#1143004 sg3-utils: CVE-2026-16313

Package:
src:sg3-utils
Source:
src:sg3-utils
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 09:51:03 UTC
Severity:
normal
Tags:
#1143004#5
Date:
2026-07-29 13:32:12 UTC
From:
To:
Hi,

The following vulnerability was published for sg3-utils.

CVE-2026-16313[0]:
| A flaw was found in sg3_utils. The sg_inq command, when invoked with
| the --export option, outputs device identification data without
| sanitizing control characters in SCSI name string fields. A newline
| character embedded in a device-supplied name string can inject
| arbitrary properties into the udev device database. This could allow
| an attacker who can present a crafted SCSI device to execute
| arbitrary commands as root when the device is disconnected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16313
https://www.cve.org/CVERecord?id=CVE-2026-16313
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2502845
[2] https://github.com/doug-gilbert/sg3_utils/pull/83

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143004#12
Date:
2026-10-08 09:49:19 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
sg3-utils, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143004@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ritesh Raj Sarraf <rrs@debian.org> (supplier of updated sg3-utils package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 08 Oct 2026 14:08:53 +0530
Source: sg3-utils
Architecture: source
Version: 1.48-4
Distribution: unstable
Urgency: high
Maintainer: Ritesh Raj Sarraf <rrs@debian.org>
Changed-By: Ritesh Raj Sarraf <rrs@debian.org>
Closes: 1143004
Changes:
 sg3-utils (1.48-4) unstable; urgency=high
 .
   * Sanitize control characters in sg_inq --export SCSI name string and ATA
     identifier fields (CVE-2026-16313, Closes: #1143004)
Checksums-Sha1:
 63d894d18d9e93420f6e13edc12145a0230c9899 2219 sg3-utils_1.48-4.dsc
 191640e21899a33fa8a5797e25a683f19b57c9dc 16092 sg3-utils_1.48-4.debian.tar.xz
Checksums-Sha256:
 0d4d4d0dae42c9001359f13e11f0e2fcd6ab16dc0cd246f35ac5623064498927 2219 sg3-utils_1.48-4.dsc
 d267027645ce2aa70d84f6ab5dfb8cb66cbf7513434f8c4aabd63401ed891603 16092 sg3-utils_1.48-4.debian.tar.xz
Files:
 aeba1135c58a0da44ebdafc5b6f01e26 2219 admin optional sg3-utils_1.48-4.dsc
 86949ff553ea6c19f081815f558c42ab 16092 admin optional sg3-utils_1.48-4.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEdv0XRkXGL5yVL3hv/1nES2xS6BAFAmrHZQIACgkQ/1nES2xS
6BAPcQ/+NNSit2B1TvzvWyCY4zZ4/7ph4S9/EbM5/n7E6c3UEwLBW4pTVXqTeWTI
QPxcK7lccAbBv32DBzTPYrs6tn4FRqtgAEL92/xpv06y9PCp3bvHDnzjPBnQi/DA
zycEh/SAellSpWBXF/mgmfVpNOJx1O1TtvXq/hthehfJMi2tFO94zNOk2qijCs6r
27gQYkOzNaq+KWsrXYKEX5IESx32jCag10YnMJCdgqWH/BTrfBXUrmv06Hq8hTlU
NvWiI7l8KnPOlbOZDS1psUIkymokTO/Gs9/YzxMZ8Ix9i5TzomQiU4lDoJwLPbK3
/azo29/GoCCNp0UBOWSsRSLCYp7yoYsk4w2FcGzEL/NXEEbiy8Pim2FW+iFHmmgL
DtF8/c4kFJkmjhGZfrIk7bkQ5/dY0YvujJnEdkqgHu7FVtWUDCMTjc7LD+W9VAvA
S4Huyu7ALjgUgKpBae0HU/PmgDjffXbOd4elAiQNWhjDStNifGyrorKp+ZatItGe
ouH3z9Q2tWSpnrtOHzFNzRmraewKj9ICLMvRzaMeQ4/y/CStEV9Hh6mHAFc37AOd
g4ZU0/tV6ctSHzhVjpRjRT4QQSTa3Tw1sD2AvjJlrCXDIF7gPI4FnZqPXWpz+ALD
rWP5b20iuh+k1UXjquiY7vKzEDPisr8yFBZtXZpHfN+ytUz+nV4=
=s2Nu
-----END PGP SIGNATURE-----