Dell PowerScale OneFS TOCTOU Race Condition Vulnerability Leading to Denial-of-Service

Vulnerability

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability has been identified in Dell PowerScale OneFS. This vulnerability affects versions 9.5.0.0 through 9.5.1.5, 9.6.0.0 through 9.7.1.10, 9.8.0.0 through 9.10.1.3, and versions starting from 9.11.0.0 and prior to 9.13.0.0. The vulnerability allows a low privileged attacker with adjacent network access to potentially cause a denial-of-service condition.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing disruptions in service availability.

Remediation

Users can upgrade to version 9.13.0.0 or later to address this vulnerability. For versions 9.5.0.0 through 9.5.1.5, users should upgrade to version 9.5.1.6 or later. For versions 9.6.0.0 through 9.7.1.10, the recommended upgrade is to version 9.7.1.11 or later. Users on versions 9.8.0.0 through 9.10.1.3 should upgrade to version 9.10.1.4 or later.

Added: Jan 22, 2026, 9:11 PM
Updated: Jan 22, 2026, 9:11 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
3.1
remediation
7.7
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.