rpm package
opensuse/dracut&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/dracut&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15816 | Hig | 7.5 | < 059+suse.726.gde083b3a1-160000.1.1 | 059+suse.726.gde083b3a1-160000.1.1 | Aug 7, 2026 | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent | |
| CVE-2026-6893 | Hig | 7.5 | < 059+suse.722.gdd9d67ff5-160000.1.1 | 059+suse.722.gdd9d67ff5-160000.1.1 | Jun 10, 2026 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are imp |
- affected < 059+suse.726.gde083b3a1-160000.1.1fixed 059+suse.726.gde083b3a1-160000.1.1
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent
- affected < 059+suse.722.gdd9d67ff5-160000.1.1fixed 059+suse.722.gdd9d67ff5-160000.1.1
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are imp