USN-8874-1: falla in sg3-utils, rischio esecuzione comandi come root
Ubuntu corregge CVE-2026-16313 in sg3-utils: dati di identificazione device non sanificati potevano portare a esecuzione di comandi arbitrari.
Redazione UptimeMag · 6 ottobre 2026 · 1 minuti di lettura

Canonical ha pubblicato il 6 ottobre 2026 l'avviso USN-8874-1, che corregge una vulnerabilità in sg3-utils, il pacchetto di utility per dispositivi che usano il comando set SCSI. Riguarda chi gestisce storage su macchine Ubuntu, specialmente in ambienti con dischi SAS/SCSI o enclosure gestite via sg3_utils.
Il problema
Secondo l'avviso ufficiale Ubuntu, sg3_utils non sanificava correttamente i dati di identificazione del dispositivo. Un attaccante poteva sfruttare l'input malformato per eseguire comandi arbitrari con privilegi di amministratore. La falla è tracciata come CVE-2026-16313 ed è stata scoperta da Shaomin Chen.
Versioni corrette
| Release Ubuntu | Pacchetto | Versione corretta | Note |
|---|---|---|---|
| 26.04 LTS (resolute) | sg3-utils / sg3-utils-udev | 1.48-3ubuntu3.2 | — |
| 24.04 LTS (noble) | sg3-utils / sg3-utils-udev | 1.46-3ubuntu4.1 | — |
| 22.04 LTS (jammy) | sg3-utils / sg3-utils-udev | 1.46-1ubuntu0.22.04.2 | — |
| 20.04 LTS (focal) | sg3-utils / sg3-utils-udev | 1.44-1ubuntu2+esm1 | richiede Ubuntu Pro |
| 18.04 LTS (bionic) | sg3-utils / sg3-utils-udev | 1.42-2ubuntu1.18.04.2+esm1 | richiede Ubuntu Pro |
| 16.04 LTS (xenial) | sg3-utils / sg3-utils-udev | 1.40-0ubuntu1+esm1 | richiede Ubuntu Pro + Legacy Support |
| 14.04 LTS (trusty) | sg3-utils | 1.36-1ubuntu1+esm1 | richiede Ubuntu Pro + Legacy Support |
Come aggiornare
Su un sistema supportato basta un aggiornamento standard:
sudo apt update && sudo apt upgrade
Sulle release più vecchie (focal, bionic, xenial, trusty) la patch è disponibile solo con un abbonamento Ubuntu Pro, gratuito fino a 5 macchine secondo quanto riportato nell'avviso Canonical.
Fonte: avviso ufficiale Ubuntu Security Notices, USN-8874-1.
Testo redatto con il supporto dell'intelligenza artificiale e verificato dalla redazione (AI Act, art. 50). Fonte: Ubuntu – avvisi di sicurezza.