RHSA-2026:61260: Important: sg3_utils security, bug fix, and enhancement update
Important: sg3utils security, bug fix, and enhancement update
Other sources
The sg3utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.Security Fix(es): sg3utils: sg3utils: arbitrary command execution via udev property injection in sginq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sginq output conformance for SCSI name string and ATA fields [rhel-9.4.z] (JIRA:RHEL-188128) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Fixed in 9.4.zPatch RHEL-188128 - Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Patch CVE-2026-16313
Event History
Frequently Asked Questions
Which Red Hat Enterprise Linux environments are covered by this advisory?
The advisory covers x86_64, ARM 64, IBM z Systems, and Power little-endian offerings, including Extended Life Cycle, four-years-of-updates, and Update Services for SAP Solutions subscriptions listed in the affected software.
Are there changes in this update beyond the security fix?
Yes. It also includes an sg_inq output conformance fix for SCSI name string and ATA fields on rhel-9.4.z.