Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

github логотип

GHSA-m789-mmmh-7vqc

около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6893

около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-6893

около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-6893

около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-6893

около 2 месяцев назад

Dracut: dracut: root code execution via dhcp options command injection

EPSS: Низкий
debian логотип

CVE-2026-6893

около 2 месяцев назад

A flaw was found in dracut. A remote attacker on the adjacent network ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21054-1

около 1 месяца назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2851-1

22 дня назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2803-1

23 дня назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2721-1

около 1 месяца назад

Security update for dracut

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2720-1

около 1 месяца назад

Security update for dracut

EPSS: Низкий
rocky логотип

RLSA-2026:26534

около 1 месяца назад

Important: dracut security update

EPSS: Низкий
rocky логотип

RLSA-2026:26533

около 1 месяца назад

Important: dracut security update

EPSS: Низкий
rocky логотип

RLSA-2026:26532

около 1 месяца назад

Important: dracut security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26534

около 2 месяцев назад

ELSA-2026-26534: dracut security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26533

около 1 месяца назад

ELSA-2026-26533: dracut security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26532

12 дней назад

ELSA-2026-26532: dracut security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m789-mmmh-7vqc

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-6893

Dracut: dracut: root code execution via dhcp options command injection

1%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network ...

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21054-1

Security update for dracut

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2851-1

Security update for dracut

1%
Низкий
22 дня назад
suse-cvrf логотип
SUSE-SU-2026:2803-1

Security update for dracut

1%
Низкий
23 дня назад
suse-cvrf логотип
SUSE-SU-2026:2721-1

Security update for dracut

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2720-1

Security update for dracut

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26534

Important: dracut security update

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26533

Important: dracut security update

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26532

Important: dracut security update

1%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-26534

ELSA-2026-26534: dracut security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-26533

ELSA-2026-26533: dracut security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-26532

ELSA-2026-26532: dracut security update (IMPORTANT)

12 дней назад

Уязвимостей на страницу