Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:26534

Опубликовано: 19 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: dracut security update

The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.

Security Fix(es):

  • dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
dracutx86_64244.git20260529.el8_10dracut-049-244.git20260529.el8_10.x86_64.rpm
dracut-capsx86_64244.git20260529.el8_10dracut-caps-049-244.git20260529.el8_10.x86_64.rpm
dracut-config-genericx86_64244.git20260529.el8_10dracut-config-generic-049-244.git20260529.el8_10.x86_64.rpm
dracut-config-rescuex86_64244.git20260529.el8_10dracut-config-rescue-049-244.git20260529.el8_10.x86_64.rpm
dracut-livex86_64244.git20260529.el8_10dracut-live-049-244.git20260529.el8_10.x86_64.rpm
dracut-networkx86_64244.git20260529.el8_10dracut-network-049-244.git20260529.el8_10.x86_64.rpm
dracut-squashx86_64244.git20260529.el8_10dracut-squash-049-244.git20260529.el8_10.x86_64.rpm
dracut-toolsx86_64244.git20260529.el8_10dracut-tools-049-244.git20260529.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
redhat
около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

msrc
около 2 месяцев назад

Dracut: dracut: root code execution via dhcp options command injection

CVSS3: 7.5
debian
около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network ...