Upstream information

CVE-2026-62899 at MITRE

Description

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (Microsoft)
Base Score 5.9
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 10
  • aspnetcore-runtime-10.0 >= 10.0.11-1.el10_2
  • aspnetcore-runtime-8.0 >= 8.0.30-1.el10_2
  • aspnetcore-runtime-9.0 >= 9.0.19-1.el10_2
  • aspnetcore-runtime-dbg-10.0 >= 10.0.11-1.el10_2
  • aspnetcore-runtime-dbg-8.0 >= 8.0.30-1.el10_2
  • aspnetcore-runtime-dbg-9.0 >= 9.0.19-1.el10_2
  • aspnetcore-targeting-pack-10.0 >= 10.0.11-1.el10_2
  • aspnetcore-targeting-pack-8.0 >= 8.0.30-1.el10_2
  • aspnetcore-targeting-pack-9.0 >= 9.0.19-1.el10_2
  • dotnet-apphost-pack-10.0 >= 10.0.11-1.el10_2
  • dotnet-apphost-pack-8.0 >= 8.0.30-1.el10_2
  • dotnet-apphost-pack-9.0 >= 9.0.19-1.el10_2
  • dotnet-host >= 10.0.11-1.el10_2
  • dotnet-hostfxr-10.0 >= 10.0.11-1.el10_2
  • dotnet-hostfxr-8.0 >= 8.0.30-1.el10_2
  • dotnet-hostfxr-9.0 >= 9.0.19-1.el10_2
  • dotnet-runtime-10.0 >= 10.0.11-1.el10_2
  • dotnet-runtime-8.0 >= 8.0.30-1.el10_2
  • dotnet-runtime-9.0 >= 9.0.19-1.el10_2
  • dotnet-runtime-dbg-10.0 >= 10.0.11-1.el10_2
  • dotnet-runtime-dbg-8.0 >= 8.0.30-1.el10_2
  • dotnet-runtime-dbg-9.0 >= 9.0.19-1.el10_2
  • dotnet-sdk-10.0 >= 10.0.111-1.el10_2
  • dotnet-sdk-10.0-source-built-artifacts >= 10.0.111-1.el10_2
  • dotnet-sdk-8.0 >= 8.0.130-1.el10_2
  • dotnet-sdk-8.0-source-built-artifacts >= 8.0.130-1.el10_2
  • dotnet-sdk-9.0 >= 9.0.120-1.el10_2
  • dotnet-sdk-9.0-source-built-artifacts >= 9.0.120-1.el10_2
  • dotnet-sdk-aot-10.0 >= 10.0.111-1.el10_2
  • dotnet-sdk-aot-9.0 >= 9.0.120-1.el10_2
  • dotnet-sdk-dbg-10.0 >= 10.0.111-1.el10_2
  • dotnet-sdk-dbg-8.0 >= 8.0.130-1.el10_2
  • dotnet-sdk-dbg-9.0 >= 9.0.120-1.el10_2
  • dotnet-targeting-pack-10.0 >= 10.0.11-1.el10_2
  • dotnet-targeting-pack-8.0 >= 8.0.30-1.el10_2
  • dotnet-targeting-pack-9.0 >= 9.0.19-1.el10_2
  • dotnet-templates-10.0 >= 10.0.111-1.el10_2
  • dotnet-templates-8.0 >= 8.0.130-1.el10_2
  • dotnet-templates-9.0 >= 9.0.120-1.el10_2
  • netstandard-targeting-pack-2.1 >= 9.0.120-1.el10_2
Patchnames:
RHSA-2026:54541 (x86_64)
RHSA-2026:54590 (x86_64)
RHSA-2026:55858 (x86_64)
SUSE Liberty Linux 8
  • aspnetcore-runtime-10.0 >= 10.0.11-1.el8_10
  • aspnetcore-runtime-8.0 >= 8.0.30-1.el8_10
  • aspnetcore-runtime-9.0 >= 9.0.19-1.el8_10
  • aspnetcore-runtime-dbg-10.0 >= 10.0.11-1.el8_10
  • aspnetcore-runtime-dbg-8.0 >= 8.0.30-1.el8_10
  • aspnetcore-runtime-dbg-9.0 >= 9.0.19-1.el8_10
  • aspnetcore-targeting-pack-10.0 >= 10.0.11-1.el8_10
