Home / mailingsPDF  

[USN-8740-1] .NET vulnerabilities

Posted on 10 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8740-1
September 10, 2026

dotnet8, dotnet10 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in .NET.

Software Description:
- dotnet10: .NET CLI tools and runtime
- dotnet8: .NET CLI tools and runtime

Details:

Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did
not properly validate cross-origin WebSocket connections. An attacker could
possibly use this issue to expose sensitive information. (CVE-2026-58649)

Rajesh Chada discovered that the .NET watch AspireServerService improperly
exposed information through the use of certain arguments. An attacker could
possibly use this issue to elevate privileges and execute arbitrary code.
(CVE-2026-69806)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
aspnetcore-runtime-10.0 10.0.12-0ubuntu1~26.04.1
dotnet-host-10.0 10.0.12-0ubuntu1~26.04.1
dotnet-hostfxr-10.0 10.0.12-0ubuntu1~26.04.1
dotnet-runtime-10.0 10.0.12-0ubuntu1~26.04.1
dotnet-sdk-10.0 10.0.112-0ubuntu1~26.04.1
dotnet-sdk-aot-10.0 10.0.112-0ubuntu1~26.04.1
dotnet-sdk-dbg-10.0 10.0.112-0ubuntu1~26.04.1
dotnet10 10.0.112-10.0.12-0ubuntu1~26.04.1

Ubuntu 24.04 LTS
aspnetcore-runtime-10.0 10.0.12-0ubuntu1~24.04.1
aspnetcore-runtime-8.0 8.0.31-0ubuntu1~24.04.1
dotnet-host-10.0 10.0.12-0ubuntu1~24.04.1
dotnet-host-8.0 8.0.31-0ubuntu1~24.04.1
dotnet-hostfxr-10.0 10.0.12-0ubuntu1~24.04.1
dotnet-hostfxr-8.0 8.0.31-0ubuntu1~24.04.1
dotnet-runtime-10.0 10.0.12-0ubuntu1~24.04.1
dotnet-runtime-8.0 8.0.31-0ubuntu1~24.04.1
dotnet-sdk-10.0 10.0.112-0ubuntu1~24.04.1
dotnet-sdk-8.0 8.0.131-0ubuntu1~24.04.1
dotnet-sdk-aot-10.0 10.0.112-0ubuntu1~24.04.1
dotnet-sdk-dbg-10.0 10.0.112-0ubuntu1~24.04.1
dotnet10 10.0.112-10.0.12-0ubuntu1~24.04.1
dotnet8 8.0.131-8.0.31-0ubuntu1~24.04.1

Ubuntu 22.04 LTS
aspnetcore-runtime-8.0 8.0.31-0ubuntu1~22.04.1
dotnet-host-8.0 8.0.31-0ubuntu1~22.04.1
dotnet-hostfxr-8.0 8.0.31-0ubuntu1~22.04.1
dotnet-runtime-8.0 8.0.31-0ubuntu1~22.04.1
dotnet-sdk-8.0 8.0.131-0ubuntu1~22.04.1
dotnet8 8.0.131-8.0.31-0ubuntu1~22.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8740-1
CVE-2026-58649, CVE-2026-69806

Package Information:
https://launchpad.net/ubuntu/+source/dotnet10/10.0.112-10.0.12-0ubuntu1~26.04.1
https://launchpad.net/ubuntu/+source/dotnet10/10.0.112-10.0.12-0ubuntu1~24.04.1
https://launchpad.net/ubuntu/+source/dotnet8/8.0.131-8.0.31-0ubuntu1~24.04.1
https://launchpad.net/ubuntu/+source/dotnet8/8.0.131-8.0.31-0ubuntu1~22.04.1

--===============6274662805661569918==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP