Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16445

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

Отчет

This is an Important vulnerability in dracut's NetworkManager-based initrd network module (nm-run.sh) that allows command injection via crafted DHCP options. An attacker on the adjacent network can exploit this by acting as a DHCP server and providing specially crafted DHCP options, leading to root code execution within the initramfs. This affects systems configured to boot using dracut's network-manager module with a DHCP-derived netroot (for example, NFS-root configurations).

Меры по смягчению последствий

Escape DHCP-derived values (root-path, next-server, dhcp-bootfile) with shell-safe quoting (for example printf '%q') before writing them to the generated dhcpopts file in modules.d/35network-manager/nm-run.sh. This approach is already used in dracut-057 and later, and is already present in the RHEL 8.10.z dracut-049-244.git20260529.el8_10 build.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dracutNot affected
Red Hat Enterprise Linux 6dracutNot affected
Red Hat Enterprise Linux 7dracutNot affected
Red Hat Enterprise Linux 9dracutNot affected
Red Hat OpenShift Container Platform 4dracutAffected
Red Hat Enterprise Linux 8dracutFixedRHSA-2026:2653417.06.2026
Red Hat Hardened Imagesdracut-main-109-7.hum1FixedRHSA-2026:4070016.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2503147dracut: dracut: Root code execution via DHCP options command injection in NetworkManager initrd module

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
27 дней назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

CVSS3: 7.5
nvd
27 дней назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

CVSS3: 7.5
debian
27 дней назад

A flaw was found in dracut. A remote attacker on the adjacent network ...

CVSS3: 7.5
github
27 дней назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

7.5 High

CVSS3