DSA-2023-132: Dell Container Storage Modules Security Update for multiple vulnerabilities.

Summary: Dell Container Storage Modules Security Update for multiple vulnerabilities.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component CVEs More Information
python3 CVE-2020-10735 https://access.redhat.com/errata/RHSA-2023:0833This hyperlink is taking you to a website outside of Dell Technologies.
libtasn1 CVE-2021-46848 https://access.redhat.com/security/cve/cve-2021-46848This hyperlink is taking you to a website outside of Dell Technologies. 
sqlite CVE-2022-35737 https://access.redhat.com/security/cve/cve-2022-35737This hyperlink is taking you to a website outside of Dell Technologies. 
systemd CVE-2022-3821 https://access.redhat.com/security/cve/cve-2022-3821This hyperlink is taking you to a website outside of Dell Technologies. 
libxml2 CVE-2022-40303 https://access.redhat.com/security/cve/cve-2022-40303This hyperlink is taking you to a website outside of Dell Technologies.  
libxml2 CVE-2022-40304 https://access.redhat.com/security/cve/cve-2022-40304This hyperlink is taking you to a website outside of Dell Technologies.  
golang: net/http CVE-2022-41717 https://access.redhat.com/security/cve/cve-2022-41717This hyperlink is taking you to a website outside of Dell Technologies. 
dbus CVE-2022-42010 https://access.redhat.com/security/cve/cve-2022-42010This hyperlink is taking you to a website outside of Dell Technologies.  
dbus CVE-2022-42011 https://access.redhat.com/security/cve/cve-2022-42011This hyperlink is taking you to a website outside of Dell Technologies.  
dbus CVE-2022-42012 https://access.redhat.com/security/cve/cve-2022-42012This hyperlink is taking you to a website outside of Dell Technologies.  
expat CVE-2022-43680 https://access.redhat.com/security/cve/cve-2022-43680This hyperlink is taking you to a website outside of Dell Technologies.  
systemd CVE-2022-4415 https://access.redhat.com/security/cve/cve-2022-4415This hyperlink is taking you to a website outside of Dell Technologies. 
python CVE-2022-45061 https://access.redhat.com/security/cve/cve-2022-45061This hyperlink is taking you to a website outside of Dell Technologies. 
sqlite CVE-2022-46908 https://access.redhat.com/security/cve/cve-2022-46908This hyperlink is taking you to a website outside of Dell Technologies.  
libksba CVE-2022-47629 https://access.redhat.com/security/cve/cve-2022-47629This hyperlink is taking you to a website outside of Dell Technologies. 
glibc CVE-2023-0687 https://access.redhat.com/security/cve/cve-2023-0687This hyperlink is taking you to a website outside of Dell Technologies. 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2020-10735, CVE-2021-46848, CVE-2022-35737, CVE-2022-3821, CVE-2022-40303, CVE-2022-40304, CVE-2022-41717, CVE-2022-42010, CVE-2022-42011, CVE-2022-42012, CVE-2022-43680, CVE-2022-4415, CVE-2022-45061, CVE-2022-46908, CVE-2022-47629, CVE-2023-0687 Dell Container Storage Modules Versions prior to 1.6 Version 1.6 https://github.com/dell/csm/tree/v1.6.0This hyperlink is taking you to a website outside of Dell Technologies.
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2020-10735, CVE-2021-46848, CVE-2022-35737, CVE-2022-3821, CVE-2022-40303, CVE-2022-40304, CVE-2022-41717, CVE-2022-42010, CVE-2022-42011, CVE-2022-42012, CVE-2022-43680, CVE-2022-4415, CVE-2022-45061, CVE-2022-46908, CVE-2022-47629, CVE-2023-0687 Dell Container Storage Modules Versions prior to 1.6 Version 1.6 https://github.com/dell/csm/tree/v1.6.0This hyperlink is taking you to a website outside of Dell Technologies.

Workarounds & Mitigations

none

Revision History

RevisionDateDescription
1.02023-03-31Initial Release
2.02023-04-03Minor Update
3.02023-09-01Updated for enhanced presentation with no changes to content.

Related Information

Article Properties
Article Number: 000211931
Article Type: Dell Security Advisory
Last Modified: 01 Sept 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.