Command Injection Vulnerability in Dracut Affecting Red Hat Systems
CVE-2026-6893
7.5HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 10 June 2026
What is CVE-2026-6893?
A command injection vulnerability exists in Dracut that can be exploited by remote attackers on adjacent networks. By supplying specially crafted DHCP options, such as a malicious hostname, the vulnerability is triggered. The improper handling of these options allows them to be written into temporary shell scripts without adequate escaping, leading to potential command execution as root within the initramfs environment. This could allow attackers to compromise critical system components, including boot and network functionalities.
Affected Version(s)
Red Hat Enterprise Linux 10 0:107-7.el10_2
Red Hat Enterprise Linux 8 0:049-244.git20260529.el8_10
Red Hat Enterprise Linux 9 0:057-115.git20260527.el9_8