DSA-2026-274: Security Update for Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software Multiple Third-Party Component Vulnerabilities
Zusammenfassung: Dell APEX Cloud Platform for Microsoft Azure remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...
Auswirkungen
Critical
Details
| Third-party Component | CVEs | More Information |
| Linux Kernel | CVE-2026-1642, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2025-45582, CVE-2026-2007, CVE-2026-2004, CVE-2026-2003, CVE-2026-2006, CVE-2026-2005, CVE-2025-6075, CVE-2025-13836, CVE-2025-13837, CVE-2025-12084, CVE-2025-11468, CVE-2026-0672, CVE-2026-0865, CVE-2025-15282, CVE-2026-1299, CVE-2026-2297, CVE-2025-13462, CVE-2026-3644, CVE-2026-4224, CVE-2026-3479, CVE-2026-4519, CVE-2025-67726, CVE-2025-67725, CVE-2025-67724, CVE-2026-23555, CVE-2026-23554, CVE-2025-12801, CVE-2026-25075, CVE-2026-35385, CVE-2026-35414, CVE-2026-23865, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-34282, CVE-2026-31431, CVE-2025-53906, CVE-2026-26269, CVE-2026-28417, CVE-2026-28390, CVE-2026-1467, CVE-2026-1539, CVE-2026-1760, CVE-2026-1965, CVE-2026-4873, CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-21637, CVE-2026-21715, CVE-2026-21717, CVE-2026-21716, CVE-2026-21714, CVE-2026-21710, CVE-2026-21713, CVE-2024-36137, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638, CVE-2024-38542, CVE-2025-37861, CVE-2025-39817, CVE-2025-39964, CVE-2025-40099, CVE-2025-40103, CVE-2023-53817, CVE-2025-40253, CVE-2025-71066, CVE-2025-71113, CVE-2026-23004, CVE-2026-23054, CVE-2026-23060, CVE-2026-23074, CVE-2026-23089, CVE-2026-23111, CVE-2026-23202, CVE-2026-23204, CVE-2026-23157, CVE-2026-23141, CVE-2026-23191, CVE-2025-71231, CVE-2026-23214, CVE-2026-23209, CVE-2026-23207, CVE-2026-23268, CVE-2026-23269, CVE-2026-1519, CVE-2026-4437, CVE-2026-4438, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789, CVE-2026-43500, CVE-2026-2291, CVE-2026-6507, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172, CVE-2026-33412, CVE-2026-34982, CVE-2026-34714, CVE-2026-2781, CVE-2026-31790, CVE-2026-35535, CVE-2025-66614, CVE-2026-24733, CVE-2026-24734, CVE-2026-24880, CVE-2026-25854, CVE-2026-29129, CVE-2026-29145, CVE-2026-29146, CVE-2026-34486, CVE-2026-34483, CVE-2026-34487, CVE-2026-34500, CVE-2026-32990, CVE-2025-39998, CVE-2026-23103, CVE-2026-23231, CVE-2026-31788, CVE-2026-23243, CVE-2026-23278, CVE-2026-23274, CVE-2026-23272, CVE-2026-23381, CVE-2026-23293, CVE-2026-23317, CVE-2026-23398, CVE-2026-23412, CVE-2026-23413, CVE-2026-3446, CVE-2026-1502, CVE-2026-4786, CVE-2026-6019, CVE-2026-6100, CVE-2026-33416, CVE-2026-33636, CVE-2026-33554, CVE-2026-27135, CVE-2026-40706, CVE-2025-54518, CVE-2026-46300, CVE-2026-46333, CVE-2026-32777, CVE-2026-32776, CVE-2026-32778, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805, CVE-2026-21620, CVE-2026-23942, CVE-2026-23943, CVE-2026-23941, CVE-2026-28808, CVE-2026-4775, CVE-2026-29111, CVE-2026-4105, CVE-2026-30922, CVE-2026-34990, CVE-2026-4878 | https://nvd.nist.gov/vuln/search |
| Security Update for NVIDIA Bluefield and ConnectX Vulnerabilities | CVE-2025-23262, CVE-2025-23299 | DSA-2026-119 , DSA-2026-121 |
| FreeRDP | CVE-2026-26950 | https://nvd.nist.gov/vuln/search |
| HTTP | CVE-2025-13836 | https://nvd.nist.gov/vuln/search |
| Security Update for Dell PowerEdge Server for an OpenSSL Vulnerability | CVE-2026-22796 | DSA-2026-136 |
| UEFI Reference Firmware Advisory | CVE-2025-35991 | DSA-2026-027 |
| NVIDIA ConnectX and BlueField | CVE-2025-23350, CVE-2025-23351 | https://nvd.nist.gov/vuln/search |
Betroffene Produkte und Korrektur
| Product | Affected Versions | Remediated Versions | Link |
| Dell APEX Cloud Platform for Microsoft Azure | Versions prior to 01.07.02.00 | Version 01.07.02.00 or later | https://www.dell.com/support/home/product-support/product/apex-cloud-pf-ms-azure/drivers |
| Product | Affected Versions | Remediated Versions | Link |
| Dell APEX Cloud Platform for Microsoft Azure | Versions prior to 01.07.02.00 | Version 01.07.02.00 or later | https://www.dell.com/support/home/product-support/product/apex-cloud-pf-ms-azure/drivers |
Workarounds und Korrekturmaßnahmen
| CVE ID | Workaround and Mitigation |
|
CVE-2026-31431 |
For customers who need to mitigate the vulnerability before upgrading to ACP Azure 01.07.02.00, Dell recommends blacklisting the algif_aead kernel module. Steps to Apply the Workaround:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf rmmod algif_aead 2>/dev/null
modprobe algif_aead This command should fail (module load denied). lsmod | grep algif_aead This should return empty (module not loaded). Post-Upgrade Cleanup: After upgrading to ACP Azure 01.07.02.00 or later, Dell strongly recommends removing the blacklist configuration to ensure compatibility with potential future enhancements: rm -f /etc/modprobe.d/disable-algif-aead.conf
Note: On fresh deployments, the file
|
Revisionsverlauf
| Revision | Date | Description |
| 1.0 | 2026-06-16 | Initial Release |
| 2.0 | 2026-06-22 | Adding the remediated vulnerabilities for the released version 01.07.02.00 |