<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:10:12.048157+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:50141</id>
    <title>ALSA-2026:50141 — Important: sg3_utils security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:10:12.463840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: sg3_utils, AlmaLinux:9: sg3_utils-devel, AlmaLinux:9: sg3_utils-libs</p>
<p>The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.</p>
<p>Security Fix(es):</p>
<p>* sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sg_inq output conformance for SCSI name string and ATA fields [almalinux-9.8.z] (JIRA:AlmaLinux-188130)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:50141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</id>
    <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T09:10:12.463944+00:00</updated>
    <content>certfr-2026-avi-1256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-380626</id>
    <title>EUVD-2026-380626</title>
    <updated>2026-10-04T09:10:12.463977+00:00</updated>
    <content>EUVD-2026-380626</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-380626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16313</id>
    <title>fkie_cve-2026-16313</title>
    <updated>2026-10-04T09:10:12.464000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-16313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wqmp-fw94-rpg4</id>
    <title>GHSA-wqmp-fw94-rpg4</title>
    <updated>2026-10-04T09:10:12.464041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wqmp-fw94-rpg4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-16313</id>
    <title>msrc_CVE-2026-16313 — Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export</title>
    <updated>2026-10-04T09:10:12.464070+00:00</updated>
    <content>msrc_CVE-2026-16313</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-16313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3244</id>
    <title>OESA-2026-3244 — sg3_utils security update</title>
    <updated>2026-10-04T09:10:12.464097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: sg3_utils, openEuler:24.03-LTS-SP4: sg3_utils, openEuler:20.03-LTS-SP4: sg3_utils, openEuler:22.03-LTS-SP4: sg3_utils, openEuler:24.03-LTS-SP1: sg3_utils</p>
<p>The sg3_utils package contains utilities that send SCSI commands to devices. As well as devices on transports traditionally associated with SCSI (e.g. Fibre Channel (FCP), Serial Attached SCSI (SAS) and the SCSI Parallel Interface(SPI)) many other devices use SCSI command sets. ATAPI cd/dvd drives and SATA disks that connect via a translation layer or a bridge device are examples of devices that use SCSI command sets.

Security Fix(es):</p>
<p>A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.(CVE-2026-16313)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3244"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50141</id>
    <title>RHSA-2026:50141 — Red Hat Security Advisory: sg3_utils security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:10:12.464149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54769</id>
    <title>RHSA-2026:54769 — Red Hat Security Advisory: OpenShift Container Platform 4.22.10 bug fix and security update</title>
    <updated>2026-10-04T09:10:12.464179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O samba: Missing access check on reparse point operations libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. unbound: Unbound: Cache manipulation via 'ghost domain names' attack unbound: Unbound: Denial of Service via excessive EDNS options vim: Vim: Arbitrary Code Execution via crafted directory names vim: Vim: Arbitrary code execution via crafted step-definition patterns vim: Vim: Arbitrary code execution via Python omni-completion acl: Symlink traversal privilege escalation via libacl functions vim: Vim: Out-of-bounds Write in Spell File Word Count vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion openssh: OpenSSH: Use-after-free vulnerab…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:50141</id>
    <title>RLSA-2026:50141 — Important: sg3_utils security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:10:12.464269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: sg3_utils</p>
<p>The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets.</p>
<p>Security Fix(es):</p>
<p>* sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sg_inq output conformance for SCSI name string and ATA fields [rhel-9.8.z] (JIRA:Rocky Linux-188130)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:50141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16313</id>
    <title>UBUNTU-CVE-2026-16313</title>
    <updated>2026-10-04T09:10:12.464321+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: sg3-utils, Ubuntu:16.04:LTS: sg3-utils, Ubuntu:18.04:LTS: sg3-utils, Ubuntu:20.04:LTS: sg3-utils, Ubuntu:22.04:LTS: sg3-utils, Ubuntu:24.04:LTS: sg3-utils, Ubuntu:26.04:LTS: sg3-utils</p>
<p>A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2645</id>
    <title>WID-SEC-W-2026-2645 — Red Hat Enterprise Linux (sg3_utils): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorr…</title>
    <updated>2026-10-04T09:10:12.464372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer mit physischem Zugriff kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2645"/>
  </entry>
</feed>
