Описание
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
Отчет
This is an Important vulnerability in dracut's NetworkManager-based initrd network module (nm-run.sh) that allows command injection via crafted DHCP options. An attacker on the adjacent network can exploit this by acting as a DHCP server and providing specially crafted DHCP options, leading to root code execution within the initramfs. This affects systems configured to boot using dracut's network-manager module with a DHCP-derived netroot (for example, NFS-root configurations).
Меры по смягчению последствий
Escape DHCP-derived values (root-path, next-server, dhcp-bootfile) with shell-safe quoting (for example printf '%q') before writing them to the generated dhcpopts file in modules.d/35network-manager/nm-run.sh. This approach is already used in dracut-057 and later, and is already present in the RHEL 8.10.z dracut-049-244.git20260529.el8_10 build.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dracut | Not affected | ||
| Red Hat Enterprise Linux 6 | dracut | Not affected | ||
| Red Hat Enterprise Linux 7 | dracut | Not affected | ||
| Red Hat Enterprise Linux 9 | dracut | Not affected | ||
| Red Hat OpenShift Container Platform 4 | dracut | Affected | ||
| Red Hat Enterprise Linux 8 | dracut | Fixed | RHSA-2026:26534 | 17.06.2026 |
| Red Hat Hardened Images | dracut-main-109-7.hum1 | Fixed | RHSA-2026:40700 | 16.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
A flaw was found in dracut. A remote attacker on the adjacent network ...
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
7.5 High
CVSS3