Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-8pxm-cr92-crx8

11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-15816

11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-15816

12 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-15816

11 дней назад

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-15816

11 дней назад

A flaw was found in dracut. The die() error-handling function writes i ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3613-1

5 дней назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3612-1

5 дней назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3611-1

5 дней назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3599-1

6 дней назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3598-1

6 дней назад

Security update for dracut

EPSS: Низкий
rocky логотип

RLSA-2026:54576

4 дня назад

Important: dracut security update

EPSS: Низкий
rocky логотип

RLSA-2026:54575

3 дня назад

Important: dracut security update

EPSS: Низкий
rocky логотип

RLSA-2026:54571

4 дня назад

Important: dracut security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54576

5 дней назад

ELSA-2026-54576: dracut security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54575

5 дней назад

ELSA-2026-54575: dracut security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54571

5 дней назад

ELSA-2026-54571: dracut security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8pxm-cr92-crx8

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
0%
Низкий
11 дней назад
ubuntu логотип
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
0%
Низкий
11 дней назад
redhat логотип
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.

CVSS3: 7.5
0%
Низкий
11 дней назад
debian логотип
CVE-2026-15816

A flaw was found in dracut. The die() error-handling function writes i ...

CVSS3: 7.5
0%
Низкий
11 дней назад
suse-cvrf логотип
SUSE-SU-2026:3613-1

Security update for dracut

0%
Низкий
5 дней назад
suse-cvrf логотип
SUSE-SU-2026:3612-1

Security update for dracut

0%
Низкий
5 дней назад
suse-cvrf логотип
SUSE-SU-2026:3611-1

Security update for dracut

0%
Низкий
5 дней назад
suse-cvrf логотип
SUSE-SU-2026:3599-1

Security update for dracut

0%
Низкий
6 дней назад
suse-cvrf логотип
SUSE-SU-2026:3598-1

Security update for dracut

0%
Низкий
6 дней назад
rocky логотип
RLSA-2026:54576

Important: dracut security update

0%
Низкий
4 дня назад
rocky логотип
RLSA-2026:54575

Important: dracut security update

0%
Низкий
3 дня назад
rocky логотип
RLSA-2026:54571

Important: dracut security update

0%
Низкий
4 дня назад
oracle-oval логотип
ELSA-2026-54576

ELSA-2026-54576: dracut security update (IMPORTANT)

0%
Низкий
5 дней назад
oracle-oval логотип
ELSA-2026-54575

ELSA-2026-54575: dracut security update (IMPORTANT)

0%
Низкий
5 дней назад
oracle-oval логотип
ELSA-2026-54571

ELSA-2026-54571: dracut security update (IMPORTANT)

0%
Низкий
5 дней назад

Уязвимостей на страницу