Skip to content

Update Microsoft.NETCore.App.Runtime to 10.0.11 - #41332

Merged
Blue (OneBlue) merged 1 commit into
masterfrom
user/oneblue/package-update
Aug 12, 2026
Merged

Blue (OneBlue) merged 1 commit into
masterfrom
user/oneblue/package-update

Conversation

@OneBlue

Copy link
Copy Markdown
Collaborator

Summary of the Pull Request

This change updates the Microsoft.NETCore.App.Runtime* packages to 10.0.11 to receive security fixes.

PR Checklist

  • Closes: Link to issue #xxx
  • Communication: I've discussed this with core contributors already. If work hasn't been agreed, this work might be rejected
  • Tests: Added/updated if needed and all pass
  • Localization: All end user facing strings can be localized
  • Dev docs: Added/updated if needed
  • Documentation updated: If checked, please file a pull request on our docs repo and link it here: #xxx

Detailed Description of the Pull Request / Additional comments

Validation Steps Performed

@OneBlue
Blue (OneBlue) requested a review from a team as a code owner August 12, 2026 19:42
Copilot AI lite review requested due to automatic review settings August 12, 2026 19:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the pinned .NET runtime NuGet dependencies used by the WSL repo to pick up security fixes by moving Microsoft.NETCore.App.Runtime.* from 10.0.10 to 10.0.11.

Changes:

  • Bumped Microsoft.NETCore.App.Runtime.win-arm64 to 10.0.11
  • Bumped Microsoft.NETCore.App.Runtime.win-x64 to 10.0.11

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages.config
@OneBlue
Blue (OneBlue) merged commit 8edd976 into master Aug 12, 2026
12 checks passed
@OneBlue
Blue (OneBlue) deleted the user/oneblue/package-update branch August 12, 2026 21:50
Ben Hillis (benhillis) pushed a commit that referenced this pull request Sep 8, 2026
Ben Hillis (benhillis) added a commit that referenced this pull request Sep 10, 2026
* Validate NUL-termination of flexible-array Buffer in interop messages (#40402)

* Validate NUL-termination of flexible-array Buffer in interop messages

Use string::FromMessageBuffer<T>() instead of directly accessing the
Buffer[] flexible-array member in interop message structs. FromMessageBuffer
validates that a NUL terminator exists within the span bounds, preventing
out-of-bounds reads when a malformed message contains no Buffer data or
lacks NUL termination.

Affected message handlers:
- LxInitMessageQueryEnvironmentVariable (config.cpp)
- LxInitMessageCreateLoginSession (config.cpp)
- LxMiniInitMessageUnmount (main.cpp)

Co-authored-by: Copilot <[email protected]>

* Remove unused Message parameter name in WSLC_UNMOUNT handler

After switching to FromMessageBuffer, the Message parameter is no longer
referenced directly. Remove the name to avoid -Wunused-parameter.

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
(cherry picked from commit 909d5eb)

* Bind KdRelay to loopback (#41260)

Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
(cherry picked from commit 5eb2138)

* Update Microsoft.NETCore.App.Runtime to 10.0.11 (#41332)

(cherry picked from commit 8edd976)

* Fix unvalidated TerminalProfileSize during distribution import (#41495)

* Fix unvalidated TerminalProfileSize when importing a distribution

_ProcessImportResultMessage constructed the terminal profile string_view
using the message-supplied TerminalProfileSize without validating it
against the received buffer length. Use the bounds-checked two-argument
span::subspan() overload (matching the existing ShortcutIconSize handling
a few lines above) so an inconsistent size value throws instead of
producing a string_view that runs past the end of the buffer.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* format source

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
(cherry picked from commit f2d87e0)

* Avoid stop service race window during uninstall (#40625)

Disable service before stopping service during uninstall.

(cherry picked from commit c28bd15)

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Blue <[email protected]>
Co-authored-by: Feng Wang <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants