Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: dracut: * dracut-109-7.hum1 (aarch64, x86_64) * dracut-caps-109-7.hum1 (aarch64, x86_64) * dracut-config-generic-109-7.hum1 (aarch64, x86_64) * dracut-config-rescue-109-7.hum1 (aarch64, x86_64) * dracut-live-109-7.hum1 (aarch64, x86_64) * dracut-network-109-7.hum1 (aarch64, x86_64) * dracut-squash-109-7.hum1 (aarch64, x86_64) * dracut-tools-109-7.hum1 (aarch64, x86_64) * dracut-109-7.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-16445 is a command injection vulnerability in dracut's NetworkManager-based initrd network module (nm-run.sh). The flaw arises because DHCP options such as root-path, next-server, or bootfile name are improperly handled and written into a temporary shell script without proper escaping. An attacker on the adjacent network acting as a DHCP server can supply malicious DHCP options that lead to command injection and root code execution within the initramfs during system boot. This affects systems using dracut's network-manager module with DHCP-derived netroot configurations, such as NFS-root setups. The vulnerability is classified under CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
Potential Impact
Successful exploitation allows an attacker on the adjacent network to execute arbitrary commands as root during system boot within the initramfs environment. This can lead to full system compromise, including unauthorized code execution, data modification, and denial of service. The attack vector requires adjacency on the network and high attack complexity but no privileges or user interaction. The impact on confidentiality, integrity, and availability is high.
Mitigation Recommendations
Red Hat has released updated dracut RPMs (version 109-7.hum1) that properly escape DHCP-derived values using shell-safe quoting before writing them to the generated dhcpopts file, preventing command injection. Users should apply the update from Red Hat Hardened Images RPMs as detailed in the advisory (https://access.redhat.com/errata/RHSA-2026:40700). Systems configured to boot with dracut's network-manager module using DHCP-derived netroot should be prioritized for patching. No alternative mitigations are specified beyond applying the official update.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: dracut: * dracut-109-7.hum1 (aarch64, x86_64) * dracut-caps-109-7.hum1 (aarch64, x86_64) * dracut-config-generic-109-7.hum1 (aarch64, x86_64) * dracut-config-rescue-109-7.hum1 (aarch64, x86_64) * dracut-live-109-7.hum1 (aarch64, x86_64) * dracut-network-109-7.hum1 (aarch64, x86_64) * dracut-squash-109-7.hum1 (aarch64, x86_64) * dracut-tools-109-7.hum1 (aarch64, x86_64) * dracut-109-7.hum1.src (src)
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16445 is a command injection vulnerability in dracut's NetworkManager-based initrd network module (nm-run.sh). The flaw arises because DHCP options such as root-path, next-server, or bootfile name are improperly handled and written into a temporary shell script without proper escaping. An attacker on the adjacent network acting as a DHCP server can supply malicious DHCP options that lead to command injection and root code execution within the initramfs during system boot. This affects systems using dracut's network-manager module with DHCP-derived netroot configurations, such as NFS-root setups. The vulnerability is classified under CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
Potential Impact
Successful exploitation allows an attacker on the adjacent network to execute arbitrary commands as root during system boot within the initramfs environment. This can lead to full system compromise, including unauthorized code execution, data modification, and denial of service. The attack vector requires adjacency on the network and high attack complexity but no privileges or user interaction. The impact on confidentiality, integrity, and availability is high.
Mitigation Recommendations
Red Hat has released updated dracut RPMs (version 109-7.hum1) that properly escape DHCP-derived values using shell-safe quoting before writing them to the generated dhcpopts file, preventing command injection. Users should apply the update from Red Hat Hardened Images RPMs as detailed in the advisory (https://access.redhat.com/errata/RHSA-2026:40700). Systems configured to boot with dracut's network-manager module using DHCP-derived netroot should be prioritized for patching. No alternative mitigations are specified beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4672-282m-8fgr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-16445"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6151289c2644c7f8da64fb
Added to database: 07/22/2026, 23:24:24 UTC
Last enriched: 08/16/2026, 17:28:15 UTC
Last updated: 09/14/2026, 22:01:32 UTC
Views: 100
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.