dracut-049-244.git20260529.el8_10
エラータID: AXSA:2026-806:01
The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition.
Security Fix(es):
* dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-6893
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
Update packages.
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.
N/A
SRPMS
- dracut-049-244.git20260529.el8_10.src.rpm
MD5: 8c13398b05772fe42bc3f9e6399c5d58
SHA-256: 01c09a1fe610e4875ecd1e7097f08a31a5b57f80482494205981e86c5b4a5f7b
Size: 578.09 kB
Asianux Server 8 for x86_64
- dracut-049-244.git20260529.el8_10.x86_64.rpm
MD5: 6d14a1a735305b9979cf97c526b21dd8
SHA-256: 968382971efdfc2d7e105b0c9ac2e6ea0c459a711af0677a8908811b5a9e9a1a
Size: 380.04 kB - dracut-caps-049-244.git20260529.el8_10.x86_64.rpm
MD5: 45cd894b0d6df9543d50fe24597d414f
SHA-256: 251554adffd91c8caa8d2e1f43561635af6c47b4c3cbe1bfa994eb69b612d8b8
Size: 63.42 kB - dracut-config-generic-049-244.git20260529.el8_10.x86_64.rpm
MD5: aebe8d8cd6d6f402ac354637236e950c
SHA-256: 1a2cdaf5407b4e742d78ba2772eacfd4a90194e15043f12cdd8be4257d52fc8c
Size: 61.72 kB - dracut-config-rescue-049-244.git20260529.el8_10.x86_64.rpm
MD5: 5a9d2a9affafb70e87c6a60376688382
SHA-256: a7bed674edc5270c91b3d3f1c4c9f626769108c413e4aa190e7e100ad581e51f
Size: 63.13 kB - dracut-live-049-244.git20260529.el8_10.x86_64.rpm
MD5: 887f4c5277c2813ff2dff3fa6a6b3597
SHA-256: 524927fd30b560093e07de39716a267b3fed7271d78c437dd77baa66ec24ccaa
Size: 72.97 kB - dracut-network-049-244.git20260529.el8_10.x86_64.rpm
MD5: fb8c5a621257467d028e65071b6f4983
SHA-256: 646baaacbb2590815bd2ff2a4451c3877a53718bd1a680598478833687bc4cea
Size: 111.19 kB - dracut-squash-049-244.git20260529.el8_10.x86_64.rpm
MD5: 1df55bfb7e8ff9401ee82e9c84552b4c
SHA-256: 43547b90776d82c3d28ebcc1cae8eaac9fe65a9f4b7575afe8c2dbad3d7d7caf
Size: 63.48 kB - dracut-tools-049-244.git20260529.el8_10.x86_64.rpm
MD5: 0797f31f29f344f766a4729930f33cd5
SHA-256: bd41fe478be22ed528256948e2111ba5906d74d16e89d9fdfdb650438f243a95
Size: 64.56 kB