Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: dotnet8.0: * aspnetcore-runtime-8.0-8.0.28-1.hum1 (aarch64, x86_64) * aspnetcore-runtime-dbg-8.0-8.0.28-1.hum1 (aarch64, x86_64) * aspnetcore-targeting-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-apphost-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-hostfxr-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-runtime-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-runtime-dbg-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-source-built-artifacts-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-sdk-dbg-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-targeting-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-templates-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet8.0-8.0.128-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-45591 is a vulnerability in the MessagePack hub protocol used by ASP.NET Core SignalR and Blazor Server, where insufficient validation of message nesting depth allows a remote attacker to send specially crafted MessagePack payloads with deeply nested arrays. This triggers excessive recursion and a stack overflow during message processing, causing the affected application or service to terminate unexpectedly and resulting in a denial of service condition. Red Hat has released an official fix for this issue as part of an update to Red Hat Hardened Images RPMs, including various dotnet10.0 packages. The vulnerability is tracked under multiple CWEs related to resource consumption and memory corruption. No known exploits in the wild have been reported.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to cause a denial of service by triggering a stack overflow through deeply nested MessagePack arrays. This results in application or service termination, impacting availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
An official fix is available from Red Hat and should be applied to affected systems. Red Hat does not currently provide a practical temporary workaround that meets usability and stability standards. Customers should update to the fixed versions of the affected RPMs as soon as possible to mitigate this vulnerability.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: dotnet8.0: * aspnetcore-runtime-8.0-8.0.28-1.hum1 (aarch64, x86_64) * aspnetcore-runtime-dbg-8.0-8.0.28-1.hum1 (aarch64, x86_64) * aspnetcore-targeting-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-apphost-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-hostfxr-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-runtime-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-runtime-dbg-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-source-built-artifacts-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-sdk-dbg-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet-targeting-pack-8.0-8.0.28-1.hum1 (aarch64, x86_64) * dotnet-templates-8.0-8.0.128-1.hum1 (aarch64, x86_64) * dotnet8.0-8.0.128-1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-45591 is a vulnerability in the MessagePack hub protocol used by ASP.NET Core SignalR and Blazor Server, where insufficient validation of message nesting depth allows a remote attacker to send specially crafted MessagePack payloads with deeply nested arrays. This triggers excessive recursion and a stack overflow during message processing, causing the affected application or service to terminate unexpectedly and resulting in a denial of service condition. Red Hat has released an official fix for this issue as part of an update to Red Hat Hardened Images RPMs, including various dotnet10.0 packages. The vulnerability is tracked under multiple CWEs related to resource consumption and memory corruption. No known exploits in the wild have been reported.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to cause a denial of service by triggering a stack overflow through deeply nested MessagePack arrays. This results in application or service termination, impacting availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
An official fix is available from Red Hat and should be applied to affected systems. Red Hat does not currently provide a practical temporary workaround that meets usability and stability standards. Customers should update to the fixed versions of the affected RPMs as soon as possible to mitigate this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:25111
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-45591"]
- Remediation Level
- official-fix
Threat ID: 6a29eece3187570649a04d64
Added to database: 06/10/2026, 23:10:06 UTC
Last enriched: 08/16/2026, 17:20:20 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 409
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.