Bug 2457741 (CVE-2026-33116)

Summary: CVE-2026-33116 dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in .NET. A remote attacker could exploit this vulnerability by crafting a malicious XML document that triggers an infinite recursion within the XmlDecryptionTransform component. This could lead to a Denial of Service (DoS), making the affected system unresponsive.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2458409, 2458410, 2458413    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-13 05:15:00 UTC
.NET - DenialOfService - Denial of Service via Infinite Recursion in XmlDecryptionTransform

Comment 2 errata-xmlrpc 2026-04-16 13:50:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:8470 https://access.redhat.com/errata/RHSA-2026:8470

Comment 3 errata-xmlrpc 2026-04-16 13:50:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:8472 https://access.redhat.com/errata/RHSA-2026:8472

Comment 4 errata-xmlrpc 2026-04-16 14:02:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:8468 https://access.redhat.com/errata/RHSA-2026:8468

Comment 5 errata-xmlrpc 2026-04-16 14:02:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:8467 https://access.redhat.com/errata/RHSA-2026:8467

Comment 6 errata-xmlrpc 2026-04-16 14:10:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:8469 https://access.redhat.com/errata/RHSA-2026:8469

Comment 7 errata-xmlrpc 2026-04-16 14:34:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:8475 https://access.redhat.com/errata/RHSA-2026:8475

Comment 8 errata-xmlrpc 2026-04-16 14:36:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:8473 https://access.redhat.com/errata/RHSA-2026:8473

Comment 9 errata-xmlrpc 2026-04-16 14:42:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:8471 https://access.redhat.com/errata/RHSA-2026:8471

Comment 10 errata-xmlrpc 2026-04-16 14:43:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:8474 https://access.redhat.com/errata/RHSA-2026:8474

Comment 17 errata-xmlrpc 2026-05-04 01:32:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:13281 https://access.redhat.com/errata/RHSA-2026:13281

Comment 18 errata-xmlrpc 2026-05-04 01:34:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:13280 https://access.redhat.com/errata/RHSA-2026:13280

Comment 19 errata-xmlrpc 2026-05-04 01:38:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:13283 https://access.redhat.com/errata/RHSA-2026:13283

Comment 20 errata-xmlrpc 2026-05-04 01:52:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:13282 https://access.redhat.com/errata/RHSA-2026:13282

Comment 21 errata-xmlrpc 2026-05-05 11:16:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:13693 https://access.redhat.com/errata/RHSA-2026:13693