  • aspnetcore-targeting-pack-8.0 >= 8.0.30-1.el8_10
  • aspnetcore-targeting-pack-9.0 >= 9.0.19-1.el8_10
  • dotnet >= 10.0.111-1.el8_10
  • dotnet-apphost-pack-10.0 >= 10.0.11-1.el8_10
  • dotnet-apphost-pack-8.0 >= 8.0.30-1.el8_10
  • dotnet-apphost-pack-9.0 >= 9.0.19-1.el8_10
  • dotnet-host >= 10.0.11-1.el8_10
  • dotnet-hostfxr-10.0 >= 10.0.11-1.el8_10
  • dotnet-hostfxr-8.0 >= 8.0.30-1.el8_10
  • dotnet-hostfxr-9.0 >= 9.0.19-1.el8_10
  • dotnet-runtime-10.0 >= 10.0.11-1.el8_10
  • dotnet-runtime-8.0 >= 8.0.30-1.el8_10
  • dotnet-runtime-9.0 >= 9.0.19-1.el8_10
  • dotnet-runtime-dbg-10.0 >= 10.0.11-1.el8_10
  • dotnet-runtime-dbg-8.0 >= 8.0.30-1.el8_10
  • dotnet-runtime-dbg-9.0 >= 9.0.19-1.el8_10
  • dotnet-sdk-10.0 >= 10.0.111-1.el8_10
  • dotnet-sdk-10.0-source-built-artifacts >= 10.0.111-1.el8_10
  • dotnet-sdk-8.0 >= 8.0.130-1.el8_10
  • dotnet-sdk-8.0-source-built-artifacts >= 8.0.130-1.el8_10
  • dotnet-sdk-9.0 >= 9.0.120-1.el8_10
  • dotnet-sdk-9.0-source-built-artifacts >= 9.0.120-1.el8_10
  • dotnet-sdk-aot-10.0 >= 10.0.111-1.el8_10
  • dotnet-sdk-aot-9.0 >= 9.0.120-1.el8_10
  • dotnet-sdk-dbg-10.0 >= 10.0.111-1.el8_10
  • dotnet-sdk-dbg-8.0 >= 8.0.130-1.el8_10
  • dotnet-sdk-dbg-9.0 >= 9.0.120-1.el8_10
  • dotnet-targeting-pack-10.0 >= 10.0.11-1.el8_10
  • dotnet-targeting-pack-8.0 >= 8.0.30-1.el8_10
  • dotnet-targeting-pack-9.0 >= 9.0.19-1.el8_10
  • dotnet-templates-10.0 >= 10.0.111-1.el8_10
  • dotnet-templates-8.0 >= 8.0.130-1.el8_10
  • dotnet-templates-9.0 >= 9.0.120-1.el8_10
  • netstandard-targeting-pack-2.1 >= 9.0.120-1.el8_10
Patchnames:
RHSA-2026:54538 (x86_64)
RHSA-2026:54542 (x86_64)
RHSA-2026:54550 (x86_64)
SUSE Liberty Linux 9.6 EMS
  • aspnetcore-runtime-8.0 >= 8.0.30-1.el9_6
  • aspnetcore-runtime-9.0 >= 9.0.19-1.el9_6
  • aspnetcore-runtime-dbg-8.0 >= 8.0.30-1.el9_6
  • aspnetcore-runtime-dbg-9.0 >= 9.0.19-1.el9_6
  • aspnetcore-targeting-pack-8.0 >= 8.0.30-1.el9_6
  • aspnetcore-targeting-pack-9.0 >= 9.0.19-1.el9_6
  • dotnet-apphost-pack-8.0 >= 8.0.30-1.el9_6
  • dotnet-apphost-pack-9.0 >= 9.0.19-1.el9_6
  • dotnet-host >= 9.0.19-1.el9_6
  • dotnet-hostfxr-8.0 >= 8.0.30-1.el9_6
  • dotnet-hostfxr-9.0 >= 9.0.19-1.el9_6
  • dotnet-runtime-8.0 >= 8.0.30-1.el9_6
  • dotnet-runtime-9.0 >= 9.0.19-1.el9_6
  • dotnet-runtime-dbg-8.0 >= 8.0.30-1.el9_6
  • dotnet-runtime-dbg-9.0 >= 9.0.19-1.el9_6
  • dotnet-sdk-8.0 >= 8.0.130-1.el9_6
  • dotnet-sdk-8.0-source-built-artifacts >= 8.0.130-1.el9_6
  • dotnet-sdk-9.0 >= 9.0.120-1.el9_6
