SCSI Device Identification Flaw in sg3_utils by Red Hat
CVE-2026-16313

7.6HIGH

What is CVE-2026-16313?

A vulnerability exists in the sg3_utils package where the sg_inq command, when used with the --export option, exposes device identification data without properly sanitizing control characters within SCSI name string fields. This oversight can lead to the injection of a newline character within a device-supplied name, potentially allowing an attacker to manipulate the udev device database. If successfully executed, this flaw could enable an attacker with access to a specially crafted SCSI device to execute arbitrary commands with root privileges upon device disconnection.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Shaomin Chen as the original reporter.
.