PT-2026-61935 · Dracut · Dracut

·

CVE-2026-16445

·

Published

2026-07-21

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dracut (affected versions not specified)
Description A flaw in the NetworkManager-based initrd network module allows a remote attacker on the adjacent network to achieve root code execution within the initramfs during system boot. The issue occurs when specially crafted DHCP options, such as root-path, next-server, or bootfile name, are improperly handled and written into a temporary shell script without proper escaping, resulting in command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16445
OESA-2026-3300
OESA-2026-3301
OPENSUSE-SU-2026:11657-1
OPENSUSE-SU-2026:21749-1
RHSA-2026:26534
RHSA-2026:40700
SUSE-SU-2026:3931-1

Affected Products

Dracut