Количество 13
Количество 13
CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes i ...
SUSE-SU-2026:3613-1
Security update for dracut
SUSE-SU-2026:3612-1
Security update for dracut
SUSE-SU-2026:3611-1
Security update for dracut
SUSE-SU-2026:3599-1
Security update for dracut
SUSE-SU-2026:3598-1
Security update for dracut
GHSA-8pxm-cr92-crx8
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
ELSA-2026-54576
ELSA-2026-54576: dracut security update (IMPORTANT)
ELSA-2026-54575
ELSA-2026-54575: dracut security update (IMPORTANT)
ELSA-2026-54571
ELSA-2026-54571: dracut security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. | CVSS3: 7.5 | 0% Низкий | 11 дней назад | |
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. | CVSS3: 7.5 | 0% Низкий | 12 дней назад | |
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. | CVSS3: 7.5 | 0% Низкий | 11 дней назад | |
CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes i ... | CVSS3: 7.5 | 0% Низкий | 11 дней назад | |
SUSE-SU-2026:3613-1 Security update for dracut | 0% Низкий | 4 дня назад | ||
SUSE-SU-2026:3612-1 Security update for dracut | 0% Низкий | 4 дня назад | ||
SUSE-SU-2026:3611-1 Security update for dracut | 0% Низкий | 4 дня назад | ||
SUSE-SU-2026:3599-1 Security update for dracut | 0% Низкий | 6 дней назад | ||
SUSE-SU-2026:3598-1 Security update for dracut | 0% Низкий | 6 дней назад | ||
GHSA-8pxm-cr92-crx8 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. | CVSS3: 7.5 | 0% Низкий | 11 дней назад | |
ELSA-2026-54576 ELSA-2026-54576: dracut security update (IMPORTANT) | 0% Низкий | 5 дней назад | ||
ELSA-2026-54575 ELSA-2026-54575: dracut security update (IMPORTANT) | 0% Низкий | 5 дней назад | ||
ELSA-2026-54571 ELSA-2026-54571: dracut security update (IMPORTANT) | 0% Низкий | 5 дней назад |
Уязвимостей на страницу