Red Hat Product Errata RHSA-2026:59397 - Security Advisory Issued: 2026-08-25 Updated: 2026-08-25 RHSA-2026:59397 - Security Advisory Overview Updated Packages Synopsis Important: sg3_utils security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for sg3_utils is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): sg_inq output conformance for SCSI name string and ATA fields [rhel-9.6.z] (JIRA:RHEL-188129) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2502845 - CVE-2026-16313 sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export CVEs CVE-2026-16313 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 x86_64 sg3_utils-1.47-10.el9_6.2.x86_64.rpm SHA-256: 7dd506cf17723b7f6fa6a609aeb38afdc82713019a1bc989339e1ff0e08b5c3a sg3_utils-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: 0ecf60544873f6fd4fd94902817219700d4aad059775432f9569ef910ac6d045 sg3_utils-debuginfo-1.47-10.el9_6.2.x86_64.rpm SHA-256: ac0091e98fc44bb67a0232ba411fe6b7681f48de1dceac5610f05e8a767a7afc sg3_utils-debugsource-1.47-10.el9_6.2.i686.rpm SHA-256: 500b3e1e3779f1dca06b7acdb12c165e45d14ad0a93df694d58f451803b775f8 sg3_utils-debugsource-1.47-10.el9_6.2.x86_64.rpm SHA-256: bddff6de6886939e9b7b88f8fc86ebc53e5ddda12b8f388682a86d9e1a032b7d sg3_utils-libs-1.47-10.el9_6.2.i686.rpm SHA-256: bc2d7f70e0d92e2b7cd91d68d2abc40c8f38892b1807c55800723608018af712 sg3_utils-libs-1.47-10.el9_6.2.x86_64.rpm SHA-256: 9acaee9d688c7474db030d273adc94342cefd17b08145657e0e62dcb5091f50d sg3_utils-libs-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: bf6a8c1829eef1c998107bbd88ada619892eaddb58fe4372d2beb07e5e2a444f sg3_utils-libs-debuginfo-1.47-10.el9_6.2.x86_64.rpm SHA-256: 5981e03e9f2546d6f51b7a5e9996ee41c729d77688bfa059dec2702b72667e38 Red Hat Enterprise Linux Server - AUS 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 x86_64 sg3_utils-1.47-10.el9_6.2.x86_64.rpm SHA-256: 7dd506cf17723b7f6fa6a609aeb38afdc82713019a1bc989339e1ff0e08b5c3a sg3_utils-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: 0ecf60544873f6fd4fd94902817219700d4aad059775432f9569ef910ac6d045 sg3_utils-debuginfo-1.47-10.el9_6.2.x86_64.rpm SHA-256: ac0091e98fc44bb67a0232ba411fe6b7681f48de1dceac5610f05e8a767a7afc sg3_utils-debugsource-1.47-10.el9_6.2.i686.rpm SHA-256: 500b3e1e3779f1dca06b7acdb12c165e45d14ad0a93df694d58f451803b775f8 sg3_utils-debugsource-1.47-10.el9_6.2.x86_64.rpm SHA-256: bddff6de6886939e9b7b88f8fc86ebc53e5ddda12b8f388682a86d9e1a032b7d sg3_utils-libs-1.47-10.el9_6.2.i686.rpm SHA-256: bc2d7f70e0d92e2b7cd91d68d2abc40c8f38892b1807c55800723608018af712 sg3_utils-libs-1.47-10.el9_6.2.x86_64.rpm SHA-256: 9acaee9d688c7474db030d273adc94342cefd17b08145657e0e62dcb5091f50d sg3_utils-libs-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: bf6a8c1829eef1c998107bbd88ada619892eaddb58fe4372d2beb07e5e2a444f sg3_utils-libs-debuginfo-1.47-10.el9_6.2.x86_64.rpm SHA-256: 5981e03e9f2546d6f51b7a5e9996ee41c729d77688bfa059dec2702b72667e38 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 s390x sg3_utils-1.47-10.el9_6.2.s390x.rpm SHA-256: 2ffe93e630004ebb4a6d5a6b2d1bc3ff92c63fa4889431bcb37fe059d26152e6 sg3_utils-debuginfo-1.47-10.el9_6.2.s390x.rpm SHA-256: 8dc05b51b77718449ec22d9eb803cfeb7e68815978adc95b4d2abafc8e34f655 sg3_utils-debugsource-1.47-10.el9_6.2.s390x.rpm SHA-256: 0916459d6493a2d4b9052366d35bd2b491dbcea7bb6a834f08c204b9ea7272a5 sg3_utils-libs-1.47-10.el9_6.2.s390x.rpm SHA-256: c3ba613c59ccfab218e78a1ff1b3ecf9f3749acb217b410e72e417d4eeaa1d78 sg3_utils-libs-debuginfo-1.47-10.el9_6.2.s390x.rpm SHA-256: