Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16313

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

Отчет

sg3_utils versions 1.34 through 1.48 contain a command injection flaw in the export_dev_ids() function of sg_inq. When sg_inq --export processes SCSI device identification data from VPD page 0x83, the SCSI name string designator (type 8) and the ATA vendor-ID subfield are printed without sanitizing embedded control characters. A crafted SCSI/USB device can embed a newline in this field, splitting sg_inq's udev KEY=VALUE output into two lines and injecting an arbitrary udev property, including REMOVE_CMD. On systems whose default udev rules invoke sg_inq --export for SCSI device identification and act on REMOVE_CMD when a device is removed, this allows a local attacker with physical access to a USB/SCSI port to achieve arbitrary command execution as root simply by disconnecting the crafted device. Exploitation requires physical access to attach the malicious device, consistent with Red Hat's Physical (AV:P) attack vector scoring. The upstream fix (udev-conforming character escaping for this field) has not yet been included in any tagged sg3_utils release; all Red Hat-shipped versions of sg3_utils in the 1.34-1.48 range are affected.

Меры по смягчению последствий

Remove or comment out the REMOVE_CMD rule from 50-udev-default.rules to prevent command execution on device removal. Alternatively, if automatic SCSI device identification is not required, disable the udev rule that invokes sg_inq --export on device connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sg3_utilsNot affected
Red Hat Enterprise Linux 7sg3_utilsAffected
Red Hat Enterprise Linux 8sg3_utilsAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10sg3_utilsFixedRHSA-2026:5014204.08.2026
Red Hat Enterprise Linux 9sg3_utilsFixedRHSA-2026:5014104.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2502845sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

EPSS

Процентиль: 16%
0.00247
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
nvd
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

msrc
4 дня назад

Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

CVSS3: 7.6
debian
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...

rocky
5 дней назад

Important: sg3_utils security, bug fix, and enhancement update

EPSS

Процентиль: 16%
0.00247
Низкий

7.6 High

CVSS3