CVE-2026-6893

EUVD-2026-36110
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67.55%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:107-7.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:105-4.el10_0.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:033-577.el7_9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:049-244.git20260529.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:049-223.git20230119.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:049-223.git20230119.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:057-115.git20260527.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:057-25.git20250717.el9_2.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:057-54.git20250423.el9_4.3 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:057-89.git20250311.el9_6.1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
109-6.hum1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
dracut
bookworm
vulnerable
forky
112-2
fixed
sid
112-5
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dracut
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
dracut
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 8.8 TUS
0:049-223.git20230119.el8_8.1
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-caps
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-config-generic
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-config-rescue
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-live
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-network
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 8.8 TUS
0:049-223.git20230119.el8_8.1
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-squash
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
dracut-tools
RHEL 8
0:049-244.git20260529.el8_10
fixed
RHEL 9
0:057-115.git20260527.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
dracut
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-caps
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-config-generic
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-config-rescue
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-debuginfo
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-debugsource
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-fips
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
dracut-fips-aesni
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
dracut-network
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
dracut-squash
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed
dracut-tools
Amazon Linux 2
0:033-535.amzn2.1.7
fixed
Amazon Linux 2023
0:102-3.amzn2023.0.3
fixed