PT-2026-65529 · Sg3 Utils+1 · Sg3 Utils+1

CVE-2026-16313

·

Published

2026-06-01

·

Updated

2026-08-31

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sg3 utils (affected versions not specified)
Description A flaw exists in the sg inq command when used with the --export option. The utility fails to sanitize control characters within SCSI name string fields. An attacker providing a specially crafted SCSI device containing a newline character in the name string can inject arbitrary properties into the udev device database. This injection can lead to the execution of arbitrary commands with root privileges when the device is disconnected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:50141
ALSA-2026:50142
ALSA-2026:56130
AZL-94311
CVE-2026-16313
ECHO-5D3C-0210-C193
OESA-2026-3244
RHSA-2026:50141
RHSA-2026:50142
RHSA-2026:56130
RHSA-2026:59397
RHSA-2026:59555
RHSA-2026:59567
RHSA-2026:59568
RHSA-2026:61260
RHSA-2026:61261

Affected Products

Rocky Linux
Sg3 Utils