CVE-2026-6893

NameCVE-2026-6893
DescriptionA flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dracut (PTS)bullseye051-1vulnerable
bookworm059-4vulnerable
trixie106-6vulnerable
forky, sid111-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dracutsource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2459963
check upstream status, as only reference is Red Hat bugzilla entry

Search for package or bug name: Reporting problems