← All Advisories

CVE-2026-16313

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-16313

Key Details

CVECVE-2026-16313
CVSS Score / Version7.6 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is physical; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-93 (Improper Neutralization of CRLF Sequences ('CRLF Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
Red HatRed Hat OpenShift Container Platform 4.22
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-16313
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-16313