It was discovered that .NET did not properly handle link resolution before file access. A local attacker could use this issue to perform unauthorized file tampering and write arbitrary files outside of the intended extraction directory. ( CVE-2026-45491 ) It was discovered that .NET did not properly handle deeply-nested MessagePack arrays. An attacker could use this to cause .NET to consume excessive resources, resulting in a denial of service. ( CVE-2026-45591 )
It was discovered that .NET did not properly handle link resolution before file access. A local attacker could use this issue to perform unauthorized file tampering and write arbitrary files outside of the intended extraction directory. ( CVE-2026-45491 )
It was discovered that .NET did not properly handle deeply-nested MessagePack arrays. An attacker could use this to cause .NET to consume excessive resources, resulting in a denial of service. ( CVE-2026-45591 )
It was discovered that .NET did not properly handle link resolution before file access. A local attacker could use this issue to perform unauthorized file tampering and write arbitrary files outside of the intended extraction directory. ( CVE-2026-45491 ) It was discovered that .NET did not properly handle deeply-nested MessagePack arrays. An attacker could use this to cause .NET to consume excessive resources, resulting in a denial of service. ( CVE-2026-45591 )
It was discovered that .NET did not properly handle link resolution before file access. A local attacker could use this issue to perform unauthorized file tampering and write arbitrary files outside of the intended extraction directory. ( CVE-2026-45491 )
It was discovered that .NET did not properly handle deeply-nested MessagePack arrays. An attacker could use this to cause .NET to consume excessive resources, resulting in a denial of service. ( CVE-2026-45591 )
In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
