Linuxsecurity
SUSE Dracut Vulnerabilities Enable Root Code Execution
Article Content
SUSE has released updates addressing two critical vulnerabilities in the dracut tool, identified as CVE-2026-6893 and CVE-2026-16445. Both vulnerabilities allow for root code execution via DHCP options command injection, affecting various SUSE Linux systems. The vulnerabilities were disclosed on June 10 and July 21, 2026, respectively. The updates sanitize values written to temporary files to mitigate the risks. The affected systems include SUSE Linux Enterprise Desktop 15 SP7, SUSE Linux Enterprise Server 15 SP7, and others. Administrators are advised to apply the patches using SUSE's recommended installation methods. The vulnerabilities have CVSS scores of 8.7 and 7.5, indicating significant risk. The updates were released on September 2 and September 3, 2026, with a rating of 'important'. Current status indicates that the vulnerabilities are patched, but administrators must act promptly to secure their systems.
Key Points: • Two critical vulnerabilities in SUSE's dracut tool allow root code execution. • Affected systems include SUSE Linux Enterprise Desktop and Server 15 SP7. • Patches are available; administrators should apply them immediately.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.