Fedora Account System
Red Hat Associate
Red Hat Customer
It was discovered that ASP.NET Core did not properly handle client disconnects under all circumstances. By sending specially crafted requests to an ASP.NET Core application, a remote unauthenticated attacker could possibly exploit this flaw to consume more disk and CPU resources than necessary, possibly leading to a denial of service via resource exhaustion. External references: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1597 https://github.com/dotnet/announcements/issues/162
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2020:3421 https://access.redhat.com/errata/RHSA-2020:3421
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:3422 https://access.redhat.com/errata/RHSA-2020:3422
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-1597