SCSI Device Identification Flaw in sg3_utils by Red Hat
CVE-2026-16313
Key Information:
What is CVE-2026-16313?
A vulnerability exists in the sg3_utils package where the sg_inq command, when used with the --export option, exposes device identification data without properly sanitizing control characters within SCSI name string fields. This oversight can lead to the injection of a newline character within a device-supplied name, potentially allowing an attacker to manipulate the udev device database. If successfully executed, this flaw could enable an attacker with access to a specially crafted SCSI device to execute arbitrary commands with root privileges upon device disconnection.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.48-7.el10_2.1
Red Hat Enterprise Linux 8 0:1.44-6.el8_10.1
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:1.44-5.el8_4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved