CVE-2026-16445

EUVD-2026-46253
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
dracut
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
dracut
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-caps
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-config-generic
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-config-rescue
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-live
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-network
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-squash
RHEL 8
0:049-244.git20260529.el8_10
fixed
dracut-tools
RHEL 8
0:049-244.git20260529.el8_10
fixed