Bug 2500565 (CVE-2026-50526)

Summary: CVE-2026-50526 dotnet: .NET: Local tampering via improper link resolution
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, sdawley, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in .NET. This vulnerability, stemming from improper link resolution before file access, allows an authorized local attacker to perform tampering. This could lead to unauthorized modification of data or system files.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2501484, 2501488, 2501489    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-14 20:02:53 UTC
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Comment 3 errata-xmlrpc 2026-07-20 04:05:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:41899 https://access.redhat.com/errata/RHSA-2026:41899

Comment 4 errata-xmlrpc 2026-07-20 04:09:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:41893 https://access.redhat.com/errata/RHSA-2026:41893

Comment 5 errata-xmlrpc 2026-07-20 04:32:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:41895 https://access.redhat.com/errata/RHSA-2026:41895

Comment 6 errata-xmlrpc 2026-07-20 04:37:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:41897 https://access.redhat.com/errata/RHSA-2026:41897

Comment 7 errata-xmlrpc 2026-07-20 04:38:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:41900 https://access.redhat.com/errata/RHSA-2026:41900

Comment 8 errata-xmlrpc 2026-07-20 04:46:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:41901 https://access.redhat.com/errata/RHSA-2026:41901

Comment 9 errata-xmlrpc 2026-07-20 04:57:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:41894 https://access.redhat.com/errata/RHSA-2026:41894

Comment 10 errata-xmlrpc 2026-07-20 06:20:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:41896 https://access.redhat.com/errata/RHSA-2026:41896

Comment 11 errata-xmlrpc 2026-07-20 06:24:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:41898 https://access.redhat.com/errata/RHSA-2026:41898

Comment 12 errata-xmlrpc 2026-08-24 02:52:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:58566 https://access.redhat.com/errata/RHSA-2026:58566

Comment 13 errata-xmlrpc 2026-08-24 02:53:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:58567 https://access.redhat.com/errata/RHSA-2026:58567

Comment 14 errata-xmlrpc 2026-08-24 04:22:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:58568 https://access.redhat.com/errata/RHSA-2026:58568

Comment 15 errata-xmlrpc 2026-08-24 05:42:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:58569 https://access.redhat.com/errata/RHSA-2026:58569

Comment 16 errata-xmlrpc 2026-08-24 05:48:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:58570 https://access.redhat.com/errata/RHSA-2026:58570