DSA-2025-375: Security Update for Dell Data Lakehouse Multiple Vulnerabilities
Summary: Dell Data Lakehouse remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
|
Third-party Component |
CVEs |
More Information |
|
containerd |
CVE-2024-40635 |
|
|
golang.org/x/net/html |
CVE-2024-45338, CVE-2025-22872 |
|
|
Intel 2025.2 IPU |
CVE-2025-20109 |
|
|
Intel 2025.3 IPU |
CVE-2025-20053, CVE-2025-24305, CVE-2025-21090, CVE-2025-21096, CVE-2025-22853, CVE-2025-20067, CVE-2025-22392 |
|
|
Integrated Dell Remote Access Controller 9 |
CVE-2025-36584 |
|
|
helm |
CVE-2025-32387, CVE-2025-32386 |
|
|
jackc |
CVE-2024-27304, CVE-2024-27289 |
|
|
SLES 15 SP6 |
CVE-2023-52888, CVE-2024-2236, CVE-2024-23337, CVE-2024-26831, CVE-2024-41965, CVE-2024-49568, CVE-2024-56613, CVE-2024-56699, CVE-2024-56738, CVE-2024-57982, CVE-2024-58053, CVE-2024-6104, CVE-2025-21658, CVE-2025-21720, CVE-2025-21868, CVE-2025-21898, CVE-2025-21899, CVE-2025-21920, CVE-2025-21938, CVE-2025-21959, CVE-2025-21997, CVE-2025-22035, CVE-2025-22083, CVE-2025-22111, CVE-2025-22113, CVE-2025-22120, CVE-2025-22869, CVE-2025-23155, CVE-2025-27144, CVE-2025-27221, CVE-2025-27465, CVE-2025-29768, CVE-2025-30258, CVE-2025-32462, CVE-2025-32463, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2025-37738, CVE-2025-37743, CVE-2025-37752, CVE-2025-37756, CVE-2025-37757, CVE-2025-37786, CVE-2025-37800, CVE-2025-37801, CVE-2025-37804, CVE-2025-37811, CVE-2025-37844, CVE-2025-37859, CVE-2025-37862, CVE-2025-37865, CVE-2025-37874, CVE-2025-37884, CVE-2025-37909, CVE-2025-37917, CVE-2025-37921, CVE-2025-37923, CVE-2025-37927, CVE-2025-37933, CVE-2025-37936, CVE-2025-37938, CVE-2025-37945, CVE-2025-37946, CVE-2025-37961, CVE-2025-37967, CVE-2025-37968, CVE-2025-37973, CVE-2025-37987, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38000, CVE-2025-38001, CVE-2025-38003, CVE-2025-38004, CVE-2025-38005, CVE-2025-38007, CVE-2025-38009, CVE-2025-38010, CVE-2025-38011, CVE-2025-38013, CVE-2025-38014, CVE-2025-38015, CVE-2025-38018, CVE-2025-38020, CVE-2025-38022, CVE-2025-38023, CVE-2025-38024, CVE-2025-38027, CVE-2025-38031, CVE-2025-38040, CVE-2025-38043, CVE-2025-38044, CVE-2025-38045, CVE-2025-38053, CVE-2025-38057, CVE-2025-38059, CVE-2025-38060, CVE-2025-38065, CVE-2025-38068, CVE-2025-38072, CVE-2025-38077, CVE-2025-38078, CVE-2025-38079, CVE-2025-38080, CVE-2025-38081, CVE-2025-38083, CVE-2025-40909, CVE-2025-4373, CVE-2025-4598, CVE-2025-46802, CVE-2025-47268, CVE-2025-47273, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796, CVE-2025-6018, CVE-2025-6020, CVE-2025-6021, CVE-2025-6052, CVE-2025-6170, CVE-2025-6297, CVE-2025-6395, CVE-2025-6442, CVE-2025-7519 |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46608 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46608 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Affected Products & Remediation
| Product | Affected Versions | Remediated Versions | Link |
| Dell Data Lakehouse | Versions prior to 1.6.0.0 | Version 1.6.0.0 or later | Contact Technical Support and Quote DSA-2025-375 |
| Product | Affected Versions | Remediated Versions | Link |
| Dell Data Lakehouse | Versions prior to 1.6.0.0 | Version 1.6.0.0 or later | Contact Technical Support and Quote DSA-2025-375 |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revision History
| Revision | Date | Description |
| 1.0 | 2025-11-12 | Initial release |