ALSA-2026:54538: .NET 8.0 security, bug fix, and enhancement update (Important)
ALSA-2026:54542: .NET 10.0 security, bug fix, and enhancement update (Important)
ALSA-2026:54654: bind security update (Important)
ALSA-2026:54550: .NET 9.0 security, bug fix, and enhancement update (Important)
ALSA-2026:54509: bind9.16 security update (Important)
ALSA-2026:54575: dracut security update (Important)
ALSA-2026:54487: freerdp security update (Important)
ALSA-2026:54510: bind security update (Important)
ALSA-2026:54571: dracut security update (Important)
ALSA-2026:54662: nghttp2 security update (Moderate)
ALSA-2026:54343: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:54486: freerdp security update (Important)
ALSA-2026:54512: gnome-remote-desktop security update (Moderate)
ALSA-2026:54576: dracut security update (Important)
ALSA-2026:54650: nghttp2 security update (Moderate)
ALSA-2026:54541: .NET 8.0 security, bug fix, and enhancement update (Important)
ALSA-2026:54590: .NET 9.0 security, bug fix, and enhancement update (Important)
ALSA-2026:54538: .NET 8.0 security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.
SDK version: 8.0.130
Runtime version: 8.0.30
Security Fix(es):
* .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899)
* .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900)
* .NET: .NET Denial of Service Vulnerability (CVE-2026-62901)
* .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909)
Bug Fix(es) and Enhancement(s):
* Update .NET 8.0 to SDK 8.0.130 and Runtime 8.0.30 (JIRA:AlmaLinux-235468)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54538.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54542: .NET 10.0 security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.
SDK version: 10.0.111
Runtime version: 10.0.11
Security Fix(es):
* .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899)
* .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900)
* .NET: .NET Denial of Service Vulnerability (CVE-2026-62901)
* .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909)
Bug Fix(es) and Enhancement(s):
* Update .NET 10.0 to SDK 10.0.111 and Runtime 10.0.11 (JIRA:AlmaLinux-235478)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54542.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54654: bind security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54654.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54550: .NET 9.0 security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.
SDK version: 9.0.120
Runtime version: 9.0.19
Security Fix(es):
* .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899)
* .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900)
* .NET: .NET Denial of Service Vulnerability (CVE-2026-62901)
* .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909)
Bug Fix(es) and Enhancement(s):
* Update .NET 9.0 to SDK 9.0.120 and Runtime 9.0.19 (JIRA:AlmaLinux-235473)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54550.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54509: bind9.16 security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-13
Summary:
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54509.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54575: dracut security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.
Security Fix(es):
* dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-54575.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54487: freerdp security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
* FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
* FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
* FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-54487.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54510: bind security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-54510.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54571: dracut security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.
Security Fix(es):
* dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-54571.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54662: nghttp2 security update (Moderate)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Moderate
Release date: 2026-08-14
Summary:
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.
Security Fix(es):
* nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-54662.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54343: kernel security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)
* kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)
* kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)
* kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)
* kernel: af_unix: set gc_in_progress to true in unix_gc() (CVE-2026-53361)
Bug Fix(es) and Enhancement(s):
* netfilter: CVE backports for AlmaLinux 10.2.z (JIRA:AlmaLinux-185311)
* tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [almalinux-10.2.z] (JIRA:AlmaLinux-214436)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54343.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54486: freerdp security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.
Security Fix(es):
* FreeRDP: FreeRDP: Remote code execution or denial of service via heap-based buffer overflow (CVE-2026-64620)
* FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution (CVE-2026-64621)
* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
* FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
* FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
* FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54486.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54512: gnome-remote-desktop security update (Moderate)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Moderate
Release date: 2026-08-14
Summary:
GNOME Remote Desktop is a remote desktop and screen sharing service for the GNOME desktop environment.
Security Fix(es):
* gnome-remote-desktop: gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service (CVE-2026-18358)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54512.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54576: dracut security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.
Security Fix(es):
* dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54576.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54650: nghttp2 security update (Moderate)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Moderate
Release date: 2026-08-14
Summary:
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.
Security Fix(es):
* nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54650.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54541: .NET 8.0 security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.
SDK version: 8.0.130
Runtime version: 8.0.30
Security Fix(es):
* .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899)
* .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900)
* .NET: .NET Denial of Service Vulnerability (CVE-2026-62901)
* .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909)
Bug Fix(es) and Enhancement(s):
* Update .NET 8.0 to SDK 8.0.130 and Runtime 8.0.30 [almalinux-10.2.z] (JIRA:AlmaLinux-235472)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54541.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:54590: .NET 9.0 security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-08-14
Summary:
.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.
SDK version: 9.0.120
Runtime version: 9.0.19
Security Fix(es):
* .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899)
* .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900)
* .NET: .NET Denial of Service Vulnerability (CVE-2026-62901)
* .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909)
Bug Fix(es) and Enhancement(s):
* Update .NET 9.0 to SDK 9.0.120 and Runtime 9.0.19 [almalinux-10.2.z] (JIRA:AlmaLinux-235477)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-54590.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team