VYPR

dracut

by Dracutdevs

Source repositories

CVEs (2)

  • CVE-2026-16445HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module.…

  • CVE-2016-8637MedAug 1, 2018
    risk 0.26cvss 5.0epss 0.00

    A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files,…