[ubuntu/resolute-updates] sg3-utils 1.48-3ubuntu3.2 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Oct 6 11:04:12 UTC 2026


sg3-utils (1.48-3ubuntu3.2) resolute-security; urgency=medium

  * SECURITY UPDATE: command injection via udev property injection
    - debian/patches/CVE-2026-16313.patch: apply udev-conforming character
      encoding to the VPD 0x83 SCSI name string and T10 vendor ID ATA
      subfield output of sg_inq --export, so a crafted SCSI device cannot
      inject udev properties and execute commands as root (fix released
      upstream in sg3_utils 1.49).
    - debian/patches/CVE-2026-16313_2.patch: avoid including 0-bytes in SCSI
      name strings (upstream follow-up fix).
    - CVE-2026-16313

Date: 2026-10-01 15:50:17.760082+00:00
Changed-By: Allen Huang <allen.huang at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/sg3-utils/1.48-3ubuntu3.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list