live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsPLATFORM

Red Hat’s .NET 8 update addresses 21 CVEs, including ASP.NET Core authentication bypasses

The Important-rated RHEL 9.6 update moves the SDK to 8.0.130 and runtime to 8.0.30 across extended-service channels.

21 CVEs fixed in the .NET 8 RHEL update
AI-generated illustration
By The News Desk· Aug 24, 2026

Red Hat has issued an Important security update for .NET 8.0 on Red Hat Enterprise Linux 9.6 extended-service channels, addressing 21 listed CVEs across .NET and ASP.NET Core. The RHSA-2026:58569 advisory, issued August 24, moves the SDK to version 8.0.130 and the runtime to 8.0.30.

What changed

The advisory groups a broad set of flaws into one .NET 8.0 update. Among them are two ASP.NET Core issues described by Red Hat as privilege-elevation vulnerabilities: CVE-2026-47300 involves an incorrect authentication algorithm, while CVE-2026-47303 is an authentication bypass. Other listed problems include security-feature and authorization bypasses, local code-execution paths, information disclosure, spoofing and several denial-of-service conditions.

One network-facing item, CVE-2026-50651, concerns an HTTP/2 SETTINGS/PING acknowledgement flood in SocketsHttpHandler that can exhaust memory. The advisory also lists CVE-2026-56170 as uncontrolled resource allocation in ASP.NET Core and CVE-2026-57108 as a .NET Core denial of service caused by type confusion.

Red Hat rates the combined update Important rather than assigning that label independently to every CVE in the bundle. Operators should use the individual CVE links in the advisory when they need per-vulnerability severity and scoring details.

Who is affected

The affected-product list covers RHEL 9.6 Extended Update Support on x86_64, Arm, IBM Z and little-endian Power, along with corresponding CodeReady Linux Builder channels. It also names 9.6 Update Services for SAP Solutions, Advanced Update Support and Extended Life Cycle variants.

That scope matters for teams that deliberately remain on a 9.6 service stream: the fix is packaged for those pinned channels rather than requiring a move to a later RHEL minor release.

What to do

Red Hat’s prescribed remediation is to apply the updated packages through the normal RHEL update process. Teams running ASP.NET Core services should prioritize inventorying hosts on the listed 9.6 channels, confirm that the installed SDK and runtime advance to 8.0.130 and 8.0.30, and then run their usual application regression checks.

The advisory also includes one build-system improvement that reduces the time needed to detect hanging .NET RPM builds. That change is secondary to the security fixes, but it arrives in the same package update.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.