Executive brief
A vulnerability in dracut, a tool used to generate the initial boot environment for Linux systems, allows an attacker on the same local network to take full control of a system during its boot process. By sending malicious network configuration data (DHCP options), an attacker can execute commands with root privileges before the operating system has even finished loading. This could lead to complete system compromise, data theft, or persistent backdoors on affected servers and workstations.
Technical details
A command injection vulnerability exists in dracut's NetworkManager-based and legacy dhclient-script.sh initrd network modules. The flaw is caused by improper neutralization of special elements in DHCP-provided values (such as root-path, next-server, or host-name) before they are written into temporary shell scripts. These scripts are subsequently sourced as root during the initramfs stage of the boot process. An attacker on the adjacent network (Layer 2) can provide specially crafted DHCP options containing shell metacharacters to achieve arbitrary code execution with root privileges within the initramfs. Red Hat has released patches for affected versions of RHEL 8 and OpenShift.
Affected products
- Red Hat dracut Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4
Timeline
- 2026-04-21: disclosed: Initial report to Red Hat maintainers
- 2026-06-17: patched: Red Hat released security advisory RHSA-2026:26534
- 2026-07-21: advisory: NVD publication date
References
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2026:26534
- https://access.redhat.com/security/cve/CVE-2026-16445
- https://bugzilla.redhat.com/show_bug.cgi?id=2459963
- https://bugzilla.redhat.com/show_bug.cgi?id=2503147
- https://github.com/dracutdevs/dracut/commit/e509c638e6