Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000207171


DSA-2022-328: Dell Container Storage Modules Security Update for a Denial of Service Vulnerability

Summary: Dell Container Storage Modules remediation is available for a golang.org/x/net vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Third-party Component CVEs More information
net/http in Go CVE-2022-27664 https://nvd.nist.gov/vuln/detail/CVE-2022-27664
Third-party Component CVEs More information
net/http in Go CVE-2022-27664 https://nvd.nist.gov/vuln/detail/CVE-2022-27664
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed  Product Affected Versions Updated Versions Link to Update
CVE-2022-27664 Dell Container Storage Modules 1.4 and prior 1.5 https://github.com/dell/csm
CVEs Addressed  Product Affected Versions Updated Versions Link to Update
CVE-2022-27664 Dell Container Storage Modules 1.4 and prior 1.5 https://github.com/dell/csm

Workarounds and Mitigations

  1. Update Go version to 1.19 in go.mod file.
  2. Update golang.org/x/net, golang.org/x/sys, and golang.org/x/text to the latest version. For example:
go get -u golang.org/x/net, go get -u golang.org/x/text
  1. Then
go mod tidy

Revision History

RevisionDateDescription
1.02023-01-04Initial Release

Related Information


Article Properties


Product

Product Security Information

Last Published Date

04 Jan 2023

Article Type

Dell Security Advisory