RHSA-2026:57580: Important: dracut security update
Important: dracut security update
Other sources
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.Security Fix(es): dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1 - Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 105-4.el10_0.1.aa - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Patch CVE-2026-15816 - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Patch CVE-2026-6893
Event History
Frequently Asked Questions
Which RHEL environments are covered by this update?
The update covers Red Hat Enterprise Linux for x86_64, ARM 64, IBM z Systems, and Power little endian systems in both the listed 4-year updates and Extended Update Support channels.
How urgent is this update?
The advisory is classified as Important and has a high severity rating of 7. It was published and last modified on 2026-08-20.