built-artifacts-3.1.424-1.0.1.el8_6.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/dotnet3.1-3.1.424-1.0.1.el8_6.src.rpm Related CVEs: CVE-2022-41032 Description of changes: [3.1.424-1.0.1] - Add missing Oracle Linux Runtime IDs [3.1.424-1] - Update to .NET SDK 3.1.424 and Runtime 3.1.30 - Resolves: RHBZ#2131728 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Oracle Linux Advisory ELSA-2022-6912 presents a significant security update for .NET Core 3.1, reinforcing system protection.. Oracle Linux Update, .NET Core Security, ELSA-2022-6912. . LinuxSecurity.com Team

Calendar%202 Oct 13, 2022 Oracle
219

Rocky Linux 8 RLSA-2022:5061 Moderate: .NET Core Bugfix Update

Moderate: .NET Core 3.1 security and bugfix update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2022:5061', 'synopsis': 'Moderate: .NET Core 3.1 security and bugfix update', 'severity': 'Moderate', 'topic': 'An update for .NET Core 3.1 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': '.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 3.1.420 and .NET Runtime 3.1.26.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2096963'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-30184.json:::CVE-2022-30184'], 'references': [], 'publishedAt': '2022-07-07T20:06:59.336173Z', 'rpms': ['aspnetcore-runtime-3.1-3.1.26-1.el8_6.x86_64.rpm', 'aspnetcore-runtime-6.0-6.0.6-1.el8_6.aarch64.rpm', 'aspnetcore-runtime-6.0-6.0.6-1.el8_6.x86_64.rpm', 'aspnetcore-targeting-pack-3.1-3.1.26-1.el8_6.x86_64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.6-1.el8_6.aarch64.rpm', 'aspnetcore-targeting-pack-6.0-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-6.0.106-1.el8_6.x86_64.rpm', 'dotnet3.1-3.1.420-1.el8_6.src.rpm', 'dotnet3.1-debuginfo-3.1.420-1.el8_6.x86_64.rpm', 'dotnet6.0-6.0.106-1.el8_6.src.rpm', 'dotnet6.0-debuginfo-6.0.106-1.el8_6.aarch64.rpm', 'dotnet6.0-debuginfo-6.0.106-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-3.1-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-3.1-debuginfo-3.1.26-1.el8_6.x86_64.rpm','dotnet-apphost-pack-6.0-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-apphost-pack-6.0-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-apphost-pack-6.0-debuginfo-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-host-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-host-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-host-debuginfo-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-host-debuginfo-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-3.1-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-3.1-debuginfo-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-6.0-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-hostfxr-6.0-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-hostfxr-6.0-debuginfo-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-runtime-3.1-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-runtime-3.1-debuginfo-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-runtime-6.0-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-runtime-6.0-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-runtime-6.0-debuginfo-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-3.1.420-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-debuginfo-3.1.420-1.el8_6.x86_64.rpm', 'dotnet-sdk-3.1-source-built-artifacts-3.1.420-1.el8_6.x86_64.rpm', 'dotnet-sdk-6.0-6.0.106-1.el8_6.aarch64.rpm', 'dotnet-sdk-6.0-6.0.106-1.el8_6.x86_64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.106-1.el8_6.aarch64.rpm', 'dotnet-sdk-6.0-debuginfo-6.0.106-1.el8_6.x86_64.rpm', 'dotnet-targeting-pack-3.1-3.1.26-1.el8_6.x86_64.rpm', 'dotnet-targeting-pack-6.0-6.0.6-1.el8_6.aarch64.rpm', 'dotnet-targeting-pack-6.0-6.0.6-1.el8_6.x86_64.rpm', 'dotnet-templates-3.1-3.1.420-1.el8_6.x86_64.rpm', 'dotnet-templates-6.0-6.0.106-1.el8_6.aarch64.rpm', 'dotnet-templates-6.0-6.0.106-1.el8_6.x86_64.rpm', 'netstandard-targeting-pack-2.1-6.0.106-1.el8_6.aarch64.rpm', 'netstandard-targeting-pack-2.1-6.0.106-1.el8_6.x86_64.rpm']}\. An updated version of .NET Core 3.1 for Rocky Linux is now available, bringing vital security enhancements and important bug fixes to improve overall performance.. Rocky Linux Update, .NETCore Patch, .NET Security Fix, Rocky Security Advisory, Bugfix Upgrade. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
98

