VYPR

dracut

by Red Hat

CVEs (3)

  • CVE-2026-15816HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent…

  • CVE-2026-16445HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module.…

  • CVE-2012-4453Oct 9, 2012
    risk 0.00cvss —epss 0.00

    dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.