CVE Vulnerabilities

CVE-2025-21176

Buffer Over-read

Published: Jan 14, 2025 | Modified: Apr 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

Name Vendor Start Version End Version
.net Microsoft 8.0.0 (including) 8.0.0 (including)
Red Hat Enterprise Linux 8 RedHat dotnet8.0-0:8.0.112-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat dotnet9.0-0:9.0.102-1.el8_10 *
Red Hat Enterprise Linux 9 RedHat dotnet8.0-0:8.0.112-1.el9_5 *
Red Hat Enterprise Linux 9 RedHat dotnet9.0-0:9.0.102-1.el9_5 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat dotnet8.0-0:8.0.112-1.el9_4 *
Dotnet6 Ubuntu jammy *
Dotnet7 Ubuntu jammy *
Dotnet8 Ubuntu devel *
Dotnet8 Ubuntu jammy *
Dotnet8 Ubuntu noble *
Dotnet8 Ubuntu oracular *
Dotnet9 Ubuntu devel *
Dotnet9 Ubuntu oracular *

References