PT-2026-3777 · Dell · Dell Powerscale Onefs

Published

2026-01-15

·

Updated

2026-01-23

·

CVE-2026-22281

CVSS v3.1

4.8

Medium

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.5 Dell PowerScale OneFS versions 9.6.0.0 through 9.7.1.10 Dell PowerScale OneFS versions 9.8.0.0 through 9.10.1.3 Dell PowerScale OneFS versions prior to 9.13.0.0
Description Dell PowerScale OneFS contains a Time-of-check Time-of-use (TOCTOU) race condition. An attacker with adjacent network access and low privileges could potentially exploit this issue, resulting in a denial of service. The vulnerability is related to synchronization errors when using a shared resource.
Recommendations Update Dell PowerScale OneFS versions 9.5.x to a version later than 9.5.1.5. Update Dell PowerScale OneFS versions 9.6.x and 9.7.x to a version later than 9.7.1.10. Update Dell PowerScale OneFS versions 9.8.x and 9.10.x to a version later than 9.10.1.3. Update Dell PowerScale OneFS versions 9.11.x and 9.12.x to version 9.13.0.0 or later.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2026-00646
CVE-2026-22281

Affected Products

Dell Powerscale Onefs