{"id":"AZL-94311","summary":"CVE-2026-16313 affecting package sg3_utils 1.48-1","details":"A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.","modified":"2026-08-30T05:26:50Z","published":"2026-07-28T17:16:37Z","upstream":["CVE-2026-16313"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16313"}],"affected":[{"package":{"name":"sg3_utils","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/sg3_utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.48-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94311.json"}}],"schema_version":"1.9.0"}