RLSA-2025:0382

Source
https://errata.rockylinux.org/RLSA-2025:0382
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2025:0382.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2025:0382
Upstream
Published
2025-02-13T20:34:26.141542Z
Modified
2026-02-05T12:30:09.375051Z
Summary
Important: .NET 9.0 security update
Details

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.102 and .NET Runtime 9.0.1.

Security Fix(es):

  • dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)
  • dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)
  • dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)
  • dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):

  • dotnet: .NET Elevation of Privilege Vulnerability (CVE-2025-21173)

  • dotnet: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21176)

  • dotnet: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2025-21172)

  • dotnet: .NET Remote Code Execution Vulnerability (CVE-2025-21171)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / dotnet9.0

Package

Name
dotnet9.0
Purl
pkg:rpm/rocky-linux/dotnet9.0?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:9.0.102-1.el8_10
Database specific
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2025:0382.json"