Command Injection Vulnerability in Dracut Affecting Red Hat Systems
CVE-2026-6893

7.5HIGH

What is CVE-2026-6893?

A command injection vulnerability exists in Dracut that can be exploited by remote attackers on adjacent networks. By supplying specially crafted DHCP options, such as a malicious hostname, the vulnerability is triggered. The improper handling of these options allows them to be written into temporary shell scripts without adequate escaping, leading to potential command execution as root within the initramfs environment. This could allow attackers to compromise critical system components, including boot and network functionalities.

Affected Version(s)

Red Hat Enterprise Linux 10 0:107-7.el10_2

Red Hat Enterprise Linux 8 0:049-244.git20260529.el8_10

Red Hat Enterprise Linux 9 0:057-115.git20260527.el9_8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.