CVE-2026-16313
HIGH 7.6A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Severe if exploited (CVSS 7.6), but no known exploitation and low modeled probability. Patch on a normal cadence.
Exploitation likelihood
0.3%chance of exploitation in 30 days · 19th percentile
Impact if exploited
7.6CVSS 3.1 · HIGH
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityHigh
What an attacker needs
- ⚠Access: Requires physical access to the device
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-16313/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-16313/poc.json
Affected
Vendors Red Hat
Products Red Hat Enterprise Linux 10 Red Hat Enterprise Linux 8 Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long Life Add On Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long Life Add On Red Hat Enterprise Linux 8.8 Telecommunications Update Service Red Hat Enterprise Linux 8.8 Update Services For Sap Solutions Red Hat Enterprise Linux 9 Red Hat Enterprise Linux 9.6 Extended Update Support Red Hat Openshift Container Platform 4.22 Red Hat Enterprise Linux 6
Weakness (CWE)
- CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
All CVSS metrics
- HIGH 7.6 v3.1 · CNA Primary
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - HIGH 7.6 v3.1 · NVD Secondary
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References
Advisories
- https://access.redhat.com/errata/RHSA-2026:50141
- https://access.redhat.com/errata/RHSA-2026:50142
- https://access.redhat.com/errata/RHSA-2026:54769
- https://access.redhat.com/errata/RHSA-2026:56130
- https://access.redhat.com/errata/RHSA-2026:59397
- https://access.redhat.com/errata/RHSA-2026:59555
- https://access.redhat.com/errata/RHSA-2026:59567
- https://access.redhat.com/errata/RHSA-2026:59568