SCSI Device Identification Flaw in sg3_utils by Red Hat
CVE-2026-16313
7.6HIGH
What is CVE-2026-16313?
A vulnerability exists in the sg3_utils package where the sg_inq command, when used with the --export option, exposes device identification data without properly sanitizing control characters within SCSI name string fields. This oversight can lead to the injection of a newline character within a device-supplied name, potentially allowing an attacker to manipulate the udev device database. If successfully executed, this flaw could enable an attacker with access to a specially crafted SCSI device to execute arbitrary commands with root privileges upon device disconnection.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Shaomin Chen as the original reporter.