Executive brief
A security vulnerability exists in dracut, a tool used by Linux systems to manage the initial boot process. An attacker on the same local network can send malicious network configuration data (DHCP) to a booting system, allowing them to take full control of the computer before the operating system even finishes starting up. This could lead to a complete system compromise, data theft, or permanent disruption of the server's operations.
Technical details
A command injection vulnerability exists in dracut's legacy DHCP module (`modules.d/35network-legacy/dhclient-script.sh`). The root cause is the improper neutralization of shell metacharacters in DHCP-provided values, such as the hostname and routing options. These values are written directly into temporary shell scripts in `/tmp/` without escaping and are subsequently sourced as root by the initramfs during the boot process. An attacker on the adjacent network (L2 segment) can provide a malicious DHCP response containing shell commands (e.g., in the `host-name` field) to achieve arbitrary code execution as root. This affects systems configured to use `ip=dhcp` or `rd.neednet=1` with the legacy network path.
Affected products
- dracut dracut 107-4.el10 and earlier versions using legacy DHCP path
Timeline
- 2026-04-21: disclosed: Vulnerability reported to Red Hat Bugzilla
- 2026-06-10: advisory: NVD and Red Hat published advisory details