This vulnerability in SignInManager.RefreshSignInAsync poses a risk of privilege escalation. It allows a locally authenticated user with low privileges to potentially elevate access due to improper handling of authentication refresh mechanisms. Affected versions: .NET 8.0 .NET 9.0 Affected packages: Package(s): Microsoft.AspNetCore.App.Runtime.* Affected version: >=9.0.0, <= 9.0.2 , >=8.0.0, <=8.0.13 Patched version: 9.0.2, 8.0.14 Package(s): Microsoft.AspNetCore.Identity Affected version: 2.3.0 Patched version: 2.3.1
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2666 https://access.redhat.com/errata/RHSA-2025:2666
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2668 https://access.redhat.com/errata/RHSA-2025:2668
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2669 https://access.redhat.com/errata/RHSA-2025:2669
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2670 https://access.redhat.com/errata/RHSA-2025:2670
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2667 https://access.redhat.com/errata/RHSA-2025:2667