PT-2026-68894 · Dracut+1 · Dracut+1

·

CVE-2026-15816

·

Published

2026-08-05

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dracut (affected versions not specified)
Description A flaw exists in the die() error-handling function which writes messages into a shell script within the initramfs emergency-hook directory without proper shell-quoting. An attacker on the adjacent network controlling a rogue DHCP server can exploit this by providing malicious data via the DHCP ROOT PATH option. This allows the injection of a command-substitution sequence that executes with root privileges when dracut sources its emergency hook scripts during standard boot-failure handling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54571
ALSA-2026:54575
ALSA-2026:54576
CVE-2026-15816
OESA-2026-3472
OESA-2026-3473
OESA-2026-3474
OESA-2026-3500
OESA-2026-3501
OPENSUSE-SU-2026:11504-1
OPENSUSE-SU-2026:21639-1
RHSA-2026:54571
RHSA-2026:54575
RHSA-2026:54576
RHSA-2026:57580
RHSA-2026:57772
RHSA-2026:57775
RHSA-2026:57785
RHSA-2026:61252
RHSA-2026:62269
SUSE-SU-2026:23195-1
SUSE-SU-2026:23246-1
SUSE-SU-2026:23276-1
SUSE-SU-2026:23314-1
SUSE-SU-2026:3598-1
SUSE-SU-2026:3599-1
SUSE-SU-2026:3611-1
SUSE-SU-2026:3612-1
SUSE-SU-2026:3613-1

Affected Products

Rocky Linux
Dracut