{"schema_version":"1.7.2","id":"OESA-2026-3300","modified":"2026-08-07T02:44:54Z","published":"2026-08-07T02:44:54Z","upstream":["CVE-2026-16445"],"summary":"dracut security update","details":"dracut contains tools to create bootable initramfses for the Linux kernel. Unlike previous implementations, dracut hard-codes as little as possible into the initramfs. dracut contains various modules which are driven by the event-based udev. Having root on MD, DM, LVM2, LUKS is supported as well as NFS, iSCSI, NBD, FCoE with the dracut-network package.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut&apos;s NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.(CVE-2026-16445)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"dracut","purl":"pkg:rpm/openEuler/dracut&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"050-12.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["dracut-050-12.oe2003sp4.aarch64.rpm","dracut-caps-050-12.oe2003sp4.aarch64.rpm","dracut-config-generic-050-12.oe2003sp4.aarch64.rpm","dracut-config-rescue-050-12.oe2003sp4.aarch64.rpm","dracut-debuginfo-050-12.oe2003sp4.aarch64.rpm","dracut-debugsource-050-12.oe2003sp4.aarch64.rpm","dracut-live-050-12.oe2003sp4.aarch64.rpm","dracut-network-050-12.oe2003sp4.aarch64.rpm","dracut-squash-050-12.oe2003sp4.aarch64.rpm","dracut-tools-050-12.oe2003sp4.aarch64.rpm"],"src":["dracut-050-12.oe2003sp4.src.rpm"],"x86_64":["dracut-050-12.oe2003sp4.x86_64.rpm","dracut-caps-050-12.oe2003sp4.x86_64.rpm","dracut-config-generic-050-12.oe2003sp4.x86_64.rpm","dracut-config-rescue-050-12.oe2003sp4.x86_64.rpm","dracut-debuginfo-050-12.oe2003sp4.x86_64.rpm","dracut-debugsource-050-12.oe2003sp4.x86_64.rpm","dracut-live-050-12.oe2003sp4.x86_64.rpm","dracut-network-050-12.oe2003sp4.x86_64.rpm","dracut-squash-050-12.oe2003sp4.x86_64.rpm","dracut-tools-050-12.oe2003sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3300"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16445"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"database_specific":{"severity":"High"}}
