DSA-2026-401: Security update for Dell ECS and ObjectScale Multiple Third Party Component Vulnerabilities

Resumen: Dell ECS and ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

Critical

Detalles

Third-party Component CVEs More Information
BusyBox CVE-2021-42374, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,;CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-28391, CVE-2022-48174, CVE-2025-46394, CVE-2025-60876 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Dell iDRAC CVE-2024-25943, CVE-2025-22396, CVE-2026-26945,CVE-2026-26948 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
EDK2 CVE-2024-38796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GLib CVE-2024-52533 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GNU C Library (glibc) CVE-2024-2961 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel Processor/Microcode CVE-2025-31648 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel TDX Module CVE-2025-22885, CVE-2025-27572,;CVE-2025-27940, CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
libexpat (Expat) CVE-2023-52340, CVE-2023-6780, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Linux Kernel CVE-2024-42154 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Nuvoton NPCT7xx TPM CVE-2026-6923 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSH CVE-2023-48795, CVE-2024-6387, CVE-2025-26466  https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
REDownloader CVE-2026-23855 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Sqlite3 CVE-2025-29088 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401

Note: 

  1. Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request. 
  2. Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.

Historial de revisiones

RevisionDateDescription
1.0 2026-09-03Initial Release

Información relacionada

Productos afectados

ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption , ObjectScale Appliance Series, ObjectScale Software Series ...
Propiedades del artículo
Número del artículo: 000509706
Tipo de artículo: Dell Security Advisory
Última modificación: 16 sept 2026
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.