> USN-8758-1: dracut vulnerability
[DATE: 14/09/2026 20:28]
[LANGUAGE: EN]
It was discovered that dracut did not properly shell-quote messages
written by the die() function to the emergency hook directory. An
attacker on the adjacent network controlling a rogue DHCP server could
use this issue to inject commands that execute as root during
boot-failure handling. (CVE-2026-15816)