Описание
ELSA-2026-50142-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)
[1.48-7.1]
- sg_inq output conformance for SCSI name string and ATA fields (RHEL-188123)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
sg3_utils
1.48-7.el10_2.1
sg3_utils-devel
1.48-7.el10_2.1
sg3_utils-libs
1.48-7.el10_2.1
Oracle Linux x86_64
sg3_utils
1.48-7.el10_2.1
sg3_utils-devel
1.48-7.el10_2.1
sg3_utils-libs
1.48-7.el10_2.1
Связанные CVE
Связанные уязвимости
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...