Skip to content
Red HatCVE-2026-16313

Red Hat sg3_utils. The sg_inq command: code execution

High7.6CVE-2026-16313 · Published Jul 28, 2026 · updated Sep 24, 2026

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat CRIU: code injection
High7.8Jul 28
A flaw was found in openshift/oauth-proxy
High8.5Jul 28
Red Hat Dogtag PKI: denial of service
Medium6.5Jul 28
Red Hat GStreamer: out-of-bounds read
Low3.3Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-fits plugin: integer overflow
High7.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.