Remote Code Execution: When running some dotnet commands(e.g. dotnet help add), dotnet attempts to locate and initiate a new process using cmd.exe. However, it prioritizes searching for cmd.exe in the current working directory (CWD) before checking other locations. This can potentially lead to the execution of malicious code;
Created dotnet6.0 tracking bugs for this issue: Affects: fedora-all [bug 2230089] Created dotnet7.0 tracking bugs for this issue: Affects: fedora-all [bug 2230088]
External References: https://devblogs.microsoft.com/dotnet/august-2023-updates/ https://github.com/advisories/GHSA-p8rx-fwgq-rh2f https://github.com/dotnet/announcements/issues/266 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35390
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2023:4639 https://access.redhat.com/errata/RHSA-2023:4639
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2023:4640 https://access.redhat.com/errata/RHSA-2023:4640
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2023:4641 https://access.redhat.com/errata/RHSA-2023:4641
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:4642 https://access.redhat.com/errata/RHSA-2023:4642
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:4644 https://access.redhat.com/errata/RHSA-2023:4644
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:4645 https://access.redhat.com/errata/RHSA-2023:4645
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:4643 https://access.redhat.com/errata/RHSA-2023:4643
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-35390