<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:49:23.863600+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:18148</id>
    <title>ALSA-2025:18148 — Important: .NET 8.0 security update</title>
    <updated>2026-10-03T05:49:24.017338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):</p>
<p>* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:18148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13256</id>
    <title>bdu:2025-13256</title>
    <updated>2026-10-03T05:49:24.017428+00:00</updated>
    <content>bdu:2025-13256</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-55247</id>
    <title>BELL-CVE-2025-55247</title>
    <updated>2026-10-03T05:49:24.017445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2025-55247</id>
    <title>BIT-dotnet-2025-55247 — .NET Elevation of Privilege Vulnerability</title>
    <updated>2026-10-03T05:49:24.017468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2025-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</id>
    <title>certfr-2025-avi-0880 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Elles permettent à un attaquant de provoquer une é…</title>
    <updated>2026-10-03T05:49:24.017488+00:00</updated>
    <content>certfr-2025-avi-0880</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-269111</id>
    <title>EUVD-2026-269111</title>
    <updated>2026-10-03T05:49:24.017504+00:00</updated>
    <content>EUVD-2026-269111</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-269111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55247</id>
    <title>fkie_cve-2025-55247</title>
    <updated>2026-10-03T05:49:24.017514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w3q9-fxm7-j8fq</id>
    <title>GHSA-w3q9-fxm7-j8fq — Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability</title>
    <updated>2026-10-03T05:49:24.017534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Microsoft.Build.Tasks.Core, NuGet: Microsoft.Build, NuGet: Microsoft.Build.Utilities.Core</p>
<p># Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability</p>
<p>## &lt;a name="executive-summary"&gt;&lt;/a&gt;Executive summary</p>
<p>Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0.xxx, .NET 9.0.xxx and .NET 10.0.xxx. This advisory also provides guidance on what developers can do to update their environments to remove this vulnerability.</p>
<p>A vulnerability exists in .NET where predictable paths for MSBuild's temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds. This only affects .NET on Linux operating systems.</p>
<p>## Announcement</p>
<p>Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/370</p>
<p>### &lt;a name="mitigation-factors"&gt;&lt;/a&gt;Mitigation factors</p>
<p>Projects which do not utilize the [DownloadFile](https://learn.microsoft.com/visualstudio/msbuild/downloadfile-task)  build task are not susceptible to this vulnerability.</p>
<p>## &lt;a name="affected-software"&gt;&lt;/a&gt;Affected software</p>
<p>* Any installation of .NET 10.0.100-rc.1.25451.107 SDK or earlier.
* Any installation of .NET 9.0.110 SDK, .NET 9.0.305 SDK or earlier.
* Any installation of .NET 8.0.120 SDK, .NET 8.0.317 SDK, .NET 8.0.414 SDK or earlier.</p>
<p>## &lt;a name="affected-packages"&gt;&lt;/a&gt;Affected Packages</p>
<p>The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below</p>
<p>Package name |Affected version | Patched version
------------ |-----…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w3q9-fxm7-j8fq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-55247</id>
    <title>msrc_CVE-2025-55247 — .NET Elevation of Privilege Vulnerability</title>
    <updated>2026-10-03T05:49:24.017608+00:00</updated>
    <content>msrc_CVE-2025-55247</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:20916</id>
    <title>RHBA-2025:20916 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
    <updated>2026-10-03T05:49:24.017632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:20916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:20993</id>
    <title>RHBA-2025:20993 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
    <updated>2026-10-03T05:49:24.017651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:20993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55247</id>
    <title>UBUNTU-CVE-2025-55247</title>
    <updated>2026-10-03T05:49:24.017668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10</p>
<p>Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</id>
    <title>WID-SEC-W-2025-2278 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:49:24.017696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278"/>
  </entry>
</feed>
