What is CVE-2026-15816?
CVE-2026-15816 is a vulnerability in dracut where the die() error-handling function writes DHCP ROOT_PATH data into a shell script under the initramfs emergency-hook directory without proper shell-quoting. This could allow an adjacent network attacker to achieve arbitrary code execution via crafted DHCP packets. Applying the dracut update is recommended.
Azərbaycanca: CVE-2026-15816, dracut-da die() funksiyasının DHCP ROOT_PATH məlumatını düzgün qabıq-mühafizə etmədən initramfs emergency-hook kataloqunda shell skriptinə yazması ilə bağlı boşluqdur. Bu, qonşu şəbəkədəki hücumçuya xüsusi DHCP paketləri ilə ixtiyari kod icrasına imkan yarada bilər. dracut yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Where does an attacker need to be positioned to exploit CVE-2026-15816?
The attacker must be on an adjacent network.
Which function's improper operation causes CVE-2026-15816?
The vulnerability occurs because the die() function does not properly shell-quote the DHCP ROOT_PATH data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.