Red Hat 7: RHSA-2021-0096-01 Important: ASP.NET Deadlock Fix

An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: .NET 5.0 on Red Hat Enterprise Linux security and bugfix update Advisory ID: RHSA-2021:0096-01 Product: .NET Core on Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0096 Issue date: 2021-01-13 CVE Names: CVE-2021-1723 ==================================================================== 1. Summary: An update for rh-dotnet50-dotnet is now available for .NET on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 5.0.102 and .NET Runtime 5.0.2. Security Fix(es): * dotnet: ASP.NET Core Callbacks outside of locks cause Krestel deadlock when using HTTP2 (CVE-2021-1723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details onhow to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1914258 - CVE-2021-1723 dotnet: ASP.NET Core Callbacks outside of locks cause Krestel deadlock when using HTTP2 6. Package List: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7): Source: rh-dotnet50-dotnet-5.0.102-1.el7_9.src.rpm x86_64: rh-dotnet50-aspnetcore-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-aspnetcore-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-apphost-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-debuginfo-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-host-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-hostfxr-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-sdk-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-templates-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-netstandard-targeting-pack-2.1-5.0.102-1.el7_9.x86_64.rpm .NET Core on Red Hat Enterprise Linux Server (v. 7): Source: rh-dotnet50-dotnet-5.0.102-1.el7_9.src.rpm x86_64: rh-dotnet50-aspnetcore-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-aspnetcore-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-apphost-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-debuginfo-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-host-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-hostfxr-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-sdk-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-templates-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-netstandard-targeting-pack-2.1-5.0.102-1.el7_9.x86_64.rpm .NET Core on Red Hat Enterprise Linux Workstation (v.7): Source: rh-dotnet50-dotnet-5.0.102-1.el7_9.src.rpm x86_64: rh-dotnet50-aspnetcore-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-aspnetcore-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-apphost-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-debuginfo-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-host-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-hostfxr-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-runtime-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-sdk-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-targeting-pack-5.0-5.0.2-1.el7_9.x86_64.rpm rh-dotnet50-dotnet-templates-5.0-5.0.102-1.el7_9.x86_64.rpm rh-dotnet50-netstandard-targeting-pack-2.1-5.0.102-1.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-1723 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIUAwUBX/8ENtzjgjWX9erEAQjh5A/2IdPxRp4QSVH27LBp52uli+P8iYNYUQzJ oSP0BhxXlPnwty70y6h3XF04F2AgWdqddLa07e/lQo/tZfD4x8a7N5qJzCd3AaHy bhQaw5Rs2Yi/JM3l7nJbwL3kMnQ6+rg/w9IZG0JLPjEnURlcJmIArgIuNmWPBoxP GRVhNlEohEwbQhgwwp0PJkIhX9MxvpVT0OPbcUV6TGox65X+b8kMuUfjRhuKdEge l97WHuXTXa6QZMgaH28lSe8Vo6tkhzH89UEgo4CweybzptzPEgNfD4GOfpOrt9HG iqiRhMnpVrfp+nqet1k+seBfjeTkMfZBmrGR8nsU69rCqG85gWvtuT5j5ba5PWRg hHAg/bG4zIRlvRgIgTD00wVkGL0DC4zE/iI3bXZ7ATdl8pCADi1+uRyBwshbjbvL jFo8RrHE4DCtM1+X0jJhPnED3tMQmNQkmYd/sUzj6dM1OfYUFu6CDnyqOo9wIPkD yYTKp1/2lM8eJDtihM4vRRtfBUicagPAQ7Qu52VjDs9PwtSAReDE0FAnnfqfoRqt FXwdqez+GIpc6JgVp+wgof9zY3mq+MKS3WKZwt+v7KUbsSrg0sQTYpuMI+JFjG9l ZzAeU/ifax0HbO4R3rz2evVsT4yLGcSW7Yb/cTuPypLMFojFpSDzpkODfw3TGArj allfL6TeAQ==fmd6 -----END PGPSIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ====================================================. update, rh-dotnet50-dotnet, enterprise, linux. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 13, 2021 Important Red Hat
98

