PT-2026-48526 · Dracut+1 · Dracut+1

CVE-2026-6893

·

Published

2026-06-10

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dracut (affected versions not specified)
Description A flaw in the legacy DHCP path allows a remote attacker on the adjacent network to achieve root code execution within the initramfs (initial RAM file system, which is loaded with the kernel at boot to initialize the system). The issue occurs when specially crafted DHCP options, such as a malicious hostname, are improperly handled and written into temporary shell scripts without proper escaping, resulting in command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:26532
ALSA-2026:26533
ALSA-2026:26534
AZL-90111
CVE-2026-6893
OESA-2026-3136
OPENSUSE-SU-2026:11076-1
OPENSUSE-SU-2026:21054-1
OPENSUSE-SU-2026:21749-1
RHSA-2026:26532
RHSA-2026:26533
RHSA-2026:26534
RHSA-2026:26713
SUSE-SU-2026:22273-1
SUSE-SU-2026:22358-1
SUSE-SU-2026:22431-1
SUSE-SU-2026:22446-1
SUSE-SU-2026:2720-1
SUSE-SU-2026:2721-1
SUSE-SU-2026:2803-1
SUSE-SU-2026:2851-1
SUSE-SU-2026:3931-1

Affected Products

Rocky Linux
Dracut