216.73.217.22

CVE-2026-6893

· Published 10/06/2026 20:17 · Modified 10/06/2026 20:22

Labels: CVE-2026-6893 2026-06-10CVE-2026-6893CWE-78[email protected]

Essential information

Published
10/06/2026 20:17
Modified
10/06/2026 20:22
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redhat / dracut cpe:2.3:a:redhat:dracut:*:*:*:*:*:*:*:*

References