USN-6278-2

    Dashboard / Vulnerabilities / USN-6278-2

    USN-6278-2

    Published: 10 Aug 2023Last Modified: 10 Feb 2026

    Summary: dotnet6, dotnet7 vulnerabilities

    Details: USN-6278-1 fixed several vulnerabilities in .NET. This update provides the corresponding updates for Ubuntu 22.04 LTS. Original advisory details: It was discovered that .NET did properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. (CVE-2023-35390) Benoit Foucher discovered that .NET did not properly implement the QUIC stream limit in HTTP/3. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38178) It was discovered that .NET did not properly handle the disconnection of potentially malicious clients interfacing with a Kestrel server. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38180)

    Affected packages

    Package

    Name: dotnet6

    Purl: pkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammy

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.0.121-0ubuntu1~22.04.1

    Affected versions

    6.0.108-0ubuntu1~22.04.1
    6.0.109-0ubuntu1~22.04.1
    6.0.110-0ubuntu1~22.04.1
    6.0.111-0ubuntu1~22.04.1
    6.0.113-0ubuntu1~22.04.1
    6.0.116-0ubuntu1~22.04.1
    6.0.118-0ubuntu1~22.04.1
    6.0.119-0ubuntu1~22.04.1
    6.0.120-0ubuntu1~22.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-6278-2 | CVE-DB