CVE-2026-16313
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
A flaw was found in sg3_utils. The sg_inq command, when invoked with the –export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.48-7.el10_2.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.44-6.el8_10.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.44-5.el8_4.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:1.44-5.el8_4.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.44-5.el8_6.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:1.44-5.el8_6.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.44-6.el8_8.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.44-6.el8_8.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.47-10.el9_8.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.47-9.el9_2.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.47-9.el9_4.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.47-10.el9_6.2 < * | unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202609021231-0 < * | unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202609021029-0 < * | unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202609021100-0 < * | unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202608130832-0 < * | unaffected |
Weaknesses
- CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
Workarounds
Remove or comment out the REMOVE_CMD rule from 50-udev-default.rules to prevent command execution on device removal. Alternatively, if automatic SCSI device identification is not required, disable the udev rule that invokes sg_inq –export on device connection.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2026:50141
- https://access.redhat.com/errata/RHSA-2026:50142
- https://access.redhat.com/errata/RHSA-2026:54769
- https://access.redhat.com/errata/RHSA-2026:56130
- https://access.redhat.com/errata/RHSA-2026:59397
- https://access.redhat.com/errata/RHSA-2026:59555
- https://access.redhat.com/errata/RHSA-2026:59567
- https://access.redhat.com/errata/RHSA-2026:59568
- https://access.redhat.com/errata/RHSA-2026:61260
- https://access.redhat.com/errata/RHSA-2026:61261
- https://access.redhat.com/errata/RHSA-2026:63041
- https://access.redhat.com/errata/RHSA-2026:63044
- https://access.redhat.com/errata/RHSA-2026:63100
- https://access.redhat.com/security/cve/CVE-2026-16313
- https://bugzilla.redhat.com/show_bug.cgi?id=2502845
- https://github.com/doug-gilbert/sg3_utils/pull/83
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.