USN-8758-1: dracut vulnerability
Ubuntu patches dracut CVE-2026-15816, where a rogue adjacent-network DHCP server can inject root-executed commands during boot-failure handling.
Ubuntu security notice USN-8758-1 fixes CVE-2026-15816 in dracut, where messages written by the die() function to the emergency hook directory are not properly shell-quoted. An attacker on an adjacent network controlling a rogue DHCP server could exploit this to inject commands executing as root during boot-failure handling. Users should apply the patched dracut package.
- CVE-2026-15816: dracut fails to shell-quote die() messages
- Rogue adjacent-network DHCP server enables root command injection at boot-failure
- Fix shipped via Ubuntu security notice USN-8758-1
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15816 | A flaw was found in dracut. A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. NVD description · AI analysis pending | 7.5 | <1% | — | — |
It was discovered that dracut did not properly shell-quote messages written by the die() function to the emergency hook directory. An attacker on the adjacent network controlling a rogue DHCP server could use this issue to inject commands that execute as root during boot-failure handling. (CVE-2026-15816)
This source does not provide full text. Read it at ubuntu.com.