CVE-2026-42899
Description
Important: .NET 9.0 security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description dotnet: .NET: infinite loop allows an attacker to cause a denial of service Red Hat statement As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity. CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linuxβ¦
Description
dotnet: .NET: infinite loop allows an attacker to cause a denial of service
Red Hat statement
As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity.
CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet8.0-0:8.0.127-1.el10_2 | RHSA-2026:21286 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 10 | dotnet9.0-0:9.0.117-1.el10_2 | RHSA-2026:21754 | 2026-05-28T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet8.0-0:8.0.127-1.el8_10 | RHSA-2026:21291 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet9.0-0:9.0.117-1.el8_10 | RHSA-2026:21294 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet10.0-0:10.0.108-1.el8_10 | RHSA-2026:21295 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet8.0-0:8.0.127-1.el9_8 | RHSA-2026:21293 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet9.0-0:9.0.117-1.el9_8 | RHSA-2026:21296 | 2026-05-27T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet10.0-0:10.0.108-1.el9_8 | RHSA-2026:21297 | 2026-05-27T00:00:00Z |
| Red Hat Hardened Images | dotnet10-0-main-10.0.108-1.hum1 | RHSA-2026:17464 | 2026-05-14T00:00:00Z |
| Red Hat Hardened Images | dotnet9-0-main-9.0.117-1.hum1 | RHSA-2026:17527 | 2026-05-14T00:00:00Z |
| Red Hat Hardened Images | dotnet8-0-main-8.0.127-1.hum1 | RHSA-2026:17682 | 2026-05-14T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0 | Affected |
Apply commands
yum update -y dotnet8
# or:
dnf upgrade -y dotnet8
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 10 | Affected |
OS impact
Windows Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
AlmaLinux Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | aspnetcore-runtime-dbg-8.0-8.0.27-1.el9_8.aarch64.rpm |
| 8 | Fixed | dotnet-sdk-8.0-source-built-artifacts-8.0.127-1.el8_10.x86_64.rpm |
Linux kernel Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | β |
macOS Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | β |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
Package impact
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | .net | {"startIncluding":"8.0.0","endExcluding":"8.0.27"} | 8.0.27 |
References
- https://access.redhat.com/errata/RHSA-2026:21293
- https://access.redhat.com/errata/RHSA-2026:21296
- https://access.redhat.com/errata/RHSA-2026:21297
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-9v76-4qcc-frgh
- https://nvd.nist.gov/vuln/detail/CVE-2026-42899
- https://github.com/dotnet/announcements/issues/397
- https://github.com/dotnet/aspnetcore
- https://github.com/advisories/GHSA-9v76-4qcc-frgh
- https://access.redhat.com/errata/RHSA-2026:21291
- https://bugzilla.redhat.com/2453284
- https://bugzilla.redhat.com/2476605
- https://errata.almalinux.org/8/ALSA-2026-21291.html
- https://errata.almalinux.org/9/ALSA-2026-21293.html
- https://access.redhat.com/errata/RHSA-2026:21294
- https://errata.almalinux.org/8/ALSA-2026-21294.html
- https://access.redhat.com/errata/RHSA-2026:21295
- https://errata.almalinux.org/8/ALSA-2026-21295.html
- https://errata.almalinux.org/9/ALSA-2026-21296.html
- https://errata.almalinux.org/9/ALSA-2026-21297.html
CWEs
CWE-835
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.