RedHat: RHSA-2020-3421-01 Important: .NET Core 3.1 Denial of Service Issue

An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: .NET Core 3.1 security and bugfix update for Red Hat Enterprise Linux Advisory ID: RHSA-2020:3421-01 Product: .NET Core on Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3421 Issue date: 2020-08-11 CVE Names: CVE-2020-1597 ==================================================================== 1. Summary: An update for rh-dotnet31-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64 .NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: .NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET Core that address a security vulnerability are now available. The updated versions are .NET Core SDK 3.1.107 and .NET Core Runtime 3.1.7. Security Fix(es): * .NET Core: ASP.NET Core Resource Consumption Denial of Service (CVE-2020-1597) Default inclusions for applications built with .NET Core have been updated to reference the newest versions and their security fixes. For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1861110 - CVE-2020-1597 dotnet: ASP.NET Core Resource Consumption Denial of Service 6. Package List: .NET Core on Red Hat Enterprise Linux ComputeNode (v. 7): Source: rh-dotnet31-dotnet-3.1.107-1.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.107-1.el7.x86_64.rpm .NET Core on Red Hat Enterprise Linux Server (v. 7): Source: rh-dotnet31-dotnet-3.1.107-1.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.107-1.el7.x86_64.rpm .NET Core on Red Hat EnterpriseLinux Workstation (v. 7): Source: rh-dotnet31-dotnet-3.1.107-1.el7.src.rpm x86_64: rh-dotnet31-aspnetcore-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-aspnetcore-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-apphost-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-debuginfo-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-host-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-hostfxr-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-runtime-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-sdk-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-dotnet-targeting-pack-3.1-3.1.7-1.el7.x86_64.rpm rh-dotnet31-dotnet-templates-3.1-3.1.107-1.el7.x86_64.rpm rh-dotnet31-netstandard-targeting-pack-2.1-3.1.107-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-1597 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXzMAFtzjgjWX9erEAQh5+A//UsOtJULqbwQ9oex9IgLFzc5KgpktYzAP Ug/yYUgoTVuwLSYEg5/BtIG4lf0loJAfDHEE1UhBvR4DHthRz+50cR5lF6fCBCYr RUYSMibbPMM6bb3/1K+El1KeBvA41bd04HYO8KbzhSSFR+JmCYMTDwl7sNiwQ4NB a5lYJYRl56j0Z/AxgXBzdme4lt6ETNMbfN0rYoSgYnPcnIeBICSvyfcd6TnX4HOq PuZgvPW+dxBDK5/wumEj7dOX2r3U9ClCc9qva2vKw8aLywrIs3eYdG07wh2HdwME FF+M5mxYNdrrIBnkYNk0CvjFSk7cWUmLMae1vqLlwjq7rBE1MUJ+RXXRV3WKkiCv 33l0er8L7hCkUIL5VQz0l3TeGcT6ITF8iO4K61xNBNXzwEOfvB161pSQp0SjVUxi AKdwxTj9m9KH4zt5lkfvfMP5a3VLQiws7i3XTG5/iBxOySVdBT+bkUizDFPVLS2C VPs8g7cZ8QvGplFzS1Y2I8nHS7K0+dBSajJQ381BmsugQOxv3u+zqG3SQ0Wxvw5M eSdTxn3k5SXfyEh9r2tUAtHF23751NEEc1RbIkDIBAa2TQee+jh//EHHiX0B2LRi 9Av6kgzXUkdnoIa9di6s5tixPwIv5Oma4cQpV6cfGujzBhuKp23yFlBJU/Olm6a7 /7QsembAUTw=Sbg6 -----END PGPSIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important .NET Core 3.1 patch for Red Hat resolves vulnerabilities, reinforces system stability.. Red Hat Linux, .NET Core update, security patch, software vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 11, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200