RHSA-2026:54571: Important: dracut security update
Important: dracut security update
Other sources
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.Security Fix(es): dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8 - Upgrade
Upgrade
redhat/dracutto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-capsto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-config-genericto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-config-rescueto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-debuginfoto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-debugsourceto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-liveto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-networkto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-squashto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa - Upgrade
Upgrade
redhat/dracut-toolsto a version that resolves this vulnerability.Fixed in 057-120.git20260728.el9_8.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54571?
The severity of RHSA-2026:54571 is rated as high with a score of 7.
How do I fix RHSA-2026:54571?
To fix RHSA-2026:54571, update the vulnerable dracut packages to the latest version provided by Red Hat.
What does RHSA-2026:54571 address?
RHSA-2026:54571 addresses security vulnerabilities in the dracut packages related to the initial RAM file system generation.
What systems are affected by RHSA-2026:54571?
The systems affected by RHSA-2026:54571 include any running the vulnerable versions of dracut and its associated packages on Red Hat.
When was RHSA-2026:54571 published?
RHSA-2026:54571 was published on August 13, 2026.