DSA-2026-401: Security update for Dell ECS and ObjectScale Multiple Third Party Component Vulnerabilities
摘要: Dell ECS and ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
本文适用于
本文不适用于
本文并非针对某种特定的产品。
本文并非包含所有产品版本。
影响
Critical
详情
| Third-party Component | CVEs | More Information |
| BusyBox | CVE-2021-42374, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,;CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-28391, CVE-2022-48174, CVE-2025-46394, CVE-2025-60876 | https://nvd.nist.gov/vuln/search |
| Dell iDRAC | CVE-2024-25943, CVE-2025-22396, CVE-2026-26945,CVE-2026-26948 | https://nvd.nist.gov/vuln/search |
| EDK2 | CVE-2024-38796 | https://nvd.nist.gov/vuln/search |
| GLib | CVE-2024-52533 | https://nvd.nist.gov/vuln/search |
| GNU C Library (glibc) | CVE-2024-2961 | https://nvd.nist.gov/vuln/search |
| Intel Processor/Microcode | CVE-2025-31648 | https://nvd.nist.gov/vuln/search |
| Intel TDX Module | CVE-2025-22885, CVE-2025-27572,;CVE-2025-27940, CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467 | https://nvd.nist.gov/vuln/search |
| libexpat (Expat) | CVE-2023-52340, CVE-2023-6780, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602 | https://nvd.nist.gov/vuln/search |
| Linux Kernel | CVE-2024-42154 | https://nvd.nist.gov/vuln/search |
| Nuvoton NPCT7xx TPM | CVE-2026-6923 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2023-48795, CVE-2024-6387, CVE-2025-26466 | https://nvd.nist.gov/vuln/search |
| OpenSSL | CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 | https://nvd.nist.gov/vuln/search |
| REDownloader | CVE-2026-23855 | https://nvd.nist.gov/vuln/search |
| Sqlite3 | CVE-2025-29088 | https://nvd.nist.gov/vuln/search |
受影响的产品和补救措施
| Product | Affected Versions | Remediated Versions | Link |
| ECS | Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 | Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401 |
| ObjectScale | Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 | Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401 |
| Product | Affected Versions | Remediated Versions | Link |
| ECS | Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 | Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401 |
| ObjectScale | Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 | Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later | Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401 |
Note:
- Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request.
- Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.
修订历史记录
| Revision | Date | Description |
| 1.0 | 2026-09-03 | Initial Release |
相关信息
法律免责声明
受影响的产品
ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption
, ObjectScale Appliance Series, ObjectScale Software Series
...
文章属性
文章编号: 000509706
文章类型: Dell Security Advisory
上次修改时间: 16 9月 2026
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。