DEBIAN-CVE-2026-16445

Source
https://security-tracker.debian.org/tracker/CVE-2026-16445
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-16445.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-16445
Upstream
Published
2026-07-21T13:17:16Z
Modified
2026-09-21T08:47:34Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

References

Affected packages

Debian:12 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
059-4
059+212-1
059+212-2
059+212-3
059+212-4
060+5-1
060+5-2~exp1
060+5-7
060+5-8
102-1
102-2
102-3
103-1
103-2
105-1
105-2~exp1
105-2~exp2
105-2~exp3
105-2~exp4
105-2~exp5
105-2~exp6
105-2~exp7
105-2~exp8
105-2
105-3
106-1
106-2
106-3
106-4
106-5~bpo12+1
106-5
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6
112-1
112-2
112-3
112-4
112-5
112-6
103-1.*
103-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-16445.json"

Debian:13 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6
112-1
112-2
112-3
112-4
112-5
112-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-16445.json"

Debian:14 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
112-1

Affected versions

Other
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-16445.json"