A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Avoid querying local disk serial numbers from untrusted or attacker-controlled storage devices or virtual storage backends. Systems should be configured to reject or sanitize malformed SCSI VPD page 0x80 data before it is processed by libstoragemgmt to prevent stack buffer overflows.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.
Title Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-121
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T20:44:03.956Z

Reserved: 2026-09-17T21:25:57.912Z

Link: CVE-2026-93433

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T21:17:17.847

Modified: 2026-09-21T21:17:17.847

Link: CVE-2026-93433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses