Dell PowerScale OneFS TOCTOU Race Condition Vulnerability Allowing Denial-of-Service and Information Tampering

Vulnerability

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in Dell PowerScale OneFS versions 9.8.0.0 prior to 9.10.1.0. This vulnerability allows an unauthenticated attacker with local access to exploit the issue, potentially leading to a denial-of-service condition and unauthorized information tampering.

Impact

Exploitation of this vulnerability could result in a denial-of-service condition and unauthorized tampering with information.

Remediation

Users can upgrade to Dell PowerScale OneFS version 9.10.1.2 or later. Instructions for downloading the update are available in the PowerScale OneFS Downloads Area.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
3.1
exploitability
3.1
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.