CVE-2026-16313

🟡 Monitoruj

Wykryta luka w sg3_utils pozwala na wykonanie dowolnych poleceń jako root przez wstrzyknięcie danych.

CVSS
7.6
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-07-28 17:16:37 UTC
Ostatnia modyfikacja (NVD)2026-09-17 12:17:24 UTC
Referencje