DSA-2025-184: Security Update for Dell Data Lakehouse Multiple Third-Party Component Vulnerabilities
Summary: Dell Data Lakehouse remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
|
busybox |
CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366 |
|
|
json-path v2.8.0 |
CVE-2023-51074 |
|
|
derby |
CVE-2018-1313, CVE-2022-46337 |
|
|
glib2 |
CVE-2024-52533 |
|
|
go |
CVE-2022-41716, CVE-2023-29402, CVE-2023-29404, CVE-2023-29405, CVE-2023-39323, CVE-2023-45285 |
|
|
Intel(R) TDX Module |
CVE-2024-27457 |
|
|
Intel(R) Xeon(R) processor |
CVE-2024-23919, CVE-2024-25565, CVE-2024-31068, CVE-2024-34023, CVE-2024-34170, CVE-2024-36242, CVE-2024-38660, CVE-2024-38665 |
|
|
java |
CVE-2024-20918, CVE-2024-20926, CVE-2024-20952 |
|
|
Apache Log4j SMTP |
CVE-2020-9488 |
|
|
Bouncy Castle Java Cryptography APIs |
CVE-2024-30172 |
|
|
iq80 Snappy |
CVE-2024-36124 |
|
|
EDK2 |
CVE-2024-38796 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Data Lakehouse |
Versions prior to 1.4.0.0 |
Version 1.4.0.0 or later |
https://www.dell.com/support/product-details/product/dell-data-lakehouse/drivers |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Data Lakehouse |
Versions prior to 1.4.0.0 |
Version 1.4.0.0 or later |
https://www.dell.com/support/product-details/product/dell-data-lakehouse/drivers |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-04-16 |
Initial Release |