News

USN-8874-1: sg3-utils flaw risks arbitrary command execution as root

Ubuntu patches CVE-2026-16313 in sg3-utils: unsanitised device identification data could lead to arbitrary command execution.

UptimeMag editorial team · 6 October 2026 · 1 min read

USN-8874-1: falla in sg3-utils, rischio esecuzione comandi come root

Canonical published advisory USN-8874-1 on 6 October 2026, fixing a vulnerability in sg3-utils, the package of utilities for devices using the SCSI command set. This concerns anyone managing storage on Ubuntu machines, especially in environments with SAS/SCSI disks or enclosures managed via sg3_utils.

The problem

According to the official Ubuntu advisory, sg3_utils did not properly sanitise device identification data. An attacker could exploit malformed input to execute arbitrary commands with administrator privileges. The flaw is tracked as CVE-2026-16313 and was discovered by Shaomin Chen.

Fixed versions

Ubuntu release Package Fixed version Notes
26.04 LTS (resolute) sg3-utils / sg3-utils-udev 1.48-3ubuntu3.2 —
24.04 LTS (noble) sg3-utils / sg3-utils-udev 1.46-3ubuntu4.1 —
22.04 LTS (jammy) sg3-utils / sg3-utils-udev 1.46-1ubuntu0.22.04.2 —
20.04 LTS (focal) sg3-utils / sg3-utils-udev 1.44-1ubuntu2+esm1 requires Ubuntu Pro
18.04 LTS (bionic) sg3-utils / sg3-utils-udev 1.42-2ubuntu1.18.04.2+esm1 requires Ubuntu Pro
16.04 LTS (xenial) sg3-utils / sg3-utils-udev 1.40-0ubuntu1+esm1 requires Ubuntu Pro + Legacy Support
14.04 LTS (trusty) sg3-utils 1.36-1ubuntu1+esm1 requires Ubuntu Pro + Legacy Support

How to update

On a supported system, a standard update is all it takes:

sudo apt update && sudo apt upgrade

On older releases (focal, bionic, xenial, trusty), the patch is only available with an Ubuntu Pro subscription, which is free for up to 5 machines according to the Canonical advisory.

Source: official Ubuntu Security Notices advisory, USN-8874-1.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.