DSA-2025-375: Security Update for Dell Data Lakehouse Multiple Vulnerabilities
Resumen: Dell Data Lakehouse remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impacto
Critical
Detalles
|
Third-party Component |
CVEs |
More Information |
|
containerd |
CVE-2024-40635 |
|
|
golang.org/x/net/html |
CVE-2024-45338, CVE-2025-22872 |
|
|
Intel 2025.2 IPU |
CVE-2025-20109 |
|
|
Intel 2025.3 IPU |
CVE-2025-20053, CVE-2025-24305, CVE-2025-21090, CVE-2025-21096, CVE-2025-22853, CVE-2025-20067, CVE-2025-22392 |
|
|
Integrated Dell Remote Access Controller 9 |
CVE-2025-36584 |
|
|
helm |
CVE-2025-32387, CVE-2025-32386 |
|
|
jackc |
CVE-2024-27304, CVE-2024-27289 |
|
|
SLES 15 SP6 |
CVE-2023-52888, CVE-2024-2236, CVE-2024-23337, CVE-2024-26831, CVE-2024-41965, CVE-2024-49568, CVE-2024-56613, CVE-2024-56699, CVE-2024-56738, CVE-2024-57982, CVE-2024-58053, CVE-2024-6104, CVE-2025-21658, CVE-2025-21720, CVE-2025-21868, CVE-2025-21898, CVE-2025-21899, CVE-2025-21920, CVE-2025-21938, CVE-2025-21959, CVE-2025-21997, CVE-2025-22035, CVE-2025-22083, CVE-2025-22111, CVE-2025-22113, CVE-2025-22120, CVE-2025-22869, CVE-2025-23155, CVE-2025-27144, CVE-2025-27221, CVE-2025-27465, CVE-2025-29768, CVE-2025-30258, CVE-2025-32462, CVE-2025-32463, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2025-37738, CVE-2025-37743, CVE-2025-37752, CVE-2025-37756, CVE-2025-37757, CVE-2025-37786, CVE-2025-37800, CVE-2025-37801, CVE-2025-37804, CVE-2025-37811, CVE-2025-37844, CVE-2025-37859, CVE-2025-37862, CVE-2025-37865, CVE-2025-37874, CVE-2025-37884, CVE-2025-37909, CVE-2025-37917, CVE-2025-37921, CVE-2025-37923, CVE-2025-37927, CVE-2025-37933, CVE-2025-37936, CVE-2025-37938, CVE-2025-37945, CVE-2025-37946, CVE-2025-37961, CVE-2025-37967, CVE-2025-37968, CVE-2025-37973, CVE-2025-37987, CVE-2025-37992, CVE-2025-37994, CVE-2025-37995, CVE-2025-37997, CVE-2025-37998, CVE-2025-38000, CVE-2025-38001, CVE-2025-38003, CVE-2025-38004, CVE-2025-38005, CVE-2025-38007, CVE-2025-38009, CVE-2025-38010, CVE-2025-38011, CVE-2025-38013, CVE-2025-38014, CVE-2025-38015, CVE-2025-38018, CVE-2025-38020, CVE-2025-38022, CVE-2025-38023, CVE-2025-38024, CVE-2025-38027, CVE-2025-38031, CVE-2025-38040, CVE-2025-38043, CVE-2025-38044, CVE-2025-38045, CVE-2025-38053, CVE-2025-38057, CVE-2025-38059, CVE-2025-38060, CVE-2025-38065, CVE-2025-38068, CVE-2025-38072, CVE-2025-38077, CVE-2025-38078, CVE-2025-38079, CVE-2025-38080, CVE-2025-38081, CVE-2025-38083, CVE-2025-40909, CVE-2025-4373, CVE-2025-4598, CVE-2025-46802, CVE-2025-47268, CVE-2025-47273, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796, CVE-2025-6018, CVE-2025-6020, CVE-2025-6021, CVE-2025-6052, CVE-2025-6170, CVE-2025-6297, CVE-2025-6395, CVE-2025-6442, CVE-2025-7519 |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46608 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46608 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Corrección y productos afectados
| Product | Affected Versions | Remediated Versions | Link |
| Dell Data Lakehouse | Versions prior to 1.6.0.0 | Version 1.6.0.0 or later | Contact Technical Support and Quote DSA-2025-375 |
| Product | Affected Versions | Remediated Versions | Link |
| Dell Data Lakehouse | Versions prior to 1.6.0.0 | Version 1.6.0.0 or later | Contact Technical Support and Quote DSA-2025-375 |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2025-11-12 | Initial release |