Red Hat Product Errata RHSA-2026:50142 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:50142 - Security Advisory Overview Updated Packages Synopsis Important: sg3_utils security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sg3_utils is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sg_inq output conformance for SCSI name string and ATA fields [rhel-10.2.z] (JIRA:RHEL-188123) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2502845 - CVE-2026-16313 sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export CVEs CVE-2026-16313 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 x86_64 sg3_utils-1.48-7.el10_2.1.x86_64.rpm SHA-256: 67d4eed187d1bcda3df04cf28e168db972c2b95b088197b15c5b58de27aa3456 sg3_utils-debuginfo-1.48-7.el10_2.1.x86_64.rpm SHA-256: b1ce1a1fdcd79150192541f35f0afdaabe7017e61e2cbc0eafb69a615110495b sg3_utils-debugsource-1.48-7.el10_2.1.x86_64.rpm SHA-256: f6913ad47db8c6aef5beeeecdb963924438ab725a1b79a654b35003b4115a1d9 sg3_utils-libs-1.48-7.el10_2.1.x86_64.rpm SHA-256: a7a7d042899c9f7b4ed7a9ba102854fa4ab32ef29f4704db54ac488293935546 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.x86_64.rpm SHA-256: e67cc5a195f674ea24e12032cef3c4465f645c2ac66fd34e3b822ed934988ea7 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 x86_64 sg3_utils-1.48-7.el10_2.1.x86_64.rpm SHA-256: 67d4eed187d1bcda3df04cf28e168db972c2b95b088197b15c5b58de27aa3456 sg3_utils-debuginfo-1.48-7.el10_2.1.x86_64.rpm SHA-256: b1ce1a1fdcd79150192541f35f0afdaabe7017e61e2cbc0eafb69a615110495b sg3_utils-debugsource-1.48-7.el10_2.1.x86_64.rpm SHA-256: f6913ad47db8c6aef5beeeecdb963924438ab725a1b79a654b35003b4115a1d9 sg3_utils-libs-1.48-7.el10_2.1.x86_64.rpm SHA-256: a7a7d042899c9f7b4ed7a9ba102854fa4ab32ef29f4704db54ac488293935546 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.x86_64.rpm SHA-256: e67cc5a195f674ea24e12032cef3c4465f645c2ac66fd34e3b822ed934988ea7 Red Hat Enterprise Linux for IBM z Systems 10 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 s390x sg3_utils-1.48-7.el10_2.1.s390x.rpm SHA-256: 1b17c7f6e0f1b201749c938306b4d70fab440994c5edf2e7ec28af28fd2d4183 sg3_utils-debuginfo-1.48-7.el10_2.1.s390x.rpm SHA-256: 1f753a7cefa3f2c076a8933f34d42c03bab1ef3861bfee21d19e51f2c98a755c sg3_utils-debugsource-1.48-7.el10_2.1.s390x.rpm SHA-256: 9aa37874daf9affea8afb9916eec90029cad00f6e4124e7be05ed43c8a1ca2bc sg3_utils-libs-1.48-7.el10_2.1.s390x.rpm SHA-256: 5aa6dc62dded99a19f54da549ec073c63c0a75863343ce62c5fe8419c39560c7 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.s390x.rpm SHA-256: 3acde124c22a90fc209649674a9f7be0678c254de192511fbea1e92bd870b4f1 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 s390x sg3_utils-1.48-7.el10_2.1.s390x.rpm SHA-256: 1b17c7f6e0f1b201749c938306b4d70fab440994c5edf2e7ec28af28fd2d4183 sg3_utils-debuginfo-1.48-7.el10_2.1.s390x.rpm SHA-256: 1f753a7cefa3f2c076a8933f34d42c03bab1ef3861bfee21d19e51f2c98a755c sg3_utils-debugsource-1.48-7.el10_2.1.s390x.rpm SHA-256: 9aa37874daf9affea8afb9916eec90029cad00f6e4124e7be05ed43c8a1ca2bc sg3_utils-libs-1.48-7.el10_2.1.s390x.rpm SHA-256: 5aa6dc62dded99a19f54da549ec073c63c0a75863343ce62c5fe8419c39560c7 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.s390x.rpm SHA-256: 3acde124c22a90fc209649674a9f7be0678c254de192511fbea1e92bd870b4f1 Red Hat Enterprise Linux for Power, little endian 10 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 ppc64le