CVE-2026-16313
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-93
- Published
- 2026-07-28
- Last modified
- 2026-09-17
Affected products
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat OpenShift Container Platform 4.22
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Weakness type
Related vulnerabilities
- CVE-2021-39172 — New line injection during configuration edition
- CVE-2024-51501 — CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2025-40671 — SQL injection vulnerability in AES Multimedia's Gestnet
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-8715 — PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
- CVE-2022-0666 — CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
- CVE-2026-23953 — Incus container environment configuration newline injection