{
  "threat_severity" : "Important",
  "public_date" : "2026-08-11T00:00:00Z",
  "bugzilla" : {
    "description" : ".NET: .NET Elevation of Privilege Vulnerability",
    "id" : "2512185",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2512185"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-252",
  "details" : [ "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.", "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally." ],
  "statement" : "This vulnerability is rated as Important. A truncation error in the .NET diagnostics IPC, specifically within ipc_transport_get_default_name when processing excessively long TMPDIR paths, could lead to a local elevation of privilege. This allows an attacker with local access to potentially gain higher privileges on the system.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54541",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet8.0-0:8.0.130-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54590",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet9.0-0:9.0.120-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55858",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet10.0-0:10.0.111-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58566",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet8.0-0:8.0.130-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58567",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet9.0-0:9.0.120-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54538",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet8.0-0:8.0.130-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54542",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet10.0-0:10.0.111-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54550",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet9.0-0:9.0.120-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54574",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet8.0-0:8.0.130-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55856",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet9.0-0:9.0.120-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55857",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet10.0-0:10.0.111-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58568",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "dotnet8.0-0:8.0.130-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58569",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet8.0-0:8.0.130-1.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58570",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet9.0-0:9.0.120-1.el9_6"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-24T00:00:00Z",
    "advisory" : "RHSA-2026:44914",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet9-0-main-9.0.119-2.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-15T00:00:00Z",
    "advisory" : "RHSA-2026:55142",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet10-0-main-10.0.11-1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-16T00:00:00Z",
    "advisory" : "RHSA-2026:55405",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet8-0-main-8.0.130-0.1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Affected",
    "package_name" : "devspaces/udi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-62909\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-62909" ],
  "name" : "CVE-2026-62909",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}