來源Ars Technica•較早收集於 29m
Microsoft 發布 macOS/Linux ASP.NET 緊急更新

#security-update#dotnet-core#cross-platformasp.netmicrosoftasp.netmacoslinux
💡ASP.NET 認證漏洞緊急修補—更新 macOS/Linux .NET 應用防範攻擊。(26字元)
⚡ 30 秒速覽
有什麼變化
Microsoft 針對 ASP.NET 的緊急安全更新。
為什麼重要
對非 Windows 平台 .NET 網頁應用開發者至關重要;防止生產環境漏洞。提升跨平台採用中的安全態勢。
下一步行動
立即在 macOS/Linux ASP.NET 應用執行 'dotnet --update' 套用安全修補。
誰應關注:Developers & AI Engineers
關鍵要點
- •Microsoft 針對 ASP.NET 的緊急安全更新。
- •特別影響 macOS 和 Linux 部署。
- •漏洞利用認證失敗情境。
- •未修補可能造成嚴重後果。
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 4 個來源。
🔑 增強重點摘要
- •The vulnerability, identified as CVE-2026-40372 with a CVSS score of 9.1, is a regression introduced in the .NET 10.0.6 package released during the April 14, 2026, Patch Tuesday.
- •The flaw specifically affects the ManagedAuthenticatedEncryptor library within the Microsoft.AspNetCore.DataProtection NuGet package, causing it to compute HMAC validation tags over incorrect payload offsets on non-Windows operating systems.
- •Mitigation requires more than just updating to version 10.0.7; developers must also rebuild applications to incorporate the fix and are strongly advised to rotate their DataProtection key rings to invalidate any tokens potentially forged during the vulnerable window.
🛠️ 技術深入
- •Vulnerability Type: Improper Verification of Cryptographic Signature (CWE-347).
- •Affected Component: Microsoft.AspNetCore.DataProtection NuGet package (versions 10.0.0 through 10.0.6).
- •Root Cause: A regression in the ManagedAuthenticatedEncryptor library causes HMAC validation tags to be computed over incorrect bytes, leading to the potential acceptance of forged payloads.
- •Impact: Allows attackers to forge authentication cookies, anti-forgery tokens, and decrypt previously-protected payloads, potentially leading to privilege escalation.
- •Platform Specificity: Primarily impacts Linux, macOS, and other non-Windows OS environments; Windows systems are generally unaffected unless they explicitly opt into managed algorithms via the UseCustomCryptographicAlgorithms API.
🔮 前景展望基於引用來源的 AI 分析
Increased scrutiny of cross-platform cryptographic implementations in .NET.
The severity of this regression on non-Windows platforms highlights a critical gap in parity testing for cryptographic libraries across different operating systems.
Mandatory key rotation will become a standard post-patching requirement for ASP.NET security incidents.
Because forged tokens remain valid even after the software is patched, organizations will increasingly adopt automated key rotation as a necessary step in incident response.
⏳ 時間線
2026-04-14
Microsoft releases .NET 10.0.6 as part of Patch Tuesday, inadvertently introducing the regression.
2026-04-21
Microsoft publishes security advisory for CVE-2026-40372 and releases version 10.0.7 to address the flaw.
2026-04-22
Emergency patching guidance is widely disseminated to developers for immediate application.
📎 來源 (4)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Ars Technica ↗
每週電子報
每週一封,可隨時退訂。