Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-16313

14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-16313

2 месяца назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-16313

14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2026-16313

4 дня назад

Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

EPSS: Низкий
debian логотип

CVE-2026-16313

14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2026:50142

5 дней назад

Important: sg3_utils security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:50141

5 дней назад

Important: sg3_utils security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-wqmp-fw94-rpg4

14 дней назад

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
EPSS: Низкий
oracle-oval логотип

ELSA-2026-50142-0

7 дней назад

ELSA-2026-50142-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-50141-0

7 дней назад

ELSA-2026-50141-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
0%
Низкий
14 дней назад
redhat логотип
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
0%
Низкий
14 дней назад
msrc логотип
CVE-2026-16313

Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

0%
Низкий
4 дня назад
debian логотип
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...

CVSS3: 7.6
0%
Низкий
14 дней назад
rocky логотип
RLSA-2026:50142

Important: sg3_utils security, bug fix, and enhancement update

0%
Низкий
5 дней назад
rocky логотип
RLSA-2026:50141

Important: sg3_utils security, bug fix, and enhancement update

0%
Низкий
5 дней назад
github логотип
GHSA-wqmp-fw94-rpg4

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

CVSS3: 7.6
0%
Низкий
14 дней назад
oracle-oval логотип
ELSA-2026-50142-0

ELSA-2026-50142-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)

0%
Низкий
7 дней назад
oracle-oval логотип
ELSA-2026-50141-0

ELSA-2026-50141-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)

0%
Низкий
7 дней назад

Уязвимостей на страницу