DSA-2026-274: Security Update for Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software Multiple Third-Party Component Vulnerabilities

Podsumowanie: Dell APEX Cloud Platform for Microsoft Azure remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...

Ten artykuł dotyczy Ten artykuł nie dotyczy Ten artykuł nie jest powiązany z żadnym konkretnym produktem. Nie wszystkie wersje produktu zostały zidentyfikowane w tym artykule.

Skutki

Critical

Szczegóły

Third-party Component CVEs More Information
Linux Kernel CVE-2026-1642, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2025-45582, CVE-2026-2007, CVE-2026-2004, CVE-2026-2003, CVE-2026-2006, CVE-2026-2005, CVE-2025-6075, CVE-2025-13836, CVE-2025-13837, CVE-2025-12084, CVE-2025-11468, CVE-2026-0672, CVE-2026-0865, CVE-2025-15282, CVE-2026-1299, CVE-2026-2297, CVE-2025-13462, CVE-2026-3644, CVE-2026-4224, CVE-2026-3479, CVE-2026-4519, CVE-2025-67726, CVE-2025-67725, CVE-2025-67724, CVE-2026-23555, CVE-2026-23554, CVE-2025-12801, CVE-2026-25075, CVE-2026-35385, CVE-2026-35414, CVE-2026-23865, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-34282, CVE-2026-31431, CVE-2025-53906, CVE-2026-26269, CVE-2026-28417, CVE-2026-28390, CVE-2026-1467, CVE-2026-1539, CVE-2026-1760, CVE-2026-1965, CVE-2026-4873, CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-21637, CVE-2026-21715, CVE-2026-21717, CVE-2026-21716, CVE-2026-21714, CVE-2026-21710, CVE-2026-21713, CVE-2024-36137, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638, CVE-2024-38542, CVE-2025-37861, CVE-2025-39817, CVE-2025-39964, CVE-2025-40099, CVE-2025-40103, CVE-2023-53817, CVE-2025-40253, CVE-2025-71066, CVE-2025-71113, CVE-2026-23004, CVE-2026-23054, CVE-2026-23060, CVE-2026-23074, CVE-2026-23089, CVE-2026-23111, CVE-2026-23202, CVE-2026-23204, CVE-2026-23157, CVE-2026-23141, CVE-2026-23191, CVE-2025-71231, CVE-2026-23214, CVE-2026-23209, CVE-2026-23207, CVE-2026-23268, CVE-2026-23269, CVE-2026-1519, CVE-2026-4437, CVE-2026-4438, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789, CVE-2026-43500, CVE-2026-2291, CVE-2026-6507, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172, CVE-2026-33412, CVE-2026-34982, CVE-2026-34714, CVE-2026-2781, CVE-2026-31790, CVE-2026-35535, CVE-2025-66614, CVE-2026-24733, CVE-2026-24734, CVE-2026-24880, CVE-2026-25854, CVE-2026-29129, CVE-2026-29145, CVE-2026-29146, CVE-2026-34486, CVE-2026-34483, CVE-2026-34487, CVE-2026-34500, CVE-2026-32990, CVE-2025-39998, CVE-2026-23103, CVE-2026-23231, CVE-2026-31788, CVE-2026-23243, CVE-2026-23278, CVE-2026-23274, CVE-2026-23272, CVE-2026-23381, CVE-2026-23293, CVE-2026-23317, CVE-2026-23398, CVE-2026-23412, CVE-2026-23413, CVE-2026-3446, CVE-2026-1502, CVE-2026-4786, CVE-2026-6019, CVE-2026-6100, CVE-2026-33416, CVE-2026-33636, CVE-2026-33554, CVE-2026-27135, CVE-2026-40706, CVE-2025-54518, CVE-2026-46300, CVE-2026-46333, CVE-2026-32777, CVE-2026-32776, CVE-2026-32778, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805, CVE-2026-21620, CVE-2026-23942, CVE-2026-23943, CVE-2026-23941, CVE-2026-28808, CVE-2026-4775, CVE-2026-29111, CVE-2026-4105, CVE-2026-30922, CVE-2026-34990, CVE-2026-4878 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Security Update for NVIDIA Bluefield and ConnectX Vulnerabilities CVE-2025-23262, CVE-2025-23299 DSA-2026-119 , DSA-2026-121
FreeRDP CVE-2026-26950 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
HTTP CVE-2025-13836 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Security Update for Dell PowerEdge Server for an OpenSSL Vulnerability CVE-2026-22796 DSA-2026-136
UEFI Reference Firmware Advisory CVE-2025-35991 DSA-2026-027
NVIDIA ConnectX and BlueField CVE-2025-23350, CVE-2025-23351 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

 

Firma Dell Technologies zaleca wszystkim klientom uwzględnienie zarówno wyniku podstawowego CVSS, jak i wszelkich istotnych wyników czasowych i środowiskowych, które mogą mieć wpływ na potencjalną dotkliwość związaną z konkretną luką w zabezpieczeniach.

Produkty, których dotyczy problem, i środki zaradcze

Product Affected Versions Remediated Versions Link
Dell APEX Cloud Platform for Microsoft Azure Versions prior to 01.07.02.00 Version 01.07.02.00 or later https://www.dell.com/support/home/product-support/product/apex-cloud-pf-ms-azure/drivers

 

Product Affected Versions Remediated Versions Link
Dell APEX Cloud Platform for Microsoft Azure Versions prior to 01.07.02.00 Version 01.07.02.00 or later https://www.dell.com/support/home/product-support/product/apex-cloud-pf-ms-azure/drivers

 

Obejścia problemu i środki zaradcze

CVE ID Workaround and Mitigation

CVE-2026-31431

For customers who need to mitigate the vulnerability before upgrading to ACP Azure 01.07.02.00, Dell recommends blacklisting the algif_aead kernel module.

Steps to Apply the Workaround:

  1. SSH into the ACP Manager as root.
  2. Run the following commands to blacklist the module and unload it if currently loaded:

echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf

rmmod algif_aead 2>/dev/null

  1. Verify the workaround is in effect:

modprobe algif_aead

           This command should fail (module load denied).

lsmod | grep algif_aead

           This should return empty (module not loaded).

Post-Upgrade Cleanup:

After upgrading to ACP Azure 01.07.02.00 or later, Dell strongly recommends removing the blacklist configuration to ensure compatibility with potential future enhancements:

rm -f /etc/modprobe.d/disable-algif-aead.conf

 

Note: On fresh deployments, the file
 /etc/modprobe.d/disable-algif-aead.conf may not exist initially. This is expected—the file is created as part of Step 2.

 

Historia zmian

RevisionDateDescription
1.02026-06-16Initial Release
2.02026-06-22Adding the remediated vulnerabilities for the released version 01.07.02.00

 

Powiązane informacje

Produkty, których dotyczy problem

APEX, APEX Cloud Platforms Solution Offerings, APEX Cloud Platform for Microsoft Azure
Właściwości artykułu
Numer artykułu: 000477945
Typ artykułu: Dell Security Advisory
Ostatnia modyfikacja: 09 lip 2026
Znajdź odpowiedzi na swoje pytania u innych użytkowników produktów Dell
Usługi pomocy technicznej
Sprawdź, czy Twoje urządzenie jest objęte usługą pomocy technicznej.