Junglewise Threat Intelligence

CVE-2026-6893: dracut command injection in legacy DHCP path

CVE-2026-6893 · Severity: high · CVSS 8.8 · Published 2026-06-10

Executive brief

A security vulnerability exists in dracut, a tool used by Linux systems to manage the initial boot process. An attacker on the same local network can send malicious network configuration data (DHCP) to a booting system, allowing them to take full control of the computer before the operating system even finishes starting up. This could lead to a complete system compromise, data theft, or permanent disruption of the server's operations.

Technical details

A command injection vulnerability exists in dracut's legacy DHCP module (`modules.d/35network-legacy/dhclient-script.sh`). The root cause is the improper neutralization of shell metacharacters in DHCP-provided values, such as the hostname and routing options. These values are written directly into temporary shell scripts in `/tmp/` without escaping and are subsequently sourced as root by the initramfs during the boot process. An attacker on the adjacent network (L2 segment) can provide a malicious DHCP response containing shell commands (e.g., in the `host-name` field) to achieve arbitrary code execution as root. This affects systems configured to use `ip=dhcp` or `rd.neednet=1` with the legacy network path.

Affected products

  • dracut dracut 107-4.el10 and earlier versions using legacy DHCP path

Timeline

  • 2026-04-21: disclosed: Vulnerability reported to Red Hat Bugzilla
  • 2026-06-10: advisory: NVD and Red Hat published advisory details

References