  • dotnet-sdk-9.0-source-built-artifacts >= 9.0.120-1.el9_6
  • dotnet-sdk-aot-9.0 >= 9.0.120-1.el9_6
  • dotnet-sdk-dbg-8.0 >= 8.0.130-1.el9_6
  • dotnet-sdk-dbg-9.0 >= 9.0.120-1.el9_6
  • dotnet-targeting-pack-8.0 >= 8.0.30-1.el9_6
  • dotnet-targeting-pack-9.0 >= 9.0.19-1.el9_6
  • dotnet-templates-8.0 >= 8.0.130-1.el9_6
  • dotnet-templates-9.0 >= 9.0.120-1.el9_6
  • netstandard-targeting-pack-2.1 >= 9.0.120-1.el9_6
Patchnames:
RHSA-2026:58569 (x86_64)
RHSA-2026:58570 (x86_64)
SUSE Liberty Linux 9
  • aspnetcore-runtime-10.0 >= 10.0.11-1.el9_8
  • aspnetcore-runtime-8.0 >= 8.0.30-1.el9_8
  • aspnetcore-runtime-9.0 >= 9.0.19-1.el9_8
  • aspnetcore-runtime-dbg-10.0 >= 10.0.11-1.el9_8
  • aspnetcore-runtime-dbg-8.0 >= 8.0.30-1.el9_8
  • aspnetcore-runtime-dbg-9.0 >= 9.0.19-1.el9_8
  • aspnetcore-targeting-pack-10.0 >= 10.0.11-1.el9_8
  • aspnetcore-targeting-pack-8.0 >= 8.0.30-1.el9_8
  • aspnetcore-targeting-pack-9.0 >= 9.0.19-1.el9_8
  • dotnet-apphost-pack-10.0 >= 10.0.11-1.el9_8
  • dotnet-apphost-pack-8.0 >= 8.0.30-1.el9_8
  • dotnet-apphost-pack-9.0 >= 9.0.19-1.el9_8
  • dotnet-host >= 10.0.11-1.el9_8
  • dotnet-hostfxr-10.0 >= 10.0.11-1.el9_8
  • dotnet-hostfxr-8.0 >= 8.0.30-1.el9_8
  • dotnet-hostfxr-9.0 >= 9.0.19-1.el9_8
  • dotnet-runtime-10.0 >= 10.0.11-1.el9_8
  • dotnet-runtime-8.0 >= 8.0.30-1.el9_8
  • dotnet-runtime-9.0 >= 9.0.19-1.el9_8
  • dotnet-runtime-dbg-10.0 >= 10.0.11-1.el9_8
  • dotnet-runtime-dbg-8.0 >= 8.0.30-1.el9_8
  • dotnet-runtime-dbg-9.0 >= 9.0.19-1.el9_8
  • dotnet-sdk-10.0 >= 10.0.111-1.el9_8
  • dotnet-sdk-10.0-source-built-artifacts >= 10.0.111-1.el9_8
  • dotnet-sdk-8.0 >= 8.0.130-1.el9_8
  • dotnet-sdk-8.0-source-built-artifacts >= 8.0.130-1.el9_8
  • dotnet-sdk-9.0 >= 9.0.120-1.el9_8
  • dotnet-sdk-9.0-source-built-artifacts >= 9.0.120-1.el9_8
  • dotnet-sdk-aot-10.0 >= 10.0.111-1.el9_8
  • dotnet-sdk-aot-9.0 >= 9.0.120-1.el9_8
  • dotnet-sdk-dbg-10.0 >= 10.0.111-1.el9_8
  • dotnet-sdk-dbg-8.0 >= 8.0.130-1.el9_8
  • dotnet-sdk-dbg-9.0 >= 9.0.120-1.el9_8
  • dotnet-targeting-pack-10.0 >= 10.0.11-1.el9_8
  • dotnet-targeting-pack-8.0 >= 8.0.30-1.el9_8
  • dotnet-targeting-pack-9.0 >= 9.0.19-1.el9_8
  • dotnet-templates-10.0 >= 10.0.111-1.el9_8
  • dotnet-templates-8.0 >= 8.0.130-1.el9_8
  • dotnet-templates-9.0 >= 9.0.120-1.el9_8
  • netstandard-targeting-pack-2.1 >= 9.0.120-1.el9_8
Patchnames:
RHSA-2026:54574 (x86_64)
RHSA-2026:55856 (x86_64)
RHSA-2026:55857 (x86_64)


SUSE Timeline for this CVE

CVE page created: Mon Aug 17 13:42:01 2026
CVE page last modified: Thu Oct 8 17:48:59 2026