Home / mailingsPDF  

[USN-8828-1] dracut vulnerabilities

Posted on 29 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8828-1
September 28, 2026

dracut vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in dracut.

Software Description:
- dracut: Initramfs generator using udev

Details:

It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)

It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)

It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network could possibly use this issue to execute
arbitrary code as root during system boot. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2026-15816)

It was discovered that dracut did not properly sanitize network
configuration data before writing it to a temporary shell script under
certain circumstances. A remote attacker controlling DHCP on the local
network could possibly use this issue to execute arbitrary code as root
during system boot. This issue only affected Ubuntu 22.04 LTS.
(CVE-2026-16445)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
dracut 110-11ubuntu0.1
dracut-core 110-11ubuntu0.1
dracut-network 110-11ubuntu0.1

Ubuntu 24.04 LTS
dracut 060+5-1ubuntu3.4
dracut-core 060+5-1ubuntu3.4
dracut-network 060+5-1ubuntu3.4

Ubuntu 22.04 LTS
dracut 051-1ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-core 051-1ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-network 051-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
dracut 048+80-2ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-core 048+80-2ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-network 048+80-2ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
dracut 047-2ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-core 047-2ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-network 047-2ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
dracut 044+3-3ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-core 044+3-3ubuntu0.1~esm1
Available with Ubuntu Pro
dracut-network 044+3-3ubuntu0.1~esm1
Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8828-1
CVE-2016-8637, CVE-2026-15816, CVE-2026-16445, CVE-2026-6893

Package Information:
https://launchpad.net/ubuntu/+source/dracut/110-11ubuntu0.1
https://launchpad.net/ubuntu/+source/dracut/060+5-1ubuntu3.4

--===============5861465516468191651==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP