CVE-2025-36854Use After Free in Microsoft Microsoft.aspnetcore.app.runtime.linux-arm

CWE-416Use After Free3 documents3 sources
Severity
8.1HIGHNVD
EPSS
0.1%
top 68.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8

Description

A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use After Free https://cwe.mitre.org/data/definitions/416.html , Use After Free is when a product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another p

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages14 packages

🔴Vulnerability Details

2
GHSA
GHSA-qwjg-j8g7-hwvh: A vulnerability ( CVE-2024-38229 https://www2025-09-08
CVEList
EOL ASP.NET 6.0 Remote Code Execution Vulnerability2025-09-08
CVE-2025-36854 — Use After Free in Microsoft | cvebase