CVE 8.8 HIGH

Dracut: dracut: root code execution via dhcp options command injection_CVE-2026-6893

8.8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

AI Analysis

Command injection vulnerability in dracut via DHCP options

Basic Information

ID CVE-2026-6893
Source redhat
Published Jun 10, 2026 at 19:49

Affected Product

Vendor Red Hat
Product Red Hat Enterprise Linux 10

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Red Hat
Product dracut

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.