Red Hat Security Advisory: sg3_utils security update
The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): * sg_inq output conformance for SCSI name string and ATA fields [rhel-10.2.z] (JIRA:RHEL-188123) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
The sg3_utils package contains a flaw in the sg_inq command when used with the --export option. It fails to sanitize control characters in SCSI device name strings, specifically allowing newline characters to inject properties into the udev device database. This vulnerability (CVE-2026-16313) could be exploited by an attacker who can present a malicious SCSI device, enabling arbitrary command execution with root privileges when the device is disconnected. The CVSS 3.1 vector indicates a high severity with partial attack vector (physical), low attack complexity, no privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with physical access to present a crafted SCSI device that can inject malicious properties into the udev device database, leading to arbitrary command execution as root when the device is disconnected. This compromises system confidentiality, integrity, and availability at a high level.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The Red Hat advisory linked does not explicitly mention a fix or workaround. Until a patch or official fix is available, restrict physical access to systems and avoid connecting untrusted SCSI devices. Monitor vendor channels for updates.
Red Hat Security Advisory: sg3_utils security update
Description
The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): * sg_inq output conformance for SCSI name string and ATA fields [rhel-10.2.z] (JIRA:RHEL-188123) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sg3_utils package contains a flaw in the sg_inq command when used with the --export option. It fails to sanitize control characters in SCSI device name strings, specifically allowing newline characters to inject properties into the udev device database. This vulnerability (CVE-2026-16313) could be exploited by an attacker who can present a malicious SCSI device, enabling arbitrary command execution with root privileges when the device is disconnected. The CVSS 3.1 vector indicates a high severity with partial attack vector (physical), low attack complexity, no privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with physical access to present a crafted SCSI device that can inject malicious properties into the udev device database, leading to arbitrary command execution as root when the device is disconnected. This compromises system confidentiality, integrity, and availability at a high level.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The Red Hat advisory linked does not explicitly mention a fix or workaround. Until a patch or official fix is available, restrict physical access to systems and avoid connecting untrusted SCSI devices. Monitor vendor channels for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wqmp-fw94-rpg4
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-16313"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6941da9c2644c7f86bd69b
Added to database: 07/28/2026, 23:57:14 UTC
Last enriched: 07/29/2026, 11:25:40 UTC
Last updated: 09/11/2026, 22:08:24 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.