CVE-2026-16445: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:049-244.git20260529.el8_10 (fixed in 0:049-244.git20260529.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:049-138.git20220131.el8_4.1 (fixed in 0:049-138.git20220131.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:049-138.git20220131.el8_4.1 (fixed in 0:049-138.git20220131.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:049-203.git20220511.el8_6.1 (fixed in 0:049-203.git20220511.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:049-203.git20220511.el8_6.1 (fixed in 0:049-203.git20220511.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:049-223.git20230119.el8_8.1 (fixed in 0:049-223.git20230119.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:049-223.git20230119.el8_8.1 (fixed in 0:049-223.git20230119.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images: before 109-7.hum1 (fixed in 109-7.hum1)
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-07-21. Last modified 2026-09-21.