Important: .NET 8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8469", "synopsis": "Important: .NET 8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.126 and .NET Runtime 8.0.26.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.s390x.rpm", "aspnetcore-runtime-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.26-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.26-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet8.0-0:8.0.126-1.el9_7.src.rpm", "dotnet8.0-debuginfo-0:8.0.126-1.el9_7.aarch64.rpm", "dotnet8.0-debuginfo-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet8.0-debuginfo-0:8.0.126-1.el9_7.s390x.rpm", "dotnet8.0-debuginfo-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet8.0-debugsource-0:8.0.126-1.el9_7.aarch64.rpm","dotnet8.0-debugsource-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet8.0-debugsource-0:8.0.126-1.el9_7.s390x.rpm", "dotnet8.0-debugsource-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-runtime-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-8.0-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.126-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-0:8.0.126-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.126-1.el9_7.aarch64.rpm","dotnet-sdk-8.0-debuginfo-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.126-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.126-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.126-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.126-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-8.0-0:8.0.126-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-8.0-0:8.0.126-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.26-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.26-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-8.0-0:8.0.26-1.el9_7.s390x.rpm", "dotnet-targeting-pack-8.0-0:8.0.26-1.el9_7.x86_64.rpm", "dotnet-templates-8.0-0:8.0.126-1.el9_7.aarch64.rpm", "dotnet-templates-8.0-0:8.0.126-1.el9_7.ppc64le.rpm", "dotnet-templates-8.0-0:8.0.126-1.el9_7.s390x.rpm", "dotnet-templates-8.0-0:8.0.126-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security update for .NET 8.0 on Rocky Linux addressing various vulnerabilities. Immediate attention recommended.. Rocky Linux .NET security update, Important dotnet vulnerabilities, Denial of Service fixes. . Severity: Important. LinuxSecurity.com Team
Important: .NET 10.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8471", "synopsis": "Important: .NET 10.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet10.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.106 and .NET Runtime 10.0.6.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet10.0-0:10.0.106-1.el9_7.src.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.aarch64.rpm","dotnet10.0-debugsource-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm","dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important .NET 10.0 security update for Rocky Linux 9 addresses key vulnerabilities including Denial of Service attacks.. Rocky Linux security update .NET 10.0 Denial of Service Security Bypass. .Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8474", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet9.0-0:9.0.116-1.el9_7.src.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.aarch64.rpm","dotnet9.0-debugsource-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for .NET 9.0 addresses critical security flaws in Rocky Linux 9 with several potential threats. Immediate action advised.. Rocky Linux 9 .NET 9.0 security update, important security advisory, security threats. . Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8474", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-138"}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet9.0-0:9.0.116-1.el9_7.src.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.aarch64.rpm","dotnet9.0-debugsource-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 9.0 features an important security update for .NET 9.0 addressing multiple security issues including DoS vulnerabilities.. Rocky Linux security update, Dotnet vulnerabilities, security bypass in Dotnet, Denial of Service issues. . Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8474", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-138"}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet9.0-0:9.0.116-1.el9_7.src.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.aarch64.rpm","dotnet9.0-debugsource-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the Important .NET 9.0 security update for Rocky Linux with crucial patch details and CVEs for protection.. Rocky Linux security .NET update Important advisory. . Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8474", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-138"}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet9.0-0:9.0.116-1.el9_7.src.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.aarch64.rpm","dotnet9.0-debugsource-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el9_7.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el9_7.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.ppc64le.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical security update for .NET 9.0 on Rocky Linux addresses several important issues including denial of service. Stay secure!. Rocky Linux, .NET 9.0, Security Update, Denial of Service, Security Bypass. . Severity: Important. LinuxSecurity.com Team
Important: .NET 10.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8471", "synopsis": "Important: .NET 10.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet10.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.106 and .NET Runtime 10.0.6.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-138"}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet10.0-0:10.0.106-1.el9_7.src.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.aarch64.rpm","dotnet10.0-debugsource-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm","dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Get the latest important .NET 10.0 security update for Rocky Linux that addresses critical security threats and vulnerabilities.. Rocky Linux Dotnet Security Update Denial of Service. . Severity:Important. LinuxSecurity.com Team
Important: .NET 10.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8471", "synopsis": "Important: .NET 10.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet10.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.106 and .NET Runtime 10.0.6.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": "CWE-138"}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-19T00:04:03.622890Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet10.0-0:10.0.106-1.el9_7.src.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.aarch64.rpm","dotnet10.0-debugsource-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.s390x.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.aarch64.rpm","dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.s390x.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el9_7.x86_64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.aarch64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.ppc64le.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.s390x.rpm", "dotnet-templates-10.0-0:10.0.106-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Learn about the important .NET 10.0 security update for Rocky Linux addressing critical vulnerabilities and threats.. Rocky Linux .NET update, security patch, vulnerability fix, denial of service,important advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.