{"id":"CVE-2026-16445","title":"A flaw was found in dracut","summary":"A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's Ne…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Red Hat","product":"dracut","affected":["dracut (all versions)","dracut (all versions)","dracut (all versions)","dracut (all versions)","dracut (all versions)","dracut (all versions)","dracut (all versions)","dracut-main (all versions)","dracut","dracut","dracut","dracut","dracut (all versions)"],"published":"2026-07-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T04:17:22.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16445","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:26534","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:40700","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:61252","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69118","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:69119","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-16445","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2459963","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2503147","label":"secalert@redhat.com"},{"url":"https://github.com/dracutdevs/dracut/commit/e509c638e6","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16445.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16445"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16445"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-07-22T17:58:44.376796Z"},"epss":0.01117,"epssPercentile":0.64644,"ingestedAt":"2026-08-31T05:03:01.503Z","patched":["enterprise_linux_baseos_v_8","enterprise_linux_baseos_aus_v_8_4","enterprise_linux_baseos_eus_extension_v_8_4","enterprise_linux_baseos_aus_v_8_6","enterprise_linux_baseos_eus_extension_v_8_6","enterprise_linux_baseos_e4s_v_8_8","enterprise_linux_baseos_tus_v_8_8","hardened_images"],"slug":"CVE-2026-16445","body":"## Overview\n\nA flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:26534** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-06-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:26534)\n- **RHSA-2026:69118** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69118)\n- **RHSA-2026:69119** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69119)\n- **RHSA-2026:61252** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61252)\n- **RHSA-2026:40700** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:40700)\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-16445.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}