Back Linuxsecurity Ubuntu 26.04 LTS dracut Critical Command Injection Vulnerability USN-8758
Artifactory Alert: Chained flaws let attackers gain admin control. Check your version now ×
Several security issues were fixed in dracut. Software Description: - dracut: Initramfs image generation tool Details: It was discovered that dracut did not properly shell-quote messages written by the die() function to the emergency hook directory. An attacker on the adjacent network controlling a rogue DHCP server could use this issue to inject commands that execute as root during boot-failure handling. (CVE-2026-15816)
Several security issues were fixed in dracut.
Software Description:
- dracut: Initramfs image generation tool
It was discovered that dracut did not properly shell-quote messages
written by the die() function to the emergency hook directory. An
attacker on the adjacent network controlling a rogue DHCP server could
use this issue to inject commands that execute as root during
boot-failure handling. (CVE-2026-15816)
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS dracut-core 110-11ubuntu0.1 dracut-network 110-11ubuntu0.1 After a standard system update you need to reboot your computer to make all the necessary changes.
Ubuntu Security Notice USN-8758-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
