A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 1, 2026 |
| Redhat_linux | — | Upgrade sg3_utils-debuginfoUpgrade sg3_utils-develUpgrade sg3_utils-libsUpgrade sg3_utilsUpgrade sg3_utils-libs-debuginfoUpgrade sg3_utils-debugsource | Jul 30, 2026 | Jun 1, 2026 |
| Rocky_linux | — | Upgrade sg3_utils-libsUpgrade sg3_utils-libs-debuginfoUpgrade sg3_utils-develUpgrade sg3_utils-debugsourceUpgrade sg3_utilsUpgrade sg3_utils-debuginfo | Aug 7, 2026 | Aug 6, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub