<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:11:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:18148 — Important: .NET 8.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:18148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aspnetcore-runtime-8.0, AlmaLinux:8: aspnetcore-runtime-dbg-8.0, AlmaLinux:8: aspnetcore-targeting-pack-8.0, AlmaLinux:8: dotnet-apphost-pack-8.0, AlmaLinux:8: dotnet-hostfxr-8.0, AlmaLinux:8: dotnet-runtime-8.0, AlmaLinux:8: dotnet-runtime-dbg-8.0, AlmaLinux:8: dotnet-sdk-8.0, AlmaLinux:8: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:8: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.121 and .NET Runtime 8.0.21.Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Information Disclosure Vulnerability (CVE-2025-55248)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2025-55315)
  * dotnet: .NET Denial of Service Vulnerability (CVE-2025-55247)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:18148</guid>
    </item>
    <item>
      <title>bdu:2025-13256</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13256</link>
      <description>bdu:2025-13256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13256</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-55247</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-55247</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: dotnet8-runtime, Alpaquita:25: dotnet8-sdk, Alpaquita:stream: dotnet8-runtime, Alpaquita:stream: dotnet8-sdk&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-55247</guid>
    </item>
    <item>
      <title>BIT-dotnet-2025-55247 — .NET Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-dotnet-2025-55247</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-dotnet-2025-55247</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0880 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Elles permettent à un attaquant de provoquer une é…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</link>
      <description>certfr-2025-avi-0880</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0880</guid>
    </item>
    <item>
      <title>EUVD-2026-269111</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-269111</link>
      <description>EUVD-2026-269111</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-269111</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55247</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55247</link>
      <description>&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55247</guid>
    </item>
    <item>
      <title>GHSA-w3q9-fxm7-j8fq — Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w3q9-fxm7-j8fq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Microsoft.Build.Tasks.Core, NuGet: Microsoft.Build, NuGet: Microsoft.Build.Utilities.Core&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0.xxx, .NET 9.0.xxx and .NET 10.0.xxx. This advisory also provides guidance on what developers can do to update their environments to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A vulnerability exists in .NET where predictable paths for MSBuild&amp;#39;s temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds. This only affects .NET on Linux operating systems.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/370&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Projects which do not utilize the [DownloadFile](https://learn.microsoft.com/visualstudio/msbuild/downloadfile-task)  build task are not susceptible to this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any installation of .NET 10.0.100-rc.1.25451.107 SDK or earlier.
* Any installation of .NET 9.0.110 SDK, .NET 9.0.305 SDK or earlier.
* Any installation of .NET 8.0.120 SDK, .NET 8.0.317 SDK, .NET 8.0.414 SDK or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages&lt;/p&gt;
&lt;p&gt;The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;Package name |Affected version | Patched version
------------ |-----…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Microsoft.Build.Tasks.Core, NuGet: Microsoft.Build, NuGet: Microsoft.Build.Utilities.Core&lt;/p&gt;
&lt;p&gt;# Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;executive-summary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0.xxx, .NET 9.0.xxx and .NET 10.0.xxx. This advisory also provides guidance on what developers can do to update their environments to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A vulnerability exists in .NET where predictable paths for MSBuild&amp;#39;s temporary directories on Linux let another user create the directories ahead of MSBuild, leading to DoS of builds. This only affects .NET on Linux operating systems.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at  https://github.com/dotnet/announcements/issues/370&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;mitigation-factors&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Mitigation factors&lt;/p&gt;
&lt;p&gt;Projects which do not utilize the [DownloadFile](https://learn.microsoft.com/visualstudio/msbuild/downloadfile-task)  build task are not susceptible to this vulnerability.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-software&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected software&lt;/p&gt;
&lt;p&gt;* Any installation of .NET 10.0.100-rc.1.25451.107 SDK or earlier.
* Any installation of .NET 9.0.110 SDK, .NET 9.0.305 SDK or earlier.
* Any installation of .NET 8.0.120 SDK, .NET 8.0.317 SDK, .NET 8.0.414 SDK or earlier.&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages&lt;/p&gt;
&lt;p&gt;The vulnerability affects any Microsoft .NET Core project if it uses any of affected packages versions listed below&lt;/p&gt;
&lt;p&gt;Package name |Affected version | Patched version
------------ |-----…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w3q9-fxm7-j8fq</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-55247 — .NET Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-55247</link>
      <description>msrc_CVE-2025-55247</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-55247</guid>
    </item>
    <item>
      <title>RHBA-2025:20916 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:20916</link>
      <description>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:20916</guid>
    </item>
    <item>
      <title>RHBA-2025:20993 — Red Hat Bug Fix Advisory: .NET 10.0 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:20993</link>
      <description>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET Denial of Service Vulnerability dotnet: .NET Security Feature Bypass Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:20993</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-55247</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55247</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:25.10: dotnet10, Ubuntu:25.10: dotnet8, Ubuntu:25.10: dotnet9, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Improper link resolution before file access (&amp;#39;link following&amp;#39;) in .NET allows an authorized attacker to elevate privileges locally.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55247</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2278 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, .NET Framework, Windows Server, ASP.NET, PowerShell und Windows ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2278</guid>
    </item>
  </channel>
</rss>
