Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54571

Опубликовано: 13 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-54571: dracut security update (IMPORTANT)

[057-120.git20260728.0.1]

  • Skip the default FIPS logic on special UEK kernels where the FIPS module is linked directly into the kernel. [Orabug: 38705580]
  • Ship Oracle IMA certificate [Orabug: 35992862]
  • Ship 98-integrity.conf, populating initramfs with Oracle IMA certificate [Orabug: 35992862]
  • Include sys-fs-fuse-connections.mount if needed [Orabug: 35267570]
  • network-legacy: Revert some shellcheck that breaks parse_option_121 in dhclient [Orabug: 33778173]
  • Change installation dir in network legacy module-setup so that file is never missing [Orabug: 33516170]
  • Fix paths in squash module, so that correct modprobe is installed [Orabug: 33514517]
  • Install missing 68-del-part-node.rules [Orabug: 32827579]
  • Fix permission denied error while upgrading from OL8u2 to OL8u3 [Orabug 32160196]
  • dracut-shutdown.service should run before shutdown.target is invoked [Orabug: 29629738]
  • Update list of necessary files after squashfs execution [Orabug: 29864620]
  • Supress iscsidm error output during non-debug PV boot [Orabug: 29846195]
  • Stop block device service in case system is dropped to emergency shell [Orabug: 29851988]
  • Enable booting from block device if netroot=iscsi has failed [Orabug: 29478156]
  • Calculate relative path for kernel and initrd in 51-dracut-rescue.instal [Orabug: 29503293]
  • 40network scripts ifup and netlib updates for iSCSI [Orabug: 28502725]
  • Increase timeout when waiting for carrier detection on a network interface [Orabug: 24657828] (kevin.x.lyons@oracle.com)
  • add hyperv-keyboard for Hyper-V Gen2 VM [Orabug: 19191303] (Vaughan Cao)

[057-120.git20260728]

  • fix(base): escape die() message in emergency hook script
  • fix(base): replace eval with safe variable indirection in

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

dracut

057-120.git20260728.0.1.el9_8

dracut-caps

057-120.git20260728.0.1.el9_8

dracut-config-generic

057-120.git20260728.0.1.el9_8

dracut-config-rescue

057-120.git20260728.0.1.el9_8

dracut-live

057-120.git20260728.0.1.el9_8

dracut-network

057-120.git20260728.0.1.el9_8

dracut-squash

057-120.git20260728.0.1.el9_8

dracut-tools

057-120.git20260728.0.1.el9_8

Oracle Linux x86_64

dracut

057-120.git20260728.0.1.el9_8

dracut-caps

057-120.git20260728.0.1.el9_8

dracut-config-generic

057-120.git20260728.0.1.el9_8

dracut-config-rescue

057-120.git20260728.0.1.el9_8

dracut-live

057-120.git20260728.0.1.el9_8

dracut-network

057-120.git20260728.0.1.el9_8

dracut-squash

057-120.git20260728.0.1.el9_8

dracut-tools

057-120.git20260728.0.1.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
redhat
12 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in dracut. The die() error-handling function writes i ...

suse-cvrf
4 дня назад

Security update for dracut