Описание
ELSA-2026-50141-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)
[1.47-10.1]
- sg_inq output conformance for SCSI name string and ATA fields (RHEL-188130)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
sg3_utils
1.47-10.el9_8.1
sg3_utils-devel
1.47-10.el9_8.1
sg3_utils-libs
1.47-10.el9_8.1
Oracle Linux x86_64
sg3_utils
1.47-10.el9_8.1
sg3_utils-devel
1.47-10.el9_8.1
sg3_utils-libs
1.47-10.el9_8.1
Связанные CVE
Связанные уязвимости
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...