USN-8828-1

Source
https://ubuntu.com/security/notices/USN-8828-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8828-1
Upstream
CVE (4)
Related
Published
2026-09-28T13:33:37Z
Modified
2026-09-28T22:57:43Z
Summary
dracut vulnerabilities
Details

It was discovered that dracut created initramfs images with overly permissive permissions under certain circumstances. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-8637)

It was discovered that dracut did not properly sanitize DHCP options before writing them to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)

It was discovered that dracut did not properly quote error messages written to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-15816)

It was discovered that dracut did not properly sanitize network configuration data before writing it to a temporary shell script under certain circumstances. A remote attacker controlling DHCP on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 22.04 LTS. (CVE-2026-16445)

References

Affected packages

Ubuntu:24.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
060+5-1ubuntu3.4

Affected versions

Other
059-4ubuntu2
060+5-1ubuntu1
060+5-1ubuntu2
060+5-1ubuntu3
060+5-1ubuntu3.*
060+5-1ubuntu3.1
060+5-1ubuntu3.2
060+5-1ubuntu3.3

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-config-generic",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-config-rescue",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-install",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-live",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "060+5-1ubuntu3.4"
        },
        {
            "binary_name":  "dracut-squash",
            "binary_version":  "060+5-1ubuntu3.4"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-6893",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
Ubuntu:26.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
110-11ubuntu0.1

Affected versions

Other
108-3ubuntu3
108-8ubuntu1
109-5ubuntu1
109-7ubuntu1
109-9ubuntu1
109-11ubuntu1
110-1ubuntu2
110-3ubuntu1
110-5
110-7
110-10
110-11

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "110-11ubuntu0.1"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "110-11ubuntu0.1"
        },
        {
            "binary_name":  "dracut-install",
            "binary_version":  "110-11ubuntu0.1"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "110-11ubuntu0.1"
        },
        {
            "binary_name":  "dracut-test",
            "binary_version":  "110-11ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
Ubuntu:Pro:16.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
044+3-3ubuntu0.1~esm1

Affected versions

Other
043-2
043-4
044+3-1
044+3-2
044+3-3

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "044+3-3ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-generic",
            "binary_version":  "044+3-3ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-rescue",
            "binary_version":  "044+3-3ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "044+3-3ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "044+3-3ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2016-8637",
            "severity":  [
                {
                    "score":  "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-6893",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:Pro:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
Ubuntu:Pro:18.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
047-2ubuntu0.1~esm1

Affected versions

Other
045+132-1
047-2

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "047-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-generic",
            "binary_version":  "047-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-rescue",
            "binary_version":  "047-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "047-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "047-2ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-6893",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:Pro:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
Ubuntu:Pro:20.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
048+80-2ubuntu0.1~esm1

Affected versions

Other
048+80-2

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "048+80-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-generic",
            "binary_version":  "048+80-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-rescue",
            "binary_version":  "048+80-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "048+80-2ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "048+80-2ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-6893",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:Pro:20.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
Ubuntu:Pro:22.04:LTS
dracut

Package

Name
dracut
Purl
pkg:deb/ubuntu/dracut?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
051-1ubuntu0.1~esm1

Affected versions

Other
051-1

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "dracut",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-generic",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-config-rescue",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-core",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-live",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-network",
            "binary_version":  "051-1ubuntu0.1~esm1"
        },
        {
            "binary_name":  "dracut-squash",
            "binary_version":  "051-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-6893",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-15816",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-16445",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:Pro:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"