SB20261001159 - Ubuntu update for dotnet10
Published: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Origin validation error (CVE-ID: CVE-2026-58649)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an origin validation error in .NET when validating origins. A remote attacker can exploit the vulnerability to disclose sensitive information.
User interaction is required. Successful exploitation could expose developer-time hot reload data, including application metadata, intermediate language updates, debugging information, method names, string literals, and file paths.
2) Information disclosure (CVE-ID: CVE-2026-69806)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in .NET for Linux when local users can access process information through the proc filesystem. A local user can access exposed process information to elevate privileges.
Successful exploitation requires a Linux environment in which users share a process identifier namespace. The attacker can gain the privileges of the user account or service account running the affected process.
Remediation
Install update from vendor's website.