CVE-2026-15816: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:107-9.el10_2 (fixed in 0:107-9.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:105-4.el10_0.1 (fixed in 0:105-4.el10_0.1)
- Red Hat Red Hat Enterprise Linux 6 Extended Lifecycle Support - Extension: before 0:004-413.el6_10 (fixed in 0:004-413.el6_10); before 0:004-414.el6_10 (fixed in 0:004-414.el6_10)
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:033-577.el7_9 (fixed in 0:033-577.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 0:049-246.git20260728.el8_10 (fixed in 0:049-246.git20260728.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:049-138.git20220131.el8_4.1 (fixed in 0:049-138.git20220131.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:049-138.git20220131.el8_4.1 (fixed in 0:049-138.git20220131.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:049-203.git20220511.el8_6.1 (fixed in 0:049-203.git20220511.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:049-203.git20220511.el8_6.1 (fixed in 0:049-203.git20220511.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:049-223.git20230119.el8_8.1 (fixed in 0:049-223.git20230119.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:049-223.git20230119.el8_8.1 (fixed in 0:049-223.git20230119.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9: before 0:057-120.git20260728.el9_8 (fixed in 0:057-120.git20260728.el9_8)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:057-25.git20250717.el9_2.2 (fixed in 0:057-25.git20250717.el9_2.2)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:057-54.git20250423.el9_4.3 (fixed in 0:057-54.git20250423.el9_4.3)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:057-89.git20250311.el9_6.1 (fixed in 0:057-89.git20250311.el9_6.1)
- Red Hat Red Hat Hardened Images
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202609080414-0 (fixed in 413.92.202609080414-0)
- Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202609011250-0 (fixed in 414.92.202609011250-0)
- Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202609140326-0 (fixed in 415.92.202609140326-0)
- Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202609011112-0 (fixed in 416.94.202609011112-0)
- Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202609191027-0 (fixed in 417.94.202609191027-0)
- Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202609031320-0 (fixed in 418.94.202609031320-0); before 418.94.202609171815-0 (fixed in 418.94.202609171815-0)
- Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202609021231-0 (fixed in 4.19.9.6.202609021231-0)
- Red Hat Red Hat Openshift Container Platform 4.20: before 4.20.9.6.202608260604-0 (fixed in 4.20.9.6.202608260604-0)
- and 2 more
Published 2026-08-07. Last modified 2026-10-08.