UbuntuUpdates.org

Package "dotnet10"

Name: dotnet10

Description:

.NET CLI tools and runtime

Latest version: 10.0.108-10.0.8-0ubuntu1~26.04.1
Release: resolute (26.04)
Level: security
Repository: main
Homepage: https://dot.net

Links


Download "dotnet10"


Other versions of "dotnet10" in Resolute

Repository Area Version
base universe 10.0.5-0ubuntu1
base main 10.0.105-10.0.5-0ubuntu1
security universe 10.0.108-0ubuntu1~26.04.1
updates main 10.0.108-10.0.8-0ubuntu1~26.04.1
updates universe 10.0.108-0ubuntu1~26.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 10.0.108-10.0.8-0ubuntu1~26.04.1 2026-05-25 09:07:27 UTC

  dotnet10 (10.0.108-10.0.8-0ubuntu1~26.04.1) resolute-security; urgency=medium

  * SECURITY UPDATE: denial of service
    - CVE-2026-42899: Loop with unreachable exit condition ('infinite loop')
      in ASP.NET Core allows an unauthorized attacker to deny service over a
      network.

  [ Mateus Rodrigues de Morais ]
  * New upstream release (LP: #2152598)
  * d/t/regular-tests/check-test-results: match to any NU1102 error
    occurrences when ignoring package not found restore errors.
  * d/t/regular-tests/template-test/test.json: increment timeout multiplier to
    avoid timeout errors when running on the autopkgtest cloud.
  * d/t/regular-tests/tools-in-path/test.json: skip test when running on the
    toolchains-ci CI pipeline.
  * d/t/run-regular-tests: define environment variable to selectively add the
    'toolchains-ci' trait to the test runner.

 -- Ian Constantin <email address hidden> Fri, 22 May 2026 17:45:46 +0300

Source diff to previous version
2152598 New upstream microrelease .NET 10.0.108/10.0.8
CVE-2026-42899 Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Version: 10.0.107-10.0.7-0ubuntu1~26.04.1 2026-04-27 15:10:10 UTC

  dotnet10 (10.0.107-10.0.7-0ubuntu1~26.04.1) resolute-security; urgency=medium

  * New upstream release
  * SECURITY UPDATE: elevation of privilege
    - CVE-2026-40372: A bug in Microsoft.AspNetCore.DataProtection
      10.0.0-10.0.6 NuGet packages can give an attacker the opportunity to
      execute an Elevation of Privilege attack by forging authentication
      cookies, and also allows some protected payloads to be decrypted.
  * SECURITY UPDATE: denial of service
    - CVE-2026-33116: Possible denial of service via infinite recursion in
      XmlDecryptionTransform.
  * SECURITY UPDATE: denial of service
    - CVE-2026-32203: Possible denial of service via stack overflow in
      EncryptedKey nested decryption.
  * SECURITY UPDATE: remote code execution
    - CVE-2026-32178: SMTP command injection and header injection via
      MailAddress parsing flaw in System.Net.Mail.
  * SECURITY UPDATE: security feature bypass
    - CVE-2026-26171: denial of service and security feature bypass via unsafe
      transforms in EncryptedXml.

 -- Mateus Rodrigues de Morais <email address hidden> Wed, 22 Apr 2026 09:43:45 -0300

CVE-2026-40372 Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-33116 Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a
CVE-2026-32203 Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-32178 Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26171 Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.



About   -   Send Feedback to @ubuntu_updates