It was discovered that dracut created initramfs images with overly permissive permissions under certain circumstances. A local attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-8637)
It was discovered that dracut did not properly sanitize DHCP options before writing them to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)
It was discovered that dracut did not properly quote error messages written to shell scripts under certain circumstances. A remote attacker controlling a DHCP server on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-15816)
It was discovered that dracut did not properly sanitize network configuration data before writing it to a temporary shell script under certain circumstances. A remote attacker controlling DHCP on the local network could possibly use this issue to execute arbitrary code as root during system boot. This issue only affected Ubuntu 22.04 LTS. (CVE-2026-16445)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-config-generic",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-config-rescue",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-core",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-install",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-live",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-network",
"binary_version": "060+5-1ubuntu3.4"
},
{
"binary_name": "dracut-squash",
"binary_version": "060+5-1ubuntu3.4"
}
]
}{
"cves": [
{
"id": "CVE-2026-6893",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "110-11ubuntu0.1"
},
{
"binary_name": "dracut-core",
"binary_version": "110-11ubuntu0.1"
},
{
"binary_name": "dracut-install",
"binary_version": "110-11ubuntu0.1"
},
{
"binary_name": "dracut-network",
"binary_version": "110-11ubuntu0.1"
},
{
"binary_name": "dracut-test",
"binary_version": "110-11ubuntu0.1"
}
]
}{
"cves": [
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
{
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "044+3-3ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-generic",
"binary_version": "044+3-3ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-rescue",
"binary_version": "044+3-3ubuntu0.1~esm1"
},
{
"binary_name": "dracut-core",
"binary_version": "044+3-3ubuntu0.1~esm1"
},
{
"binary_name": "dracut-network",
"binary_version": "044+3-3ubuntu0.1~esm1"
}
]
}{
"cves": [
{
"id": "CVE-2016-8637",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-6893",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:16.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "047-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-generic",
"binary_version": "047-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-rescue",
"binary_version": "047-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-core",
"binary_version": "047-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-network",
"binary_version": "047-2ubuntu0.1~esm1"
}
]
}{
"cves": [
{
"id": "CVE-2026-6893",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:18.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "048+80-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-generic",
"binary_version": "048+80-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-rescue",
"binary_version": "048+80-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-core",
"binary_version": "048+80-2ubuntu0.1~esm1"
},
{
"binary_name": "dracut-network",
"binary_version": "048+80-2ubuntu0.1~esm1"
}
]
}{
"cves": [
{
"id": "CVE-2026-6893",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:20.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "dracut",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-generic",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-config-rescue",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-core",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-live",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-network",
"binary_version": "051-1ubuntu0.1~esm1"
},
{
"binary_name": "dracut-squash",
"binary_version": "051-1ubuntu0.1~esm1"
}
]
}{
"cves": [
{
"id": "CVE-2026-6893",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-15816",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-16445",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:Pro:22.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8828-1.json"