RHSA-2026:61261: Important: sg3_utils security, bug fix, and enhancement update
Important: sg3utils security, bug fix, and enhancement update
Other sources
The sg3utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.Security Fix(es): sg3utils: sg3utils: arbitrary command execution via udev property injection in sginq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sginq output conformance for SCSI name string and ATA fields (JIRA:RHEL-188127) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Patch CVE-2026-16313 - Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Patch RHEL-188127
Event History
Frequently Asked Questions
Which systems are most exposed to this issue?
Systems running the affected Red Hat Enterprise Linux offerings listed in the advisory and using sg3_utils are in scope. Exposure is specifically associated with use of sg_inq --export and udev property injection.
What capability does an attacker need to exploit this vulnerability?
The issue is described as arbitrary command execution through injection of udev properties processed by sg_inq --export. The advisory does not state whether this can be exploited remotely or without prior local access.
What remediation is available?
Red Hat has issued RHSA-2026:61261 as a security, bug-fix, and enhancement update for sg3_utils. The supplied information does not include fixed package versions or alternative mitigations if updates cannot be applied immediately.