Red Hat Fixes sg3_utils udev Injection in RHEL 10.0 EUS
Quick Answer
Red Hat published RHSA-2026:69124 for CVE-2026-16313, a 7.6 High sg3_utils property-injection flaw in RHEL 10.0 EUS. A crafted physical SCSI or USB device can influence a udev removal command; the fixed package is 1.48-7.el10_0.2.
Control Physical Devices And Update sg3_utils
What to do now: Identify RHEL 10.0 EUS systems that use sg3_utils udev rules, restrict untrusted SCSI and USB access, install the fixed package, and validate device discovery and removal behavior.
Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.
Scope And Authority
| Product scope | RHEL 10.0 EUS sg3_utils |
|---|---|
| Advisory | RHSA-2026:69124 |
| CVE | CVE-2026-16313 |
| Authoritative release date | 2026-09-21 03:17:41 UTC |
| Authority revision date | 2026-09-21 03:18:11 UTC |
| Affected versions | RHEL 10.0 EUS sg3_utils packages before 1.48-7.el10_0.2 |
| Fixed version | sg3_utils 1.48-7.el10_0.2 |
| CVSS base score | 7.6 (CVSS v3.1) |
| CVSS severity | High |
| Exploitation status | Not stated by Red Hat; no exploitation claim is inferred. |
What Changed
The vulnerability allows crafted device data to inject a udev property used by a removal command, which Red Hat says can lead to root command execution when the device disconnects. Physical access or an equivalent device path is part of the stated scenario; the advisory does not confirm exploitation.
What To Validate Now
- Inventory. Locate RHEL 10.0 EUS systems with sg3_utils and identify endpoints, servers, appliances, labs, or operational environments where untrusted physical SCSI or USB devices can be connected.
- Establish applicability. Confirm the exact EUS stream, package NVR, and udev rule that invokes
sg_inq --exportand usesREMOVE_CMD. - Remediate. Update sg3_utils and sg3_utils-libs to 1.48-7.el10_0.2 or a supported superseding build. Red Hat's workaround removes or comments the REMOVE_CMD assignment or disables the affected rule.
- Validate. Confirm package NVRs, inspect the active udev rule, and test approved device discovery, disconnect, logging, and any storage-management dependencies.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Changing udev rules can disrupt legitimate storage or device workflows. Coordinate with platform and operations owners, test the supported fix or workaround, and preserve console or recovery access.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

