{"schema_version":"1.7.2","id":"OESA-2026-3474","modified":"2026-08-20T10:00:51Z","published":"2026-08-20T10:00:51Z","upstream":["CVE-2026-15816"],"summary":"dracut security update","details":"dracut contains tools to create bootable initramfses for the Linux kernel. Unlike previous implementations, dracut hard-codes as little as possible into the initramfs. dracut contains various modules which are driven by the event-based udev. Having root on MD, DM, LVM2, LUKS is supported as well as NFS, iSCSI, NBD, FCoE with the dracut-network package.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.(CVE-2026-15816)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"dracut","purl":"pkg:rpm/openEuler/dracut&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"059-18.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["dracut-059-18.oe2403sp4.aarch64.rpm","dracut-caps-059-18.oe2403sp4.aarch64.rpm","dracut-config-generic-059-18.oe2403sp4.aarch64.rpm","dracut-config-rescue-059-18.oe2403sp4.aarch64.rpm","dracut-debuginfo-059-18.oe2403sp4.aarch64.rpm","dracut-debugsource-059-18.oe2403sp4.aarch64.rpm","dracut-live-059-18.oe2403sp4.aarch64.rpm","dracut-network-059-18.oe2403sp4.aarch64.rpm","dracut-squash-059-18.oe2403sp4.aarch64.rpm","dracut-tools-059-18.oe2403sp4.aarch64.rpm"],"src":["dracut-059-18.oe2403sp4.src.rpm"],"x86_64":["dracut-059-18.oe2403sp4.x86_64.rpm","dracut-caps-059-18.oe2403sp4.x86_64.rpm","dracut-config-generic-059-18.oe2403sp4.x86_64.rpm","dracut-config-rescue-059-18.oe2403sp4.x86_64.rpm","dracut-debuginfo-059-18.oe2403sp4.x86_64.rpm","dracut-debugsource-059-18.oe2403sp4.x86_64.rpm","dracut-live-059-18.oe2403sp4.x86_64.rpm","dracut-network-059-18.oe2403sp4.x86_64.rpm","dracut-squash-059-18.oe2403sp4.x86_64.rpm","dracut-tools-059-18.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3474"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15816"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"database_specific":{"severity":"High"}}
