RHSA-2026:57775: Important: dracut security update
Important: dracut security update
Other sources
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.Security Fix(es): dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2 - Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 057-25.git20250717.el9_2.2.aa - Compensating control
Apply the dracut security update described in the Red Hat advisory referenced as access.redhat.com/articles/11258 to address dracut root code execution issues (CVE-2026-15816 and CVE-2026-6893).
Event History
Frequently Asked Questions
Which installed packages should be included in the remediation inventory?
Inventory dracut, dracut-caps, dracut-config-generic, dracut-config-rescue, dracut-debuginfo, dracut-debugsource, dracut-live, and dracut-network. The advisory identifies these as the affected software packages.
What level of access could successful exploitation provide?
Both listed fixes concern root code execution. One issue is triggered through DHCP options command injection, and the other involves an unescaped error message written into an emergency hook script that is sourced by dracut's die() function.
What exploitation prerequisites are specified for these issues?
The provided advisory identifies the affected input paths but does not specify the network, configuration, or local-access prerequisites needed to exploit them. It also does not state whether a default dracut configuration is affected.