Dsa 2025 435 Security Update For Dell Powerflex Rack Multiple Third Party Component Vulnerabilities
Third-party Component CVEs More Information Dell PowerEdge Server BIOS CVE-2024-31068, CVE-2024-28047, CVE-2024-39279, CVE-2024-36293, CVE-2024-28956, CVE-2024-45332, CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, CVE-2024-36357, CVE-2024-36350, CVE-2024-36348, CVE-2024-33607, CVE-2025-20109, CVE-2025-20044, CVE-2024-56161, CVE-2024-25571, CVE-2024-37020, CVE-2024-21859, CVE-2024-31155 DSA-2024-381 , DSA-2025-041 , DSA-2025-156 , DSA-2025-181 , DSA-2025-324 , DSA-2025-156 , DSA-2025-040 , DSA-2025-042 , iDRAC CVE-2025-26482, CVE-2025-22397, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602, CVE-2024-2961, CVE-2024-52533, CVE-2023-6780, CVE-2025-26466, CVE-2026-26945 DSA-2025-046 , DSA-2025-146 , DSA-2025-145 , DSA-2026-113 Cisco Switches CVE-2025-20191, CVE-2025-20161, CVE-2025-20111 VMware CVE-2025-41225, CVE-2025-41226, CVE-2025-41227, CVE-2025-41228, CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239, CVE-2025-41241, CVE-2025-41250 VMSA-2025-0010 , VMSA-2025-0013 , VMSA-2025-0014 , VMSA-2025-0016 Sudo CVE-2025-32463 Numpy CVE-2021-41495 OpenJDK CVE-2025-21502 OpenSSH CVE-2023-48795 Go CVE-2024-24790 PostgreSQL CVE-2024-0985, CVE-2023-5869 Redis CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819 IntelAdapters CVE-2024-24852, CVE-2024-36274 DSA-2025-042 bundler CVE-2020-36327 cryptography CVE-2023-50782 Docker CVE-2024-41110 GoFiber CVE-2024-38513 GoGo Protobuf CVE-2021-3121 pgproto3, pgx CVE-2024-27304 glibc CVE-2024-2961, CVE-2024-33599, CVE-2024-33600 golang.org/x/crypto CVE-2022-27191 java-17-openjdk CVE-2024-20918, CVE-2024-20932, CVE-2024-20952, CVE-2024-21147 keycloak-core CVE-2024-10039, CVE-2023-6841 keycloak-quarkus-server CVE-2024-10451 keycloak-saml-core CVE-2024-8698 keycloak-services CVE-2024-3656, CVE-2024-7341, CVE-2024-4540, CVE-2024-1132, CVE-2024-1249, CVE-2023-6291, CVE-2024-2419, CVE-2024-10270 krb5 CVE-2024-26458, CVE-2024-26461, CVE-2024-26462, CVE-2024-37370 libxml2-2 CVE-2024-56171 nokogiri CVE-2025-24855, CVE-2024-55549 postgresql15 CVE-2025-1094 rexml CVE-2021-28965, CVE-2024-43398 go-grpc-compression CVE-2024-36129 stdlib CVE-2022-30632, CVE-2023-45288, CVE-2024-24791, CVE-2024-34156 Keycloak CVE-2025-7962, CVE-2025-49574, CVE-2025-55163, CVE-2025-58057, CVE-2025-48924, CVE-2025-9162, CVE-2025-8419, CVE-2025-7784, CVE-2025-7365, CVE-2025-50106, CVE-2025-30749 SQLite CVE-2023-7104 Python CVE-2024-35195, CVE-2022-40899, CVE-2024-6345 CPython CVE-2024-7592, CVE-2024-6232, CVE-2024-3219, CVE-2024-6923 urllib3 CVE-2024-37891 Python-Requests CVE-2023-32681 XZ Utils CVE-2024-47611, CVE-2020-22916
In the case of manual upgrade for PowerFlex rack, please see this link:
Revision Date Description 1.0 2025-11-13 Initial Release 2.0 2025-11-17 Updated CVE Identifier, Third Party Components: Added CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819 3.0 2025-11-24 Updated CVE Identifier, Third Party Components: Added CVE-2024-24852, CVE-2024-36274 4.0 2025-11-26 Added details for CVE-2025-41250 5.0 2025-12-11 Update addressed 40 CVEs in Third Party Components 6.0 2026-01-20 Updated CVE Identifier, Third Party Components: Added Keycloak 11 CVEs 7.0 2026-03-18 Added details for CVE-2026-26945 8.0 2026-04-24 formating data to link some CVEs to their OSS Library
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
