Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:3580 - Security Advisory
Issued:
2023-06-14
Updated:
2023-06-14

RHSA-2023:3580 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: .NET 6.0 security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.118 and .NET Runtime 6.0.18.

The following packages have been upgraded to a later upstream version: rh-dotnet60-dotnet (6.0.118). (BZ#2211715)

Security Fix(es):

  • dotnet: .NET Kestrel: Denial of Service processing X509 Certificates (CVE-2023-29331)
  • dotnet: vulnerability exists in NuGet where a potential race condition can lead to a symlink attack (CVE-2023-29337)
  • dotnet: Remote Code Execution - Source generators issue can lead to a crash due to unmanaged heap corruption (CVE-2023-33128)
  • dotnet: Bypass restrictions when deserializing a DataSet or DataTable from XML (CVE-2023-24936)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • dotNET on RHEL (for RHEL Server) 1 x86_64
  • dotNET on RHEL (for RHEL Workstation) 1 x86_64
  • dotNET on RHEL (for RHEL Compute Node) 1 x86_64

Fixes

  • BZ - 2192438 - CVE-2023-24936 dotnet: Bypass restrictions when deserializing a DataSet or DataTable from XML
  • BZ - 2212617 - CVE-2023-29331 dotnet: .NET Kestrel: Denial of Service processing X509 Certificates
  • BZ - 2212618 - CVE-2023-33128 dotnet: Remote Code Execution - Source generators issue can lead to a crash due to unmanaged heap corruption
  • BZ - 2213703 - CVE-2023-29337 dotnet: vulnerability exists in NuGet where a potential race condition can lead to a symlink attack

CVEs

  • CVE-2023-24936
  • CVE-2023-29331
  • CVE-2023-29337
  • CVE-2023-33128

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

dotNET on RHEL (for RHEL Server) 1

SRPM
rh-dotnet60-dotnet-6.0.118-1.el7_9.src.rpm SHA-256: a8f0344766f83264797c3471fbf1cbd2e73f72a57d0969e44ebf482966e2e834
x86_64
rh-dotnet60-aspnetcore-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 16830ac11afc0087c3a05fefce9fbda7154aa76ccf2881edb49115aecf775049
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 014f84b3bb1e3adb51b0dbcd2feade8ccc36562b22efc99a892e5b30796ae58c
rh-dotnet60-dotnet-6.0.118-1.el7_9.x86_64.rpm SHA-256: 05f4db3dbe4c6a94946665aa5971a077fff5d7ccc750b7800c8ee7ee55f648e8
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: c86adea7ac4865e5287920b07543d4943e8db88988216382b67938c06f983f0b
rh-dotnet60-dotnet-debuginfo-6.0.118-1.el7_9.x86_64.rpm SHA-256: a1993ac54a72b69e0e5b7f894068c8833adf45c34f8369ece3c2c154c2638354
rh-dotnet60-dotnet-host-6.0.18-1.el7_9.x86_64.rpm SHA-256: 4f92983bfe39d163e6a55667399403e375133f8729b8359651177ab4678535f6
rh-dotnet60-dotnet-hostfxr-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 5acbedb5966bbf29360fb5990625f4deda09e6ec0cc1caf363af4b2caf6d6e3c
rh-dotnet60-dotnet-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ee53c9ab7206b2d873be40d98bcfd72602fc82854133bb4533aff6ba1239ab8a
rh-dotnet60-dotnet-sdk-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 20ef945250b73b223c00bc4eb3ebd575ca6e4cc3145a8dd285aec4ab29c23d17
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.118-1.el7_9.x86_64.rpm SHA-256: 4dd920340c8957f87e497c75679d71133f32d9a5e6448d2a3bec64f1c9918838
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ed2ea71b8f94f465364387a2c6b4eb6a6a148a9ca2b0b3acf2b184ff36f14594
rh-dotnet60-dotnet-templates-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 2c3e6695abf43b59c22e3dabf9fee1bb386145ec2464946862ae94871a612aaa
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.118-1.el7_9.x86_64.rpm SHA-256: 6f82fddadaa5b45643d75daff90e4cc1235a52e80f4864fc81aa6c8aea04bdd1

