Red Hat has addressed CVE-2026-16313, a command-injection vulnerability in sg3_utils versions 1.34 through 1.48. The sg_inq --export function emitted SCSI VPD page 0x83 device-identification values for udev without sanitizing control characters in SCSI name strings and ATA fields. An attacker able to present a crafted SCSI device could inject udev properties such as REMOVE_CMD; when the device is removed, default udev rules may execute the injected command as root.
The defect, introduced in February 2022 and corrected upstream in PR #83, also affects output conformance for SCSI name-string and ATA fields. Red Hat issued Important advisories for affected RHEL 9.6 and selected RHEL 8.8 servicing channels, supplying sg3_utils-1.47-10.el9_6.2 for RHEL 9.6 and sg3_utils-1.44-6.el8_8.1 or later for RHEL 8.8; organizations should apply the package updates through their applicable support channels.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2026:61261 for affected RHEL 9 sg3_utils and sg3_utils-libs packages, remediating CVE-2026-16313. The flaw permits arbitrary command execution through udev property injection when sg_inq is run with --export.
Red Hat published Important advisory RHSA-2026:61260 for RHEL 9 systems, updating affected sg3_utils and sg3_utils-libs packages to remediate CVE-2026-16313. The vulnerability enables arbitrary command execution through udev property injection via sg_inq --export.
Alibaba Cloud Linux 3 published security advisory ALINUX3-SA-2026:0273, patching CVE-2026-16313 in sg3_utils packages, including sg3_utils-devel, sg3_utils-doc, and sg3_utils-libs. Tenable added local RPM-inventory detection through plugin alinux3_sa_2026-0273.
Unity Linux published advisory UTSA-2026-104844 for Unity Linux 20, updating sg3_utils to address CVE-2026-16313. The flaw in sg_inq --export could allow a crafted SCSI device name string to inject udev properties and execute commands as root upon device removal.
Red Hat published Important advisory RHSA-2026:59568 for selected RHEL 8.8 update-service channels, supplying sg3_utils 1.44-6.el8_8.1 to fix CVE-2026-16313.
Red Hat published Important advisory RHSA-2026:59397 for RHEL 9.6 servicing channels, providing sg3_utils 1.47-10.el9_6.2 to remediate CVE-2026-16313 and address sg_inq output conformance for SCSI name-string and ATA fields.
TencentOS Server 3 published a patch for CVE-2026-16313 affecting its sg3_utils package, tracked in Tencent advisory TSSA-2026:0906. Nessus detection is provided through Tencent local security checks.
Commit c410806c introduced the unsanitized handling of SCSI name strings and ATA subfields in sg_inq's export_dev_ids() function, creating the command-injection flaw later assigned CVE-2026-16313.
Red Hat addressed CVE-2026-16313 through advisories for RHEL 8, RHEL 9, RHEL 10, OpenShift Container Platform 4.22, and RHEL 8.4 and 8.6 extended-support channels, including RHSA-2026:50141, 50142, 56130, 54769, 59555, and 59567.
The sg3_utils project fixed CVE-2026-16313 in upstream pull request #83. The flaw allowed crafted device identification data emitted by sg_inq --export to inject udev properties such as REMOVE_CMD and execute commands as root when the device was removed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.