CVE-2026-6893Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-21: 1Technical Details · 2026-06-21: 106-21
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Falha crítica no dracut (CVE-2026-6893) afeta Rocky Linux e RHEL. Atacante na mesma rede pode executar código como root no boot via DHCP. Saiba mais: -> http://shorturl.at/bUHRb https://t.co/6eN76DePAt

    Post summary

    A critical dracut vulnerability (CVE-2026-6893) can let an attacker execute code as root during boot via DHCP on Rocky Linux and RHEL, but no patch, exploit code, or PoC is provided.

    1101098
    1.5K followersView on X

Explore more