CVE-2026-16445

EUVD-2026-46253
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 86.05%
Debian logo
Debian Releases
Debian Product
Codename
dracut
bookworm
vulnerable
forky
112-2
fixed
sid
112-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dracut
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
dracut
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 8.8 TUS
0:049-223.git20230119.el8_8.1
fixed
dracut-caps
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-config-generic
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-config-rescue
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-live
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-network
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 8.8 TUS
0:049-223.git20230119.el8_8.1
fixed
dracut-squash
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-tools
RHEL 8
0:049-244.git20260529.el8_10
fixed