Количество 10
Количество 10
CVE-2026-16313
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
CVE-2026-16313
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
CVE-2026-16313
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
CVE-2026-16313
Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
CVE-2026-16313
A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...
RLSA-2026:50142
Important: sg3_utils security, bug fix, and enhancement update
RLSA-2026:50141
Important: sg3_utils security, bug fix, and enhancement update
GHSA-wqmp-fw94-rpg4
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
ELSA-2026-50142-0
ELSA-2026-50142-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-50141-0
ELSA-2026-50141-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-16313 A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. | CVSS3: 7.6 | 0% Низкий | 14 дней назад | |
CVE-2026-16313 A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. | CVSS3: 7.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-16313 A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. | CVSS3: 7.6 | 0% Низкий | 14 дней назад | |
CVE-2026-16313 Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export | 0% Низкий | 4 дня назад | ||
CVE-2026-16313 A flaw was found in sg3_utils. The sg_inq command, when invoked with t ... | CVSS3: 7.6 | 0% Низкий | 14 дней назад | |
RLSA-2026:50142 Important: sg3_utils security, bug fix, and enhancement update | 0% Низкий | 5 дней назад | ||
RLSA-2026:50141 Important: sg3_utils security, bug fix, and enhancement update | 0% Низкий | 5 дней назад | ||
GHSA-wqmp-fw94-rpg4 A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. | CVSS3: 7.6 | 0% Низкий | 13 дней назад | |
ELSA-2026-50142-0 ELSA-2026-50142-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT) | 0% Низкий | 7 дней назад | ||
ELSA-2026-50141-0 ELSA-2026-50141-0: sg3_utils security, bug fix, and enhancement update (IMPORTANT) | 0% Низкий | 7 дней назад |
Уязвимостей на страницу