[ubuntu/resolute-updates] sg3-utils 1.48-3ubuntu3.2 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue Oct 6 11:04:12 UTC 2026
sg3-utils (1.48-3ubuntu3.2) resolute-security; urgency=medium
* SECURITY UPDATE: command injection via udev property injection
- debian/patches/CVE-2026-16313.patch: apply udev-conforming character
encoding to the VPD 0x83 SCSI name string and T10 vendor ID ATA
subfield output of sg_inq --export, so a crafted SCSI device cannot
inject udev properties and execute commands as root (fix released
upstream in sg3_utils 1.49).
- debian/patches/CVE-2026-16313_2.patch: avoid including 0-bytes in SCSI
name strings (upstream follow-up fix).
- CVE-2026-16313
Date: 2026-10-01 15:50:17.760082+00:00
Changed-By: Allen Huang <allen.huang at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/sg3-utils/1.48-3ubuntu3.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list