DSA-2026-417: Security update for Dell Update Package (DUP) Framework Vulnerabilities
Oversigt: Dell Update Package (DUP) Framework remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Virkning
High
Oplysninger
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-71179 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2026-71180 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
|
|
CVE-2026-71181 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
3.0 |
|
|
CVE-2026-71182 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
3.0 |
|
|
CVE-2026-86358 |
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. |
6.5 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-71179 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
7.3 |
|
|
CVE-2026-71180 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
8.2 |
|
|
CVE-2026-71181 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
3.0 |
|
|
CVE-2026-71182 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
3.0 |
|
|
CVE-2026-86358 |
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. |
6.5 |
Berørte produkter og udbedring
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Version prior to 26.07.03 |
Version 26.07.03 or later |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Update Package (DUP) Framework |
Version prior to 26.07.03 |
Version 26.07.03 or later |
Revisionshistorik
|
Revision |
Date |
Description |
|
1.0 |
2026-09-15 |
Initial Release |