RHSA-2026:50141: Important: sg3_utils security, bug fix, and enhancement update
The sg3utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.Security Fix(es): sg3utils: sg3utils: arbitrary command execution via udev property injection in sginq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sginq output conformance for SCSI name string and ATA fields [rhel-9.8.z] (JIRA:RHEL-188130) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Fixed in rhel-9.8.zPatch JIRA:RHEL-188130 - Upgrade
Upgrade
sg3_utilsto a version that resolves this vulnerability.Patch CVE-2026-16313