Linuxsecurity Critical dracut Security Updates for Oracle Linux 9 and 10 Released
Article Content
- •Oracle released critical dracut updates for Oracle Linux 9 and 10 on August 15, 2026.
- •The updates address vulnerabilities that may lead to privilege escalation and system damage.
- •System administrators should audit Linux privileges and apply updates immediately.
On August 15, 2026, Oracle released important security updates for dracut in Oracle Linux 9 and 10. Both updates address vulnerabilities that could allow privilege escalation and system-wide damage. The updates include fixes for issues such as permission errors during upgrades and logic for FIPS compliance. The affected versions are dracut-057-120.git20260728.0.1 for Oracle Linux 9 and dracut-107-9.0.1 for Oracle Linux 10. Users are advised to audit Linux privileges to mitigate potential compromises. The updates also include enhancements to the integrity management features. Specific bugs were tracked under various Orabug IDs, indicating a thorough review process. System administrators are urged to apply these updates promptly to secure their environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-15816 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical dracut Command Injection Vulnerability in Ubuntu A vulnerability (CVE-2026-15816) was discovered in dracut, an initramfs image generation tool, affecting Ubuntu 26.04 LTS. The flaw allows an attacker on an adjacent network with control over a rogue DHCP server to inject commands that execute as root during boot-failure handling. This vulnerability arises from…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…