Количество 11
Количество 11
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
CVE-2026-6893
Dracut: dracut: root code execution via dhcp options command injection
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network ...
RLSA-2026:26534
Important: dracut security update
RLSA-2026:26533
Important: dracut security update
RLSA-2026:26532
Important: dracut security update
GHSA-m789-mmmh-7vqc
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
ELSA-2026-26534
ELSA-2026-26534: dracut security update (IMPORTANT)
ELSA-2026-26533
ELSA-2026-26533: dracut security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6893 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-6893 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-6893 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-6893 Dracut: dracut: root code execution via dhcp options command injection | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-6893 A flaw was found in dracut. A remote attacker on the adjacent network ... | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
RLSA-2026:26534 Important: dracut security update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:26533 Important: dracut security update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:26532 Important: dracut security update | 1% Низкий | около 1 месяца назад | ||
GHSA-m789-mmmh-7vqc A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior. | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
ELSA-2026-26534 ELSA-2026-26534: dracut security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-26533 ELSA-2026-26533: dracut security update (IMPORTANT) | около 1 месяца назад |
Уязвимостей на страницу