doug-gilbert sg3_utils是doug-gilbert个人开发者的一套SCSI通用工具软件。 doug-gilbert sg3_utils存在输入验证错误漏洞,该漏洞源于sg_inq命令在使用--export选项时未对SCSI名称字符串字段中的控制字符进行清理,导致换行符可注入任意属性到udev设备数据库,攻击者通过提供特制SCSI设备可在设备断开时以root权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.48-7.el10_2.1 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.48-7.el10_0.2 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 1:1.37-20.el7_9 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.44-6.el8_10.1 ~ * |
cpe:/a:redhat:enterprise_linux:8::crb
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.44-5.el8_4.1 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:1.44-5.el8_4.1 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.44-5.el8_6.1 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:1.44-5.el8_6.1 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.44-6.el8_8.1 ~ * |
cpe:/o:redhat:rhel_e4s:8.8::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.44-6.el8_8.1 ~ * |
cpe:/o:redhat:rhel_e4s:8.8::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.47-10.el9_8.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::crb
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.47-9.el9_2.1 ~ * |
cpe:/o:redhat:rhel_e4s:9.2::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.47-9.el9_4.1 ~ * |
cpe:/o:redhat:rhel_e4s:9.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.47-10.el9_6.2 ~ * |
cpe:/a:redhat:rhel_eus:9.6::crb
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202609082051-0 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202609140240-0 ~ * |
cpe:/a:redhat:openshift:4.16::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202609191027-0 ~ * |
cpe:/a:redhat:openshift:4.17::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202609031320-0 ~ * |
cpe:/a:redhat:openshift:4.18::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202609021231-0 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202609021029-0 ~ * |
cpe:/a:redhat:openshift:4.20::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202609021100-0 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202608130832-0 ~ * |
cpe:/a:redhat:openshift:4.22::el9
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49332 | 8.5 HIGH | Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity |
| CVE-2026-18107 | 7.8 HIGH | Criu: criu: container escape via rseq critical section hijack during checkpoint/restore |
| CVE-2026-18047 | 6.5 MEDIUM | Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication b |
| CVE-2026-17072 | 3.3 LOW | Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_fla |
No comments yet