High severity7.5NVD Advisory· Published Aug 7, 2026· Updated Sep 21, 2026
CVE-2026-15816
CVE-2026-15816
Description
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- osv-coords10 versionspkg:rpm/almalinux/dracutpkg:rpm/almalinux/dracut-capspkg:rpm/almalinux/dracut-config-genericpkg:rpm/almalinux/dracut-config-rescuepkg:rpm/almalinux/dracut-livepkg:rpm/almalinux/dracut-networkpkg:rpm/almalinux/dracut-squashpkg:rpm/almalinux/dracut-toolspkg:rpm/opensuse/dracut&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/dracut&distro=openSUSE%20Tumbleweed
< 057-120.git20260728.el9_8+ 9 more
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 057-120.git20260728.el9_8
- (no CPE)range: < 059+suse.726.gde083b3a1-160000.1.1
- (no CPE)range: < 112+suse.29.gc0c5e1d-1.1
Patches
Vulnerability mechanics
References
25- access.redhat.com/errata/RHSA-2026:54571nvd
- access.redhat.com/errata/RHSA-2026:54575nvd
- access.redhat.com/errata/RHSA-2026:54576nvd
- access.redhat.com/errata/RHSA-2026:57580nvd
- access.redhat.com/errata/RHSA-2026:57772nvd
- access.redhat.com/errata/RHSA-2026:57775nvd
- access.redhat.com/errata/RHSA-2026:57785nvd
- access.redhat.com/errata/RHSA-2026:60440nvd
- access.redhat.com/errata/RHSA-2026:60445nvd
- access.redhat.com/errata/RHSA-2026:61252nvd
- access.redhat.com/errata/RHSA-2026:62269nvd
- access.redhat.com/errata/RHSA-2026:62409nvd
- access.redhat.com/errata/RHSA-2026:62549nvd
- access.redhat.com/errata/RHSA-2026:63041nvd
- access.redhat.com/errata/RHSA-2026:63044nvd
- access.redhat.com/errata/RHSA-2026:65839nvd
- access.redhat.com/errata/RHSA-2026:65851nvd
- access.redhat.com/errata/RHSA-2026:66357nvd
- access.redhat.com/errata/RHSA-2026:69118nvd
- access.redhat.com/errata/RHSA-2026:69119nvd
- access.redhat.com/security/cve/CVE-2026-15816nvd
- bugzilla.redhat.com/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/dracutdevs/dracut/blob/master/modules.d/40network/netroot.shnvd
- github.com/dracutdevs/dracut/blob/master/modules.d/99base/dracut-lib.shnvd
News mentions
0No linked articles in our index yet.