Medium severity5.0NVD Advisory· Published Aug 1, 2018· Updated Jun 17, 2026
CVE-2016-8637
CVE-2016-8637
Description
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- Range: <045
- osv-coords9 versionspkg:rpm/opensuse/dracut&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/dracut&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2
< 044-17.1+ 8 more
- (no CPE)range: < 044-17.1
- (no CPE)range: < 037-91.1
- (no CPE)range: < 044-108.1
- (no CPE)range: < 037-91.1
- (no CPE)range: < 044-108.1
- (no CPE)range: < 037-51.31.1
- (no CPE)range: < 044-108.1
- (no CPE)range: < 037-91.1
- (no CPE)range: < 044-108.1
- Range: 045
Patches
Vulnerability mechanics
References
4- github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4nvdPatchThird Party Advisory
- seclists.org/oss-sec/2016/q4/352nvdExploitMailing ListThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/94128nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.