A Remote Code Execution vulnerability exists in .NET 7.0 and .NET 8.0 where a stack buffer overrun occurs in .NET Double Parse routine. Affected versions: .NET 7.0 .NET 8.0
CVE is Now public: https://github.com/dotnet/core/pull/9308/files#diff-9b061df180d53fac4004dec7d2894a3bf4baf36c5016756016a1ebbe3b83a05f
Created dotnet7.0 tracking bugs for this issue: Affects: fedora-all [bug 2280373] Created dotnet8.0 tracking bugs for this issue: Affects: fedora-all [bug 2280374]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2842 https://access.redhat.com/errata/RHSA-2024:2842
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2843 https://access.redhat.com/errata/RHSA-2024:2843
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3340 https://access.redhat.com/errata/RHSA-2024:3340
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3345 https://access.redhat.com/errata/RHSA-2024:3345