RHSA-2026:50142: Important: sg3_utils security, bug fix, and enhancement update
The sg3utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.Security Fix(es): sg3utils: sg3utils: arbitrary command execution via udev property injection in sginq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sginq output conformance for SCSI name string and ATA fields [rhel-10.2.z] (JIRA:RHEL-188123) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Fixed in rhel-10.2.zPatch RHEL-188123
Event History
Frequently Asked Questions
What is the CVE associated with RHSA-2026:50142?
The CVE associated with RHSA-2026:50142 is CVE-2026-16313.
What is the nature of the vulnerability in RHSA-2026:50142?
The vulnerability in RHSA-2026:50142 allows for arbitrary command execution via udev property injection in sg_inq --export.
How do I fix the vulnerability identified in RHSA-2026:50142?
To fix the vulnerability identified in RHSA-2026:50142, you should update the sg3_utils package to the latest version.
What severity level is assigned to RHSA-2026:50142?
RHSA-2026:50142 is assigned a risk level of 65.
What functionality does the sg3_utils package provide as noted in RHSA-2026:50142?
The sg3_utils package provides command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.