RHSA-2026:61252: Important: dracut security update
Important: dracut security update
Other sources
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.Security Fix(es): dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) dracut: dracut: Root code execution via DHCP options command injection in NetworkManager initrd module (CVE-2026-16445) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 049-223.git20230119.el8_8.1 - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Patch CVE-2026-6893 - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Patch CVE-2026-16445 - Upgrade
Upgrade
dracutto a version that resolves this vulnerability.Patch CVE-2026-15816
Event History
Frequently Asked Questions
Which systems are most exposed to the DHCP-related issues?
Systems whose initramfs uses networking and obtains configuration through DHCP are the relevant exposure group for the DHCP option command-injection issues. The affected components include dracut-network and the NetworkManager initrd module.
What does an attacker need to exploit the DHCP-related vulnerabilities?
An attacker would need to supply or control DHCP options processed during initramfs networking. Successful exploitation can result in code execution as root.
How can I identify systems that may need this update?
Check for installed dracut packages named in the advisory, including dracut, dracut-network, dracut-caps, dracut-config-generic, dracut-config-rescue, dracut-live, dracut-debuginfo, and dracut-debugsource. Systems with these packages should be reviewed against RHSA-2026:61252.