CVE-2025-26646

high
Published 2025-05-14 · Modified 2025-07-02
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

Important: .NET 9.0 security update

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description dotnet: .NET and Visual Studio Spoofing Vulnerability Red Hat statement This vulnerability in .NET is Important because it allows spoofing of trusted identities or content through crafted input, exploiting weaknesses in validation logic. While it requires user interaction and limited privileges, it can subvert authentication flows or integrity checks, leading to unauthorized actions.…

Description

dotnet: .NET and Visual Studio Spoofing Vulnerability

Red Hat statement

This vulnerability in .NET is Important because it allows spoofing of trusted identities or content through crafted input, exploiting weaknesses in validation logic. While it requires user interaction and limited privileges, it can subvert authentication flows or integrity checks, leading to unauthorized actions. In security-sensitive contexts—like signed assembly loading, secure package feeds, or automated build systems—such spoofing can compromise trust boundaries and facilitate privilege escalation or supply chain attacks, making it more severe than a typical moderate flaw. ``` .NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core. ```

CVSS v3: 8.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10dotnet8.0-0:8.0.116-1.el10_0RHSA-2025:75992025-05-14T00:00:00Z
Red Hat Enterprise Linux 10dotnet9.0-0:9.0.106-1.el10_0RHSA-2025:76012025-05-14T00:00:00Z
Red Hat Enterprise Linux 8dotnet9.0-0:9.0.106-1.el8_10RHSA-2025:75712025-05-14T00:00:00Z
Red Hat Enterprise Linux 8dotnet8.0-0:8.0.116-1.el8_10RHSA-2025:75892025-05-14T00:00:00Z
Red Hat Enterprise Linux 9dotnet8.0-0:8.0.116-1.el9_6RHSA-2025:75982025-05-14T00:00:00Z
Red Hat Enterprise Linux 9dotnet9.0-0:9.0.106-1.el9_6RHSA-2025:76002025-05-14T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportdotnet8.0-0:8.0.116-1.el9_4RHSA-2025:76032025-05-14T00:00:00Z
Red Hat Hardened Imagesdotnet8-0-main-8.0.126-1.hum1RHSA-2026:90802026-04-20T00:00:00Z
Red Hat Hardened Imagesdotnet9-0-main-9.0.116-1.hum1RHSA-2026:92052026-04-21T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 9dotnet6.0Out of support scope
Red Hat Enterprise Linux 9dotnet7.0Out of support scope
Red Hat Hardened Imagesdotnet10.0Not affected

Apply commands

bash fix
Apply RHSA-2025:7599 for Red Hat Enterprise Linux 10
yum update -y dotnet8
# or:
dnf upgrade -y dotnet8

Affected

VendorProductVersion
redhatRed Hat Hardened ImagesNot affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
rockylinux rocky9fixed
almalinux almalinux9fixedaspnetcore-targeting-pack-9.0-9.0.5-1.el9_6.ppc64le.rpm

Package impact

EcosystemPackageVulnerableFixed
nuget NuGetMicrosoft.Build.Tasks.Core>=15.8.166,<15.9.3015.9.30
nuget NuGetMicrosoft.Build.Tasks.Core>=16.0.461,<16.11.616.11.6
nuget NuGetMicrosoft.Build.Tasks.Core>=17.0.0,<17.8.2917.8.29
nuget NuGetMicrosoft.Build.Tasks.Core>=17.9.5,<17.10.2917.10.29
nuget NuGetMicrosoft.Build.Tasks.Core>=17.11.4,<17.12.3617.12.36
nuget NuGetMicrosoft.Build.Tasks.Core>=17.12.6,<17.13.2617.13.26
nuget NuGetMicrosoft.Build.Tasks.Core>=17.13.9,<17.14.817.14.8

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.