Red HatCVE-2026-16313
Red Hat sg3_utils. The sg_inq command: code execution
High7.6CVE-2026-16313 · Published Jul 28, 2026 · updated Sep 24, 2026
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-93
- www.cve.org/CVERecord?id=CVE-2026-16313
- nvd.nist.gov/vuln/detail/CVE-2026-16313
- access.redhat.com/errata/RHSA-2026:50141
- access.redhat.com/errata/RHSA-2026:50142
- access.redhat.com/errata/RHSA-2026:54769
- access.redhat.com/errata/RHSA-2026:56130
- access.redhat.com/errata/RHSA-2026:59397
- access.redhat.com/errata/RHSA-2026:59555
- access.redhat.com/errata/RHSA-2026:59567
- access.redhat.com/errata/RHSA-2026:59568
- access.redhat.com/errata/RHSA-2026:61260
- access.redhat.com/errata/RHSA-2026:61261
- access.redhat.com/errata/RHSA-2026:63041
- access.redhat.com/errata/RHSA-2026:63044
- access.redhat.com/errata/RHSA-2026:63100
- access.redhat.com/errata/RHSA-2026:65851
- access.redhat.com/errata/RHSA-2026:65907
- access.redhat.com/errata/RHSA-2026:67157
- access.redhat.com/errata/RHSA-2026:67935
- access.redhat.com/errata/RHSA-2026:69124
- access.redhat.com/security/cve/CVE-2026-16313
- bugzilla.redhat.com/show_bug.cgi?id=2502845
- github.com/doug-gilbert/sg3_utils/pull/83
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 28 | Red Hat CRIU: code injection | High7.8 | No fix yet |
| Jul 28 | A flaw was found in openshift/oauth-proxy | High8.5 | No fix yet |
| Jul 28 | Red Hat Dogtag PKI: denial of service | Medium6.5 | No fix yet |
| Jul 28 | Red Hat GStreamer: out-of-bounds read | Low3.3 | No fix yet |
| Jul 27 | Red Hat file-sgi plugin: integer overflow | Medium5.5 | No fix yet |
| Jul 27 | Red Hat file-fits plugin: integer overflow | High7.8 | No fix yet |