rpm package
almalinux/dracut-live
pkg:rpm/almalinux/dracut-live
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15816 | Hig | 7.5 | < 057-120.git20260728.el9_8 | 057-120.git20260728.el9_8 | Aug 7, 2026 | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent | |
| CVE-2026-6893 | Hig | 7.5 | < 107-7.el10_2 | 107-7.el10_2 | Jun 10, 2026 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are imp |
- affected < 057-120.git20260728.el9_8fixed 057-120.git20260728.el9_8
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent
- affected < 107-7.el10_2fixed 107-7.el10_2
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are imp