Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (network-facing management service): OMSA is the in-band hardware management agent
Impact
OMSA is the in-band hardware management agent operators install on PowerEdge compute nodes - including GPU nodes - to read sensor, storage and firmware state. Dell states that the use of a broken or risky cryptographic algorithm lets an attacker with remote network access and no credentials obtain information from the service. On a fleet where OMSA listens on a management or provisioning network, that is inventory and hardware-state disclosure across every node running the affected agent, and potentially material useful for a follow-on attack on the management plane. The advisory does not describe which data is exposed, so treat the scope as unspecified confidentiality loss rather than a known credential leak.
Who can reach it
Anyone who can reach the OMSA service over the network on an affected node. No authentication required (CVSS AV:N/PR:N).
What to do
Upgrade OMSA Managed Node to 11.1.0.3 or later per DSA-2026-403 (packages exist for RHEL 8.10/9.4, SLES 15, Ubuntu 22.04 and Windows); the agent services restart as part of the package upgrade, so no node reboot is called for in the advisory. Until then, restrict the OMSA listener to the management VLAN or stop the service on nodes that do not need it.
References
Related entries
- Linux kernel nfsd: uncapped POSIX ACL entry count drives an O(n^2) sort in the NFS serverCVE-2026-89695 · Linux kernel nfsd (NFSv4 POSIX ACL decoder, sort_pacl_range)High
- Linux kernel nfsd: crafted inter-server COPY compound reaches ops with a NULL filehandle and panics nfsdCVE-2026-89696 · Linux kernel nfsd (inter-server COPY, NFSD4_FH_FOREIGN compound dispatch)High
- Linux kernel nfsd: unbounded symlink target length lets a client force multi-MiB kmallocs per COMPOUND opCVE-2026-89699 · Linux kernel nfsd (NFSv4 CREATE symlink decoder, cr_datalen)High
- Linux kernel nfsd: async COPY samples the writeback error cursor late and reports failed copies as durableCVE-2026-89704 · Linux kernel nfsd (async server-side COPY, writeback error cursor in _nfsd_copy_file_range)High
- Linux kernel nfsd: write verifier not rotated when async COPY writeback fails, so COMMIT confirms lost dataCVE-2026-89706 · Linux kernel nfsd (async COPY write verifier rotation, nn->writeverf)High
- Linux kernel nfsd: failed cross-mount leaks mount and dentry references on the NFS serverCVE-2026-89707 · Linux kernel nfsd (nfsd_cross_mnt, follow_down() error path refcount leak)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.