DSA-2026-401: Security update for Dell ECS and ObjectScale Multiple Third Party Component Vulnerabilities

Podsumowanie: Dell ECS and ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Ten artykuł dotyczy Ten artykuł nie dotyczy Ten artykuł nie jest powiązany z żadnym konkretnym produktem. Nie wszystkie wersje produktu zostały zidentyfikowane w tym artykule.

Skutki

Critical

Szczegóły

Third-party Component CVEs More Information
BusyBox CVE-2021-42374, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,;CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-28391, CVE-2022-48174, CVE-2025-46394, CVE-2025-60876 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Dell iDRAC CVE-2024-25943, CVE-2025-22396, CVE-2026-26945,CVE-2026-26948 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
EDK2 CVE-2024-38796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GLib CVE-2024-52533 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GNU C Library (glibc) CVE-2024-2961 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel Processor/Microcode CVE-2025-31648 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel TDX Module CVE-2025-22885, CVE-2025-27572,;CVE-2025-27940, CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
libexpat (Expat) CVE-2023-52340, CVE-2023-6780, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Linux Kernel CVE-2024-42154 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Nuvoton NPCT7xx TPM CVE-2026-6923 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSH CVE-2023-48795, CVE-2024-6387, CVE-2025-26466  https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
REDownloader CVE-2026-23855 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Sqlite3 CVE-2025-29088 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Firma Dell Technologies zaleca wszystkim klientom uwzględnienie zarówno wyniku podstawowego CVSS, jak i wszelkich istotnych wyników czasowych i środowiskowych, które mogą mieć wpływ na potencjalną dotkliwość związaną z konkretną luką w zabezpieczeniach.

Produkty, których dotyczy problem, i środki zaradcze

Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401

Note: 

  1. Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request. 
  2. Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.

Historia zmian

RevisionDateDescription
1.0 2026-09-03Initial Release

Powiązane informacje

Produkty, których dotyczy problem

ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption , ObjectScale Appliance Series, ObjectScale Software Series ...
Właściwości artykułu
Numer artykułu: 000509706
Typ artykułu: Dell Security Advisory
Ostatnia modyfikacja: 16 wrz 2026
Znajdź odpowiedzi na swoje pytania u innych użytkowników produktów Dell
Usługi pomocy technicznej
Sprawdź, czy Twoje urządzenie jest objęte usługą pomocy technicznej.