CVE-2025-21173

Publication date 15 January 2025

Last updated 16 January 2025


Ubuntu priority

.NET Elevation of Privilege Vulnerability: Insecure Temp File Usage Allows Malicious Package Dependency Injection on Linux. An attacker could exploit this vulnerability to writing a specially crafted file in the security context of the local system. This only affects .NET on Linux operating systems.

Read the notes from the security team

Status

Package Ubuntu Release Status
dotnet6 24.10 oracular Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Ignored see notes
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release
dotnet7 24.10 oracular Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Ignored see notes
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release
dotnet8 24.10 oracular
Fixed 8.0.112-8.0.12-0ubuntu1~24.10.1
24.04 LTS noble
Fixed 8.0.112-8.0.12-0ubuntu1~24.04.1
22.04 LTS jammy
Fixed 8.0.112-8.0.12-0ubuntu1~22.04.1
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release
dotnet9 24.10 oracular
Fixed 9.0.102-9.0.1-0ubuntu1~24.10.1
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Notes


iconstantin

.NET 6 and .NET 7 are end of life upstream.