Debian Patches
Status for sg3-utils/1.48-4
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 0001-Fix-path-for-udevadm.patch | Fix path for udevadm See DBug #852585, for details |
Ritesh Raj Sarraf <rrs@debian.org> | no | 2020-04-10 | ||
| 0002-Fix-missing-sg-inq-fiels.patch | sg_inq: fix missing output fields The SCSI_MODEL, SCSI_MODEL_ENC, SCSI_REVISION, and other fields are missing in the output of sg_inq with --export due to a clobbering of the length field. diff --git a/src/sg_inq.c b/src/sg_inq.c index b3b8127..8e6b269 100644 |
Martin Wilck <wilck@suse.com> | invalid | debian | https://github.com/doug-gilbert/sg3_utils/pull/49/commits/c263d14510d310541606eacc3a5285f2eadc23aa | |
| 0003-sg_inq-udev-encode-SCSI-name-string-CVE-2026-16313.patch | sg_inq: udev-encode SCSI name string and ATA fields in --export The sg_inq --export path printed VPD 0x83 designator type 8 (SCSI name string) and the T10 vendor ID ATA subfield with %.*s, so a newline in a device-supplied identifier could inject udev properties. An attacker who can present a crafted SCSI device could then execute commands as root when the device is disconnected (CVE-2026-16313). . Apply the same udev-conforming character encoding already used for designator types 0 and 1 since 4d770f1. Stop the SCSI name-string loop at a terminating NUL so null-padded designators do not emit raw NULs. |
Martin Wilck <mwilck@suse.com> | yes | debian upstream | https://github.com/doug-gilbert/sg3_utils/commit/d3fa07d69e68986169bc057feff375951c4b894d | 2026-10-08 |
All known versions for source package 'sg3-utils'
- 1.48-4 (sid)
- 1.48-3 (forky)
- 1.48-3~deb13u1 (trixie)
- 1.46-3 (bookworm)
