[ubuntu/jammy-security] dotnet8 8.0.129-8.0.29-0ubuntu1~22.04.1 (Accepted)
Ian Constantin
ian.constantin at canonical.com
Wed Jul 15 13:49:33 UTC 2026
dotnet8 (8.0.129-8.0.29-0ubuntu1~22.04.1) jammy-security; urgency=medium
* New upstream release
* SECURITY UPDATE: denial of service
- CVE-2026-57108: .NET runtime - CryptoNative_GetX509NameInfo - UPN
BOOLEAN ASN.1 type-confusion DoS.
* SECURITY UPDATE:
- CVE-2026-47303: ASP.NET Core - Negotiate/LdapAdapter.cs - LDAP
identifier confusion CN vs sAMAccountName.
* SECURITY UPDATE: code injection
- CVE-2026-47300: LdapAdapter query validation fix - LDAP injection via
unvalidated filter input.
* SECURITY UPDATE: code injection
- CVE-2026-50659: System.Net.Mail - SMTP smuggling via CRLF split across
buffers.
* SECURITY UPDATE: security feature bypass
- CVE-2026-50528: System.Net.Security - additional SslStream fix (auth
bypass via ignored channel binding).
* SECURITY UPDATE: denial of service
- CVE-2026-50525: EncryptedXml/TransformChain - DoS via XML transform
chain DTD/base64 amplification.
* SECURITY UPDATE: security feature bypass
- CVE-2026-47304: EncryptedXml - XML Encryption vulnerability
(SignedXml.CheckSignature forgery via empty HMAC).
* SECURITY UPDATE: stack overflow
- CVE-2026-50527: EncryptedXml - System.Security.Cryptography.Xml.Utils -
Unauth XML triggers Type.GetType stack overflow.
* SECURITY UPDATE: denial of service
- CVE-2026-50648: EncryptedXml - XmlDecryptionTransform document-rooted
XPath queries causing O(n²) CPU DoS.
* SECURITY UPDATE: denial of service
- CVE-2026-47302: EncryptedXml - XML Encryption vulnerability +
XmlTextReaderImpl.Read duplicate attributes DoS.
* SECURITY UPDATE: security feature bypass
- CVE-2026-50524: System.Net.Security - SslStream handshake with malformed
TLS packets.
* SECURITY UPDATE: blob injection
- CVE-2026-50526: .NET SDK - Container image build cache uses predictable
world-writable location enabling blob injection.
* SECURITY UPDATE: denial of service
- CVE-2026-50651: SocketsHttpHandler Http2Connection - HTTP/2
SETTINGS/PING ACK flood causing OOM.
* Fix `dotnet sdk check` command source URL. (LP: #2156464)
- d/eng/dotnet-pkg-info.mk: strip suffixes from changelog distribution
name to avoid using wrong release names.
- d/t/regular-tests/dotnet-sdk-check-url-verification: test to verify the
sdk check command queries a URL with a valid release name.
- d/t/regular-tests/README.md: add distro-info as a necessary dependency
for the testsuite.
- d/t/control: add distro-info as a test dependency.
Date: 2026-07-08 20:48:20.698106+00:00
Changed-By: Mateus Rodrigues de Morais <mateus.morais at canonical.com>
Signed-By: Ian Constantin <ian.constantin at canonical.com>
https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list