Skip to content
Rota Nacional

Cyber ·

USN-8828-1: dracut vulnerabilities

A security notice published on September 28, 2026 describes four dracut vulnerabilities, including local information exposure and possible root code execution through manipulated DHCP data.

Notice USN-8828-1, published on September 28, 2026 and presented as an automatic translation of the Ubuntu Security feed, reports four dracut flaws. One could expose local information because of overly permissive initramfs image permissions and affected Ubuntu 16.04 LTS only (CVE-2016-8637). The others concern DHCP options, error messages, or network configuration data written to shell scripts without proper sanitization or quoting. In certain circumstances, an attacker controlling a DHCP server on the local network could run code as root during system startup.

The three flaws involving DHCP and scripts are identified as CVE-2026-6893, CVE-2026-15816, and CVE-2026-16445. The notice lists Ubuntu 16.04, 18.04, 20.04, 22.04, and 24.04 LTS for the first two; the last affects Ubuntu 22.04 LTS only. Consult the original notice and each CVE record to confirm affected versions, status, and current guidance before taking action; the supplied text does not provide remediation details.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free