Package "dotnet10"
| Name: |
dotnet10
|
Description: |
.NET CLI tools and runtime
|
| Latest version: |
10.0.108-10.0.8-0ubuntu1~26.04.1 |
| Release: |
resolute (26.04) |
| Level: |
security |
| Repository: |
main |
| Homepage: |
https://dot.net |
Links
Download "dotnet10"
Other versions of "dotnet10" in Resolute
Packages in group
Deleted packages are displayed in grey.
Changelog
|
dotnet10 (10.0.108-10.0.8-0ubuntu1~26.04.1) resolute-security; urgency=medium
* SECURITY UPDATE: denial of service
- CVE-2026-42899: Loop with unreachable exit condition ('infinite loop')
in ASP.NET Core allows an unauthorized attacker to deny service over a
network.
[ Mateus Rodrigues de Morais ]
* New upstream release (LP: #2152598)
* d/t/regular-tests/check-test-results: match to any NU1102 error
occurrences when ignoring package not found restore errors.
* d/t/regular-tests/template-test/test.json: increment timeout multiplier to
avoid timeout errors when running on the autopkgtest cloud.
* d/t/regular-tests/tools-in-path/test.json: skip test when running on the
toolchains-ci CI pipeline.
* d/t/run-regular-tests: define environment variable to selectively add the
'toolchains-ci' trait to the test runner.
-- Ian Constantin <email address hidden> Fri, 22 May 2026 17:45:46 +0300
|
| Source diff to previous version |
| 2152598 |
New upstream microrelease .NET 10.0.108/10.0.8 |
| CVE-2026-42899 |
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
|
|
dotnet10 (10.0.107-10.0.7-0ubuntu1~26.04.1) resolute-security; urgency=medium
* New upstream release
* SECURITY UPDATE: elevation of privilege
- CVE-2026-40372: A bug in Microsoft.AspNetCore.DataProtection
10.0.0-10.0.6 NuGet packages can give an attacker the opportunity to
execute an Elevation of Privilege attack by forging authentication
cookies, and also allows some protected payloads to be decrypted.
* SECURITY UPDATE: denial of service
- CVE-2026-33116: Possible denial of service via infinite recursion in
XmlDecryptionTransform.
* SECURITY UPDATE: denial of service
- CVE-2026-32203: Possible denial of service via stack overflow in
EncryptedKey nested decryption.
* SECURITY UPDATE: remote code execution
- CVE-2026-32178: SMTP command injection and header injection via
MailAddress parsing flaw in System.Net.Mail.
* SECURITY UPDATE: security feature bypass
- CVE-2026-26171: denial of service and security feature bypass via unsafe
transforms in EncryptedXml.
-- Mateus Rodrigues de Morais <email address hidden> Wed, 22 Apr 2026 09:43:45 -0300
|
| CVE-2026-40372 |
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-33116 |
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a |
| CVE-2026-32203 |
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. |
| CVE-2026-32178 |
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-26171 |
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. |
|
About
-
Send Feedback to @ubuntu_updates