DEBIAN-CVE-2026-6893

Source
https://security-tracker.debian.org/tracker/CVE-2026-6893
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-6893.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-6893
Upstream
  • CVE-2026-6893
Published
2026-06-10T20:17:29Z
Modified
2026-09-19T22:47:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

References

Affected packages

Debian:12 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
059-4
059+212-1
059+212-2
059+212-3
059+212-4
060+5-1
060+5-2~exp1
060+5-7
060+5-8
102-1
102-2
102-3
103-1
103-2
105-1
105-2~exp1
105-2~exp2
105-2~exp3
105-2~exp4
105-2~exp5
105-2~exp6
105-2~exp7
105-2~exp8
105-2
105-3
106-1
106-2
106-3
106-4
106-5~bpo12+1
106-5
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6
112-1
112-2
112-3
112-4
112-5
112-6
103-1.*
103-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-6893.json"

Debian:13 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6
112-1
112-2
112-3
112-4
112-5
112-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-6893.json"

Debian:14 / dracut

Package

Name
dracut
Purl
pkg:deb/debian/dracut?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
112-1

Affected versions

Other
106-6
107-1
107-2
108-1
108-2
108-3
108-4
108-5
108-6
108-7
108-8
109-1
109-1exp1
109-2
109-3
109-4
109-5
109-6
109-6exp1
109-6exp2
109-6exp3
109-7
109-8
109-9
109-10
109-11
110-1
110-2
110-3
110-4
110-5
110-6
110-7
110-8
110-9
110-10
110-11
110-12
111-1
111-2
111-3
111-4
111-5
111-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-6893.json"