SB20261001159 - Ubuntu update for dotnet10



SB20261001159 - Ubuntu update for dotnet10

Published: October 1, 2026

Security Bulletin ID SB20261001159
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Origin validation error (CVE-ID: CVE-2026-58649)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an origin validation error in .NET when validating origins. A remote attacker can exploit the vulnerability to disclose sensitive information.

User interaction is required. Successful exploitation could expose developer-time hot reload data, including application metadata, intermediate language updates, debugging information, method names, string literals, and file paths.


2) Information disclosure (CVE-ID: CVE-2026-69806)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to elevate privileges.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in .NET for Linux when local users can access process information through the proc filesystem. A local user can access exposed process information to elevate privileges.

Successful exploitation requires a Linux environment in which users share a process identifier namespace. The attacker can gain the privileges of the user account or service account running the affected process.


Remediation

Install update from vendor's website.