d43f71db39557db105c9a5fd735dc0eaa3ffdaa7a5de60ca53e211fe3b739fab Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 ppc64le sg3_utils-1.47-10.el9_6.2.ppc64le.rpm SHA-256: 0f851ae5fbe0de4ddf92d6fbd87667956e1b25dbfeff44d905683798a6204dc7 sg3_utils-debuginfo-1.47-10.el9_6.2.ppc64le.rpm SHA-256: c7a8229de8dcbd298613717ce202547f5568a266b7f817aef2ae2a5701a15b82 sg3_utils-debugsource-1.47-10.el9_6.2.ppc64le.rpm SHA-256: 97d8f912ce496cbc970f93dba862e0c22c00e4c6c74ffe41bbc16bab45d7ac13 sg3_utils-libs-1.47-10.el9_6.2.ppc64le.rpm SHA-256: ffffa0260cac3c8054ff57556291cb19642d4e5438c8e2471047db6305fef2b0 sg3_utils-libs-debuginfo-1.47-10.el9_6.2.ppc64le.rpm SHA-256: ee37eb2add24d847d8c867c4ce3bae8c15954cfff91a1ba08f06c06cc1677a47 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 aarch64 sg3_utils-1.47-10.el9_6.2.aarch64.rpm SHA-256: d4fb67ef9e60e08c8f7d82a7f0ea67a7bc3bf3f2d36315b913cc12e54e35a325 sg3_utils-debuginfo-1.47-10.el9_6.2.aarch64.rpm SHA-256: afdb82ad872ef5e92274541dbea5ec463cdd2d622d95584f910d3c17c2cdc205 sg3_utils-debugsource-1.47-10.el9_6.2.aarch64.rpm SHA-256: 5b7caa2a2dd8194e17a2dd67684eb533fa65a9bad431d2014471db5db98e2306 sg3_utils-libs-1.47-10.el9_6.2.aarch64.rpm SHA-256: a6e8e289d1258f1678c457ab5ad3601508f0b20e084ae000f6aabef3367f4e86 sg3_utils-libs-debuginfo-1.47-10.el9_6.2.aarch64.rpm SHA-256: 3905c505e34f0257a02c7c056642f4a667dce13a5aca8b2d40448e970c04d6d8 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 ppc64le sg3_utils-1.47-10.el9_6.2.ppc64le.rpm SHA-256: 0f851ae5fbe0de4ddf92d6fbd87667956e1b25dbfeff44d905683798a6204dc7 sg3_utils-debuginfo-1.47-10.el9_6.2.ppc64le.rpm SHA-256: c7a8229de8dcbd298613717ce202547f5568a266b7f817aef2ae2a5701a15b82 sg3_utils-debugsource-1.47-10.el9_6.2.ppc64le.rpm SHA-256: 97d8f912ce496cbc970f93dba862e0c22c00e4c6c74ffe41bbc16bab45d7ac13 sg3_utils-libs-1.47-10.el9_6.2.ppc64le.rpm SHA-256: ffffa0260cac3c8054ff57556291cb19642d4e5438c8e2471047db6305fef2b0 sg3_utils-libs-debuginfo-1.47-10.el9_6.2.ppc64le.rpm SHA-256: ee37eb2add24d847d8c867c4ce3bae8c15954cfff91a1ba08f06c06cc1677a47 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 SRPM sg3_utils-1.47-10.el9_6.2.src.rpm SHA-256: 2419e0fb4135c8c50568ed4c6a54e61695465632f5553b7c75ac0b6acc7ce983 x86_64 sg3_utils-1.47-10.el9_6.2.x86_64.rpm SHA-256: 7dd506cf17723b7f6fa6a609aeb38afdc82713019a1bc989339e1ff0e08b5c3a sg3_utils-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: 0ecf60544873f6fd4fd94902817219700d4aad059775432f9569ef910ac6d045 sg3_utils-debuginfo-1.47-10.el9_6.2.x86_64.rpm SHA-256: ac0091e98fc44bb67a0232ba411fe6b7681f48de1dceac5610f05e8a767a7afc sg3_utils-debugsource-1.47-10.el9_6.2.i686.rpm SHA-256: 500b3e1e3779f1dca06b7acdb12c165e45d14ad0a93df694d58f451803b775f8 sg3_utils-debugsource-1.47-10.el9_6.2.x86_64.rpm SHA-256: bddff6de6886939e9b7b88f8fc86ebc53e5ddda12b8f388682a86d9e1a032b7d sg3_utils-libs-1.47-10.el9_6.2.i686.rpm SHA-256: bc2d7f70e0d92e2b7cd91d68d2abc40c8f38892b1807c55800723608018af712 sg3_utils-libs-1.47-10.el9_6.2.x86_64.rpm SHA-256: 9acaee9d688c7474db030d273adc94342cefd17b08145657e0e62dcb5091f50d sg3_utils-libs-debuginfo-1.47-10.el9_6.2.i686.rpm SHA-256: bf6a8c1829eef1c998107bbd88ada619892eaddb58fe4372d2be
The vulnerability CVE-2026-16313 (CVSS 7.6 High) in the sg3_utils package allows for arbitrary command execution via udev property injection in the `sg_inq --export` command. This update for Red Hat Enterprise Linux 9.6 Extended Update Support addresses the security flaw, along with bug fixes and enhancements. Administrators should apply the update using the referenced Red Hat solution article.