CVE-2024-0056
Description
Important: .NET 6.0 security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0156.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0151.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-0152.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0157.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0157
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0150.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0150
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0158.html
Vendor advisory: alma — https://bugzilla.redhat.com/2257566
Vendor advisory: alma — https://bugzilla.redhat.com/2255386
Vendor advisory: alma — https://bugzilla.redhat.com/2255384
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0158
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0157
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0150
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:0158
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0156
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0152
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:0151
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | Microsoft.Data.SqlClient | <2.1.7 | 2.1.7 |
| NuGet | System.Data.SqlClient | <4.8.6 | 4.8.6 |
| NuGet | Microsoft.Data.SqlClient | >=3.0.0,<3.1.5 | 3.1.5 |
| NuGet | Microsoft.Data.SqlClient | >=4.0.0,<4.0.5 | 4.0.5 |
| NuGet | Microsoft.Data.SqlClient | >=5.0.0,<5.1.3 | 5.1.3 |
References
- https://access.redhat.com/errata/RHSA-2024:0151
- https://access.redhat.com/errata/RHSA-2024:0152
- https://access.redhat.com/errata/RHSA-2024:0156
- https://errata.rockylinux.org/RLSA-2024:0158
- https://errata.rockylinux.org/RLSA-2024:0150
- https://errata.rockylinux.org/RLSA-2024:0157
- https://nvd.nist.gov/vuln/detail/CVE-2024-0056
- https://github.com/dotnet/announcements/issues/292
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-0056
- https://access.redhat.com/errata/RHSA-2024:0158
- https://bugzilla.redhat.com/2255384
- https://bugzilla.redhat.com/2255386
- https://bugzilla.redhat.com/2257566
- https://errata.almalinux.org/8/ALSA-2024-0158.html
- https://access.redhat.com/errata/RHSA-2024:0150
- https://errata.almalinux.org/8/ALSA-2024-0150.html
- https://access.redhat.com/errata/RHSA-2024:0157
- https://errata.almalinux.org/8/ALSA-2024-0157.html
- https://errata.almalinux.org/9/ALSA-2024-0152.html
- https://errata.almalinux.org/9/ALSA-2024-0151.html
- https://errata.almalinux.org/9/ALSA-2024-0156.html
Verify integrity in audit chain (admin only). AS-IS.