DSA-2026-401: Security update for Dell ECS and ObjectScale Multiple Third Party Component Vulnerabilities

摘要: Dell ECS and ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

影响

Critical

详情

Third-party Component CVEs More Information
BusyBox CVE-2021-42374, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,;CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-28391, CVE-2022-48174, CVE-2025-46394, CVE-2025-60876 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Dell iDRAC CVE-2024-25943, CVE-2025-22396, CVE-2026-26945,CVE-2026-26948 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
EDK2 CVE-2024-38796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GLib CVE-2024-52533 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GNU C Library (glibc) CVE-2024-2961 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel Processor/Microcode CVE-2025-31648 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel TDX Module CVE-2025-22885, CVE-2025-27572,;CVE-2025-27940, CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
libexpat (Expat) CVE-2023-52340, CVE-2023-6780, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Linux Kernel CVE-2024-42154 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Nuvoton NPCT7xx TPM CVE-2026-6923 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSH CVE-2023-48795, CVE-2024-6387, CVE-2025-26466  https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
REDownloader CVE-2026-23855 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Sqlite3 CVE-2025-29088 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401

Note: 

  1. Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request. 
  2. Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.

修订历史记录

RevisionDateDescription
1.0 2026-09-03Initial Release

相关信息

受影响的产品

ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption , ObjectScale Appliance Series, ObjectScale Software Series ...
文章属性
文章编号: 000509706
文章类型: Dell Security Advisory
上次修改时间: 16 9月 2026
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。