THREAT OPS › Threat News › [NVD] CVE-2026-16313 (HIGH 7.6) — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary proper
[NVD] CVE-2026-16313 (HIGH 7.6) — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary proper
CVE-2026-16313 CVSS: 7.6 HIGH Published: 2026-07-28T17:16:37.807
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow a
Indicators of compromise
- CVE-2026-16313cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16313