Dracut · Dracut · CVE-2026-16445
**Name of the Vulnerable Software and Affected Versions**
dracut (affected versions not specified)
**Description**
A flaw in the NetworkManager-based initrd network module allows a remote attacker on the adjacent network to achieve root code execution within the initramfs during system boot. The issue occurs when specially crafted DHCP options, such as `root-path`, `next-server`, or `bootfile name`, are improperly handled and written into a temporary shell script without proper escaping, resulting in command injection.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.