CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
- Published Aug 7, 2026
- CVSS 7.5 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·