CVE-2012-4453: Dracut Project Dracut
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Affected products
- Dracut Project Dracut: before 024 (fixed in 024)
- Fedoraproject Fedora: version 16 only; version 17 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2012-10-09. Last modified 2026-06-16.