CVE-2026-16445

Published: July 22, 2026Last modified: July 28, 2026

Description

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorADJACENT_NETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Notes

We don't provide NetworkManager.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSdracutNot affected (055-r23)
25 LTSdracutNot affected (055-r34)
StreamdracutNot affected (055-r25)

References

ON THIS PAGE