<Vulnerability name="CVE-2026-6893">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-10T19:39:00</PublicDate>
    <Bugzilla id="2459963" url="https://bugzilla.redhat.com/show_bug.cgi?id=2459963" xml:lang="en:us">
dracut: dracut: Root code execution via DHCP options command injection
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-78</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
    </Details>
    <Statement xml:lang="en:us">
This is an Important vulnerability in dracut's legacy DHCP client script (`dhclient-script.sh`) that allows command injection. An attacker on the adjacent network can exploit this by providing specially crafted DHCP options, leading to root code execution within the initramfs. This primarily affects systems configured to use DHCP for network setup during the initial boot phase.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank AISLE Research for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, ensure that systems configured to obtain network settings via DHCP in the initramfs are only booted on trusted networks. This vulnerability requires an attacker to control a DHCP server on the adjacent network segment. If network configuration via DHCP is not strictly necessary during the initramfs phase, consider using static network configuration.
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26532">RHSA-2026:26532</Advisory>
        <Package name="dracut">dracut-0:107-7.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-08-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:57580">RHSA-2026:57580</Advisory>
        <Package name="dracut">dracut-0:105-4.el10_0.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_els:7">
        <ProductName>Red Hat Enterprise Linux 7 Extended Lifecycle Support</ProductName>
        <ReleaseDate>2026-09-01T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:62269">RHSA-2026:62269</Advisory>
        <Package name="dracut">dracut-0:033-577.el7_9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26534">RHSA-2026:26534</Advisory>
        <Package name="dracut">dracut-0:049-244.git20260529.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_tus:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-08-31T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:61252">RHSA-2026:61252</Advisory>
        <Package name="dracut">dracut-0:049-223.git20230119.el8_8.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_e4s:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-08-31T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:61252">RHSA-2026:61252</Advisory>
        <Package name="dracut">dracut-0:049-223.git20230119.el8_8.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26533">RHSA-2026:26533</Advisory>
        <Package name="dracut">dracut-0:057-115.git20260527.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26533">RHSA-2026:26533</Advisory>
        <Package name="dracut">dracut-0:057-115.git20260527.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-08-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:57775">RHSA-2026:57775</Advisory>
        <Package name="dracut">dracut-0:057-25.git20250717.el9_2.2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-08-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:57785">RHSA-2026:57785</Advisory>
        <Package name="dracut">dracut-0:057-54.git20250423.el9_4.3</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-08-20T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:57772">RHSA-2026:57772</Advisory>
        <Package name="dracut">dracut-0:057-89.git20250311.el9_6.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift:4.16::el9">
        <ProductName>Red Hat OpenShift Container Platform 4.16</ProductName>
        <ReleaseDate>2026-09-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:62549">RHSA-2026:62549</Advisory>
        <Package name="rhcos">rhcos-416.94.202609011112-0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift:4.19::el9">
        <ProductName>Red Hat OpenShift Container Platform 4.19</ProductName>
        <ReleaseDate>2026-09-09T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63044">RHSA-2026:63044</Advisory>
        <Package name="rhcos">rhcos-4.19.9.6.202609021231-0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26713">RHSA-2026:26713</Advisory>
        <Package name="dracut-main">dracut-main-109-6.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Affected</FixState>
        <PackageName>dracut</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift/ose-rhel-coreos-8</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-6893
https://nvd.nist.gov/vuln/detail/CVE-2026-6893
    </References>
</Vulnerability>