PT-2026-65529 · Sg3 Utils+1 · Sg3 Utils+1
CVE-2026-16313
·
Published
2026-06-01
·
Updated
2026-08-31
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sg3 utils (affected versions not specified)
Description
A flaw exists in the
sg inq command when used with the --export option. The utility fails to sanitize control characters within SCSI name string fields. An attacker providing a specially crafted SCSI device containing a newline character in the name string can inject arbitrary properties into the udev device database. This injection can lead to the execution of arbitrary commands with root privileges when the device is disconnected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Sg3 Utils