REDHAT-BUG-2500889: High severity dracut vulnerability
A flaw was found in dracut. The die() function in dracut-lib.sh appends its error message to $hookdir/emergency/01-die.sh using echo "warn dracut: FATAL: \"$\"", without shell-quoting the message. When the message passed to die() contains DHCP-controlled data -- specifically $netroot, derived from the DHCP ROOTPATH option via netroot.sh's handler-resolution failure path (die "No handler for netroot type '$netroot'") -- a command-substitution sequence such as $(cmd) embedded in that data survives into the generated 01-die.sh line and executes as root the next time dracut sources the emergency hook directory. This occurs during dracut's standard boot-failure handling: when the netroot handler cannot be resolved, dracut's initqueue-timeout fallback (or, on non-default rd.shell configurations, die() itself) eventually invokes emergencyshell(), which sources every script under $hookdir/emergency/, including the attacker-poisoned 01-die.sh. This is a distinct code path from CVE-2026-6893 (dhclient-script.sh writing unescaped DHCP hostname/route values); CVE-2026-6893's fix does not touch die() and does not remediate this issue. Reproduced directly against die() extracted from shipped dracut RPMs spanning RHEL 6 through RHEL 10 in an isolated sandbox: a crafted netroot value containing $(touch /tmp/marker) created the marker file upon sourcing the generated 01-die.sh, while a clean/benign netroot value round-tripped with identical warning text in every version tested. Replacing the manual echo/quoting with printf '%q' was verified to neutralize the injection while preserving identical warning output for benign input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In dracut-lib.sh, modify die() so the error message appended to "$hookdir/emergency/01-die.sh" is shell-quoted (use printf '%q' for the message) instead of writing unquoted data via echo. This prevents command-substitution sequences (e.g., $(...)) present in the message (such as $netroot) from executing when the emergency directory is later sourced as root.
dracut die() / dracut-lib.sh (emergency hook 01-die.sh generation) echo = Replace echo "warn dracut: FATAL: \"$*\"" with printf '%q' quoting for the message before writing into $hookdir/emergency/01-die.sh