Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:50142

Опубликовано: 06 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: sg3_utils security, bug fix, and enhancement update

The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.

Security Fix(es):

  • sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313)

Bug Fix(es) and Enhancement(s):

  • sg_inq output conformance for SCSI name string and ATA fields [rhel-10.2.z] (JIRA:Rocky Linux-188123)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
sg3_utils-libsaarch647.el10_2.1sg3_utils-libs-1.48-7.el10_2.1.aarch64.rpm
sg3_utilsaarch647.el10_2.1sg3_utils-1.48-7.el10_2.1.aarch64.rpm
sg3_utils-libsx86_647.el10_2.1sg3_utils-libs-1.48-7.el10_2.1.x86_64.rpm
sg3_utilsx86_647.el10_2.1sg3_utils-1.48-7.el10_2.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.6
ubuntu
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
redhat
2 месяца назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
nvd
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

msrc
4 дня назад

Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

CVSS3: 7.6
debian
14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...