Fedora Linux 8481 Published by

A dotnet6.0 security update has been released for Fedora 38.



[SECURITY] Fedora 38 Update: dotnet6.0-6.0.121-1.fc38


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-cbc688b8ca
2023-08-20 00:48:10.269313
--------------------------------------------------------------------------------

Name : dotnet6.0
Product : Fedora 38
Version : 6.0.121
Release : 1.fc38
URL : https://github.com/dotnet/
Summary : .NET Runtime and SDK
Description :
.NET is a fast, lightweight and modular platform for creating
cross platform applications that work on Linux, macOS and Windows.

It particularly focuses on creating console applications, web
applications and micro-services.

.NET contains a runtime conforming to .NET Standards a set of
framework libraries, an SDK containing compilers and a 'dotnet'
application to drive everything.

--------------------------------------------------------------------------------
Update Information:

This is the August 2023 update for .NET 6 and .NET 7. Release Notes: - 7.0
SDK: https://github.com/dotnet/core/blob/main/release-
notes/7.0/7.0.10/7.0.110.md - 7.0 Runtime:
https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.10/7.0.10.md -
6.0 SDK: https://github.com/dotnet/core/blob/main/release-
notes/6.0/6.0.21/6.0.121.md - 6.0 Runtime:
https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.21/6.0.21.md
--------------------------------------------------------------------------------
ChangeLog:

* Tue Aug 8 2023 Omair Majid [omajid@redhat.com] - 6.0.121-1
- Update to .NET SDK 6.0.121 and Runtime 6.0.21
* Wed Jul 19 2023 Fedora Release Engineering [releng@fedoraproject.org] - 6.0.120-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2230088 - CVE-2023-35390 dotnet7.0: dotnet: RCE under dotnet commands [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2230088
[ 2 ] Bug #2230089 - CVE-2023-35390 dotnet6.0: dotnet: RCE under dotnet commands [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2230089
[ 3 ] Bug #2230090 - CVE-2023-38180 dotnet6.0: dotnet: Kestrel vulnerability to slow read attacks leading to Denial of Service attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2230090
[ 4 ] Bug #2230091 - CVE-2023-38180 dotnet7.0: dotnet: Kestrel vulnerability to slow read attacks leading to Denial of Service attack [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2230091
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-cbc688b8ca' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------