Fedora Account System
Red Hat Associate
Red Hat Customer
sg3_utils v1.34 through v1.48 contains a command injection flaw in export_dev_ids() in src/sg_inq.c. The sg_inq --export command outputs SCSI device identification data from VPD page 0x83 in KEY=VALUE format for udev import. The SCSI name string field (designator type 8, line 2046) and the ATA subfield (line 1922) are printed with printf("%.*s") without sanitizing control characters. A newline embedded in a device-controlled name string splits a single property into two lines, allowing injection of arbitrary udev properties including REMOVE_CMD. Combined with the default udev rule in 50-udev-default.rules that executes REMOVE_CMD on device removal, this enables arbitrary root command execution when a crafted SCSI device is disconnected. CWE-93. Introduced in commit c410806c (2012-02-23). Fixed upstream in PR #83.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:50141 https://access.redhat.com/errata/RHSA-2026:50141
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:50142 https://access.redhat.com/errata/RHSA-2026:50142
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:56130 https://access.redhat.com/errata/RHSA-2026:56130
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:59397 https://access.redhat.com/errata/RHSA-2026:59397
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:59555 https://access.redhat.com/errata/RHSA-2026:59555
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:59567 https://access.redhat.com/errata/RHSA-2026:59567
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:59568 https://access.redhat.com/errata/RHSA-2026:59568
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:61261 https://access.redhat.com/errata/RHSA-2026:61261
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:61260 https://access.redhat.com/errata/RHSA-2026:61260
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:63100 https://access.redhat.com/errata/RHSA-2026:63100
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:63041 https://access.redhat.com/errata/RHSA-2026:63041
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:63044 https://access.redhat.com/errata/RHSA-2026:63044