sg3_utils-1.48-7.el10_2.1.ppc64le.rpm SHA-256: ba7bbcf79d5b26ded69aed4917a4d3da93f407237eebc8846dcfb188fbb712bb sg3_utils-debuginfo-1.48-7.el10_2.1.ppc64le.rpm SHA-256: b983f2fa8fde797c7f11490903f04c3250da61dbdad62e8311f46b82353f0b6c sg3_utils-debugsource-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 13d3e4b27de860a4036c2a38b1b3dbc0a22753e74584b2c9785ffd2104d74ab9 sg3_utils-libs-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 65e6efc1dec861a009be03f531068ae940d6ff52621c23226dd920c07fd57222 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 63658cdaea14d1ffbb20e8460bc0d40ca94f5f8c78eadd3f3508af55c0dd9ba8 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 ppc64le sg3_utils-1.48-7.el10_2.1.ppc64le.rpm SHA-256: ba7bbcf79d5b26ded69aed4917a4d3da93f407237eebc8846dcfb188fbb712bb sg3_utils-debuginfo-1.48-7.el10_2.1.ppc64le.rpm SHA-256: b983f2fa8fde797c7f11490903f04c3250da61dbdad62e8311f46b82353f0b6c sg3_utils-debugsource-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 13d3e4b27de860a4036c2a38b1b3dbc0a22753e74584b2c9785ffd2104d74ab9 sg3_utils-libs-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 65e6efc1dec861a009be03f531068ae940d6ff52621c23226dd920c07fd57222 sg3_utils-libs-debuginfo-1.48-7.el10_2.1.ppc64le.rpm SHA-256: 63658cdaea14d1ffbb20e8460bc0d40ca94f5f8c78eadd3f3508af55c0dd9ba8 Red Hat Enterprise Linux for ARM 64 10 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 aarch64 sg3_utils-1.48-7.el10_2.1.aarch64.rpm SHA-256: f35568e589967ba773b4376017ee1aa6eff74ef1e5d7fb1278e1ff6ba6c50dd3 sg3_utils-debuginfo-1.48-7.el10_2.1.aarch64.rpm SHA-256: 4d99982a117f0f00bd45353add48a9d18519319509b4eb5d7532a02f9355a17e sg3_utils-debugsource-1.48-7.el10_2.1.aarch64.rpm SHA-256: 367765682f50c1cb9ee1e94de8219efc6cbed1b959671a5cd8b7a747aaea8616 sg3_utils-libs-1.48-7.el10_2.1.aarch64.rpm SHA-256: 3317388c57e6df7612aa36985269093becca6a9232decd2cb3425fae3381535c sg3_utils-libs-debuginfo-1.48-7.el10_2.1.aarch64.rpm SHA-256: 298946a0bee5b9cda0a6fcd37ad1e93f57421c208e317cbd77ab829db07ff33d Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM sg3_utils-1.48-7.el10_2.1.src.rpm SHA-256: f8e39ef7a4fa43c90c1da3ac0b77d15e46a2a945492dd4dd53354d61156e86e6 aarch64 sg3_utils-1.48-7.el10_2.1.aarch64.rpm SHA-256: f35568e589967ba773b4376017ee1aa6eff74ef1e5d7fb1278e1ff6ba6c50dd3 sg3_utils-debuginfo-1.48-7.el10_2.1.aarch64.rpm SHA-256: 4d99982a117f0f00bd45353add48a9d18519319509b4eb5d7532a02f9355a17e sg3_utils-debugsource-1.48-7.el10_2.1.aarch64.rpm SHA-256: 367765682f50c1cb9ee1e94de8219efc6cbed1b959671a5cd8b7a747aaea8616 sg3_utils-libs-1.48-7.el10_2.1.aarch64.rpm SHA-256: 3317388c57e6df7612aa36985269093becca6a9232decd2cb3425fae3381535c sg3_utils-libs-debuginfo-1.48-7.el10_2.1.aarch64.rpm SHA-256: 298946a0bee5b9cda0a6fcd37ad1e93f57421c208e317cbd77ab829db07ff33d Red Hat CodeReady Linux Builder for x86_64 10 SRPM x86_64 sg3_utils-debuginfo-1.48-7.el10_2.1.x86_64.rpm SHA-256: b1ce1a1fdcd79150192541f35f0afdaabe7017e61e2cbc0eafb69a615110495b sg3_utils-debugsource-1.48-7.el10_2.1.x86_64.rpm SHA-256: f6913
A vulnerability (CVE-2026-16313, CVSS 7.6 High) in sg3_utils allows for arbitrary command execution via udev property injection in the `sg_inq --export` command. The Red Hat Security Advisory RHSA-2026:50142 addresses this issue for Red Hat Enterprise Linux 10, providing updated packages that include this security fix alongside bug fixes and enhancements.