dotNET on RHEL (for RHEL Workstation) 1

SRPM
rh-dotnet60-dotnet-6.0.118-1.el7_9.src.rpm SHA-256: a8f0344766f83264797c3471fbf1cbd2e73f72a57d0969e44ebf482966e2e834
x86_64
rh-dotnet60-aspnetcore-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 16830ac11afc0087c3a05fefce9fbda7154aa76ccf2881edb49115aecf775049
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 014f84b3bb1e3adb51b0dbcd2feade8ccc36562b22efc99a892e5b30796ae58c
rh-dotnet60-dotnet-6.0.118-1.el7_9.x86_64.rpm SHA-256: 05f4db3dbe4c6a94946665aa5971a077fff5d7ccc750b7800c8ee7ee55f648e8
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: c86adea7ac4865e5287920b07543d4943e8db88988216382b67938c06f983f0b
rh-dotnet60-dotnet-debuginfo-6.0.118-1.el7_9.x86_64.rpm SHA-256: a1993ac54a72b69e0e5b7f894068c8833adf45c34f8369ece3c2c154c2638354
rh-dotnet60-dotnet-host-6.0.18-1.el7_9.x86_64.rpm SHA-256: 4f92983bfe39d163e6a55667399403e375133f8729b8359651177ab4678535f6
rh-dotnet60-dotnet-hostfxr-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 5acbedb5966bbf29360fb5990625f4deda09e6ec0cc1caf363af4b2caf6d6e3c
rh-dotnet60-dotnet-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ee53c9ab7206b2d873be40d98bcfd72602fc82854133bb4533aff6ba1239ab8a
rh-dotnet60-dotnet-sdk-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 20ef945250b73b223c00bc4eb3ebd575ca6e4cc3145a8dd285aec4ab29c23d17
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.118-1.el7_9.x86_64.rpm SHA-256: 4dd920340c8957f87e497c75679d71133f32d9a5e6448d2a3bec64f1c9918838
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ed2ea71b8f94f465364387a2c6b4eb6a6a148a9ca2b0b3acf2b184ff36f14594
rh-dotnet60-dotnet-templates-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 2c3e6695abf43b59c22e3dabf9fee1bb386145ec2464946862ae94871a612aaa
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.118-1.el7_9.x86_64.rpm SHA-256: 6f82fddadaa5b45643d75daff90e4cc1235a52e80f4864fc81aa6c8aea04bdd1

dotNET on RHEL (for RHEL Compute Node) 1

SRPM
rh-dotnet60-dotnet-6.0.118-1.el7_9.src.rpm SHA-256: a8f0344766f83264797c3471fbf1cbd2e73f72a57d0969e44ebf482966e2e834
x86_64
rh-dotnet60-aspnetcore-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 16830ac11afc0087c3a05fefce9fbda7154aa76ccf2881edb49115aecf775049
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 014f84b3bb1e3adb51b0dbcd2feade8ccc36562b22efc99a892e5b30796ae58c
rh-dotnet60-dotnet-6.0.118-1.el7_9.x86_64.rpm SHA-256: 05f4db3dbe4c6a94946665aa5971a077fff5d7ccc750b7800c8ee7ee55f648e8
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: c86adea7ac4865e5287920b07543d4943e8db88988216382b67938c06f983f0b
rh-dotnet60-dotnet-debuginfo-6.0.118-1.el7_9.x86_64.rpm SHA-256: a1993ac54a72b69e0e5b7f894068c8833adf45c34f8369ece3c2c154c2638354
rh-dotnet60-dotnet-host-6.0.18-1.el7_9.x86_64.rpm SHA-256: 4f92983bfe39d163e6a55667399403e375133f8729b8359651177ab4678535f6
rh-dotnet60-dotnet-hostfxr-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: 5acbedb5966bbf29360fb5990625f4deda09e6ec0cc1caf363af4b2caf6d6e3c
rh-dotnet60-dotnet-runtime-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ee53c9ab7206b2d873be40d98bcfd72602fc82854133bb4533aff6ba1239ab8a
rh-dotnet60-dotnet-sdk-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 20ef945250b73b223c00bc4eb3ebd575ca6e4cc3145a8dd285aec4ab29c23d17
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.118-1.el7_9.x86_64.rpm SHA-256: 4dd920340c8957f87e497c75679d71133f32d9a5e6448d2a3bec64f1c9918838
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.18-1.el7_9.x86_64.rpm SHA-256: ed2ea71b8f94f465364387a2c6b4eb6a6a148a9ca2b0b3acf2b184ff36f14594
rh-dotnet60-dotnet-templates-6.0-6.0.118-1.el7_9.x86_64.rpm SHA-256: 2c3e6695abf43b59c22e3dabf9fee1bb386145ec2464946862ae94871a612aaa
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.118-1.el7_9.x86_64.rpm SHA-256: 6f82fddadaa5b45643d75daff90e4cc1235a52e80f4864fc81aa6c8aea04bdd1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility