Dracut DHCP Option Injection: Command Injection in initrd Network Module
CVE-2026-16445 Published on July 21, 2026
Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 53 days later.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-16445 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-16445
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Enterprise Linux 8:- Version 0:049-244.git20260529.el8_10 and below * is unaffected.