GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of service

CVSS 5.5CVE-2026-81479Firmware, BMC & network fabriccurated

Impact

A separate defect in the same OMSA release train: a partial string comparison that a low-privileged local account can abuse to make the hardware management agent unavailable. Reported as availability-only, with no disclosure, no tampering and no privilege gain. The operator consequence on a GPU host is the same as the companion issue - loss of in-band chassis, PSU, thermal and RAID telemetry for that node - but the mechanism and the preconditions differ, so it is tracked on its own.

Who can reach it

Local, authenticated as any low-privileged user on the node running the OMSA managed-node service. No network reachability required (AV:L, PR:L).

What to do

Upgrade the OMSA managed-node package to 11.1.0.3 or later per Dell DSA-2026-403 - the same release that addresses the companion OMSA issue, so patch both in one pass. Package update plus an OMSA service restart; the advisory does not call for a firmware flash or a host reboot.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.