Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54576

Опубликовано: 13 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-54576: dracut security update (IMPORTANT)

[107-9.0.1]

  • Suppress stderr for btrfs subvolume check [Orabug: 39059254]
  • fips: add logic for /boot subvolume on BTRFS [Orabug: 36028061]
  • Skip unneeded FIPS logic on UEK with special FIPS [Orabug: 38138800] [Orabug: 38709306]
  • Include correct modprobe into squashfs root [Orabug: 38559936]
  • Ship Oracle IMA certificate [Orabug: 35992862]
  • Ship 98-integrity.conf, populating initramfs with Oracle IMA certificate [Orabug: 35992862]
  • Include sys-fs-fuse-connections.mount if needed [Orabug: 35267570]
  • Change installation dir in network legacy module-setup so that file is never missing [Orabug: 33516170]
  • Fix paths in squash module, so that correct modprobe is installed [Orabug: 33514517]
  • Install missing 68-del-part-node.rules [Orabug: 32827579]
  • Fix permission denied error while upgrading from OL8u2 to OL8u3 [Orabug 32160196]
  • dracut-shutdown.service should run before shutdown.target is invoked [Orabug: 29629738]
  • Update list of necessary files after squashfs execution [Orabug: 29864620]
  • Supress iscsidm error output during non-debug PV boot [Orabug: 29846195]
  • Stop block device service in case system is dropped to emergency shell [Orabug: 29851988]
  • Enable booting from block device if netroot=iscsi has failed [Orabug: 29478156]
  • Calculate relative path for kernel and initrd in 51-dracut-rescue.instal [Orabug: 29503293]
  • Increase timeout when waiting for carrier detection on a network interface [Orabug: 24657828] (kevin.x.lyons@oracle.com)
  • add hyperv-keyboard for Hyper-V Gen2 VM [Orabug: 19191303] (Vaughan Cao)

[107-9]

  • fix(base): escape die() message in emergency hook script
  • fix(base): replace eval with safe variable indirection in splitsep and export_n

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

dracut

107-9.0.1.el10_2

dracut-caps

107-9.0.1.el10_2

dracut-config-generic

107-9.0.1.el10_2

dracut-config-rescue

107-9.0.1.el10_2

dracut-live

107-9.0.1.el10_2

dracut-network

107-9.0.1.el10_2

dracut-squash

107-9.0.1.el10_2

dracut-tools

107-9.0.1.el10_2

Oracle Linux x86_64

dracut

107-9.0.1.el10_2

dracut-caps

107-9.0.1.el10_2

dracut-config-generic

107-9.0.1.el10_2

dracut-config-rescue

107-9.0.1.el10_2

dracut-live

107-9.0.1.el10_2

dracut-network

107-9.0.1.el10_2

dracut-squash

107-9.0.1.el10_2

dracut-tools

107-9.0.1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
redhat
12 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
nvd
11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
debian
11 дней назад

A flaw was found in dracut. The die() error-handling function writes i ...

suse-cvrf
4 дня назад

Security update for dracut