USN-8874-1: sg3-utils flaw risks arbitrary command execution as root
Ubuntu patches CVE-2026-16313 in sg3-utils: unsanitised device identification data could lead to arbitrary command execution.
UptimeMag editorial team · 6 October 2026 · 1 min read

Canonical published advisory USN-8874-1 on 6 October 2026, fixing a vulnerability in sg3-utils, the package of utilities for devices using the SCSI command set. This concerns anyone managing storage on Ubuntu machines, especially in environments with SAS/SCSI disks or enclosures managed via sg3_utils.
The problem
According to the official Ubuntu advisory, sg3_utils did not properly sanitise device identification data. An attacker could exploit malformed input to execute arbitrary commands with administrator privileges. The flaw is tracked as CVE-2026-16313 and was discovered by Shaomin Chen.
Fixed versions
| Ubuntu release | Package | Fixed version | Notes |
|---|---|---|---|
| 26.04 LTS (resolute) | sg3-utils / sg3-utils-udev | 1.48-3ubuntu3.2 | — |
| 24.04 LTS (noble) | sg3-utils / sg3-utils-udev | 1.46-3ubuntu4.1 | — |
| 22.04 LTS (jammy) | sg3-utils / sg3-utils-udev | 1.46-1ubuntu0.22.04.2 | — |
| 20.04 LTS (focal) | sg3-utils / sg3-utils-udev | 1.44-1ubuntu2+esm1 | requires Ubuntu Pro |
| 18.04 LTS (bionic) | sg3-utils / sg3-utils-udev | 1.42-2ubuntu1.18.04.2+esm1 | requires Ubuntu Pro |
| 16.04 LTS (xenial) | sg3-utils / sg3-utils-udev | 1.40-0ubuntu1+esm1 | requires Ubuntu Pro + Legacy Support |
| 14.04 LTS (trusty) | sg3-utils | 1.36-1ubuntu1+esm1 | requires Ubuntu Pro + Legacy Support |
How to update
On a supported system, a standard update is all it takes:
sudo apt update && sudo apt upgrade
On older releases (focal, bionic, xenial, trusty), the patch is only available with an Ubuntu Pro subscription, which is free for up to 5 machines according to the Canonical advisory.
Source: official Ubuntu Security Notices advisory, USN-8874-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.