SCSI Device Identification Flaw in sg3_utils by Red Hat
CVE-2026-16313

7.6HIGH

What is CVE-2026-16313?

A vulnerability exists in the sg3_utils package where the sg_inq command, when used with the --export option, exposes device identification data without properly sanitizing control characters within SCSI name string fields. This oversight can lead to the injection of a newline character within a device-supplied name, potentially allowing an attacker to manipulate the udev device database. If successfully executed, this flaw could enable an attacker with access to a specially crafted SCSI device to execute arbitrary commands with root privileges upon device disconnection.

Affected Version(s)

Red Hat Enterprise Linux 10 0:1.48-7.el10_2.1

Red Hat Enterprise Linux 8 0:1.44-6.el8_10.1

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:1.44-5.el8_4.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Shaomin Chen as the original reporter.
.