Dotnet: Denial of Service - Parsing an empty HTTP response as a JSON.NET JObject causes a stack overflow and crashes a process Affected packages System.Runtime.Serialization.Xml is the affected component that is included in NETCore.App. Affected: Microsoft.NETCore.App.Runtime.* Affected version: >= 6.0.0, < 6.0.13 Patched version: 6.0.13
Created dotnet6.0 tracking bugs for this issue: Affects: fedora-all [bug 2159810]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:0077 https://access.redhat.com/errata/RHSA-2023:0077
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2023:0078 https://access.redhat.com/errata/RHSA-2023:0078
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0079 https://access.redhat.com/errata/RHSA-2023:0079
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-21538