USN-8828-1: dracut vulnerabilities

Publication date

28 September 2026

Overview

Several security issues were fixed in dracut.


Packages

  • dracut - Initramfs generator using udev

Details

It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)

It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)

It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network...

It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)

It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)

It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network could possibly use this issue to execute
arbitrary code as root during system boot. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2026-15816)

It was discovered that dracut did not properly sanitize network
configuration data before writing it to a temporary shell script under
certain circumstances. A remote attacker controlling DHCP on the local
network could possibly use this issue to execute arbitrary code as root
during system boot. This issue only affected Ubuntu 22.04 LTS.
(CVE-2026-16445)


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute dracut –  110-11ubuntu0.1
dracut-core –  110-11ubuntu0.1
dracut-network –  110-11ubuntu0.1
24.04 LTS noble dracut –  060+5-1ubuntu3.4
dracut-core –  060+5-1ubuntu3.4
dracut-network –  060+5-1ubuntu3.4
22.04 LTS jammy dracut –  051-1ubuntu0.1~esm1  
dracut-core –  051-1ubuntu0.1~esm1  
dracut-network –  051-1ubuntu0.1~esm1  
20.04 LTS focal dracut –  048+80-2ubuntu0.1~esm1  
dracut-core –  048+80-2ubuntu0.1~esm1  
dracut-network –  048+80-2ubuntu0.1~esm1  
18.04 LTS bionic dracut –  047-2ubuntu0.1~esm1  
dracut-core –  047-2ubuntu0.1~esm1  
dracut-network –  047-2ubuntu0.1~esm1  
16.04 LTS xenial dracut –  044+3-3ubuntu0.1~esm1
dracut-core –  044+3-3ubuntu0.1~esm1
dracut-network –  044+3-3ubuntu0.1~esm1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›