ALSA-2026:41898

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:41898
Related
  • CVE-2026-47300
  • CVE-2026-47302
  • CVE-2026-47303
  • CVE-2026-47304
  • CVE-2026-50524
  • CVE-2026-50525
  • CVE-2026-50526
  • CVE-2026-50527
  • CVE-2026-50528
  • CVE-2026-50646
  • CVE-2026-50648
  • CVE-2026-50649
  • CVE-2026-50650
  • CVE-2026-50651
  • CVE-2026-50659
  • CVE-2026-56170
  • CVE-2026-57108
Published
2026-07-20T00:00:00Z
Modified
2026-07-31T15:44:58.325706772Z
Summary
Important: .NET 10.0 security, bug fix, and enhancement update
Details

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10.

Security Fix(es):

  • dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
  • dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
  • ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
  • ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
  • ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
  • dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
  • dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
  • dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
  • dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
  • dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
  • dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
  • dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
  • dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525)
  • dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527)
  • dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648)
  • .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659)
  • dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524)

Bug Fix(es) and Enhancement(s):

  • Update .NET 10.0 to SDK 10.0.110 and Runtime 10.0.10 [almalinux-9.8.z] (JIRA:AlmaLinux-192462)
  • dotnet10.0: Reduce time to detect hanging builds during .NET RPM builds (c9s) [almalinux-9.8.z] (JIRA:AlmaLinux-192336)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9
aspnetcore-runtime-10.0

Package

Name
aspnetcore-runtime-10.0
Purl
pkg:rpm/almalinux/aspnetcore-runtime-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
aspnetcore-runtime-dbg-10.0

Package

Name
aspnetcore-runtime-dbg-10.0
Purl
pkg:rpm/almalinux/aspnetcore-runtime-dbg-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
aspnetcore-targeting-pack-10.0

Package

Name
aspnetcore-targeting-pack-10.0
Purl
pkg:rpm/almalinux/aspnetcore-targeting-pack-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-apphost-pack-10.0

Package

Name
dotnet-apphost-pack-10.0
Purl
pkg:rpm/almalinux/dotnet-apphost-pack-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-host

Package

Name
dotnet-host
Purl
pkg:rpm/almalinux/dotnet-host

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-hostfxr-10.0

Package

Name
dotnet-hostfxr-10.0
Purl
pkg:rpm/almalinux/dotnet-hostfxr-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-runtime-10.0

Package

Name
dotnet-runtime-10.0
Purl
pkg:rpm/almalinux/dotnet-runtime-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-runtime-dbg-10.0

Package

Name
dotnet-runtime-dbg-10.0
Purl
pkg:rpm/almalinux/dotnet-runtime-dbg-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-sdk-10.0

Package

Name
dotnet-sdk-10.0
Purl
pkg:rpm/almalinux/dotnet-sdk-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.110-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-sdk-10.0-source-built-artifacts

Package

Name
dotnet-sdk-10.0-source-built-artifacts
Purl
pkg:rpm/almalinux/dotnet-sdk-10.0-source-built-artifacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.110-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-sdk-aot-10.0

Package

Name
dotnet-sdk-aot-10.0
Purl
pkg:rpm/almalinux/dotnet-sdk-aot-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.110-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-sdk-dbg-10.0

Package

Name
dotnet-sdk-dbg-10.0
Purl
pkg:rpm/almalinux/dotnet-sdk-dbg-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.110-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-targeting-pack-10.0

Package

Name
dotnet-targeting-pack-10.0
Purl
pkg:rpm/almalinux/dotnet-targeting-pack-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.10-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"
dotnet-templates-10.0

Package

Name
dotnet-templates-10.0
Purl
pkg:rpm/almalinux/dotnet-templates-10.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.110-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:41898.json"