{"id":"DEBIAN-CVE-2026-15816","details":"A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.","modified":"2026-09-28T08:47:30.593090740Z","published":"2026-08-07T11:17:05.100Z","upstream":["CVE-2026-15816"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-15816"}],"affected":[{"package":{"name":"dracut","ecosystem":"Debian:12","purl":"pkg:deb/debian/dracut?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["059+212-1","059+212-2","059+212-3","059+212-4","059-4","060+5-1","060+5-2~exp1","060+5-7","060+5-8","102-1","102-2","102-3","103-1","103-1.1","103-2","105-1","105-2","105-2~exp1","105-2~exp2","105-2~exp3","105-2~exp4","105-2~exp5","105-2~exp6","105-2~exp7","105-2~exp8","105-3","106-1","106-2","106-3","106-4","106-5","106-5~bpo12+1","106-6","107-1","107-2","108-1","108-2","108-3","108-4","108-5","108-6","108-7","108-8","109-1","109-10","109-11","109-1exp1","109-2","109-3","109-4","109-5","109-6","109-6exp1","109-6exp2","109-6exp3","109-7","109-8","109-9","110-1","110-10","110-11","110-12","110-2","110-3","110-4","110-5","110-6","110-7","110-8","110-9","111-1","111-2","111-3","111-4","111-5","111-6","112-1","112-2","112-3","112-4","112-5","112-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15816.json"}},{"package":{"name":"dracut","ecosystem":"Debian:13","purl":"pkg:deb/debian/dracut?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["106-6","107-1","107-2","108-1","108-2","108-3","108-4","108-5","108-6","108-7","108-8","109-1","109-10","109-11","109-1exp1","109-2","109-3","109-4","109-5","109-6","109-6exp1","109-6exp2","109-6exp3","109-7","109-8","109-9","110-1","110-10","110-11","110-12","110-2","110-3","110-4","110-5","110-6","110-7","110-8","110-9","111-1","111-2","111-3","111-4","111-5","111-6","112-1","112-2","112-3","112-4","112-5","112-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15816.json"}},{"package":{"name":"dracut","ecosystem":"Debian:14","purl":"pkg:deb/debian/dracut?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"112-2"}]}],"versions":["106-6","107-1","107-2","108-1","108-2","108-3","108-4","108-5","108-6","108-7","108-8","109-1","109-10","109-11","109-1exp1","109-2","109-3","109-4","109-5","109-6","109-6exp1","109-6exp2","109-6exp3","109-7","109-8","109-9","110-1","110-10","110-11","110-12","110-2","110-3","110-4","110-5","110-6","110-7","110-8","110-9","111-1","111-2","111-3","111-4","111-5","111-6","112-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15816.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}