Red Hat and SUSE disclosed DHCP-related command injection flaws that can let an attacker on the same or adjacent network execute code during system boot. CVE-2026-6893 affects dracut's legacy networking path, where DHCP-supplied values such as host-name are written into temporary shell scripts by modules.d/35network-legacy/dhclient-script.sh and later sourced as root inside initramfs. On systems booting with configurations such as ip=dhcp and rd.neednet=1, a malicious DHCP server can abuse the legacy dhclient flow to achieve root code execution before the operating system fully starts.
SUSE separately assigned CVE-2026-44932 to wicked, which writes DHCP option values into /run/wicked/leaseinfo.* files without sufficient sanitization. Although wicked does not directly source those files, downstream scripts and components that do can execute attacker-controlled shell metacharacters delivered in DHCP responses, creating an indirect remote shell injection path that SUSE said can reach root-level execution in components including dracut's network-legacy module on SLE 15 SP7. Both disclosures tie the risk to unsafe handling of untrusted DHCP data in early-boot networking, and SUSE said it issued security updates across affected product lines.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:61252 for RHEL 8, including supported 8.8 E4S and TUS configurations, with Important-rated updates for dracut and dracut-network. The advisory addresses CVE-2026-6893, CVE-2026-15816, and CVE-2026-16445, a command-injection issue in dracut's NetworkManager initrd module that can allow root code execution via DHCP options.
Red Hat published advisory RHSA-2026:57785 for Red Hat Enterprise Linux 9.4 Extended Update Support, providing dracut security updates for CVE-2026-6893 and CVE-2026-15816. The advisory was rated Important and covered affected dracut-network packages on RHEL 9.4 EUS.
Red Hat published advisory RHSA-2026:57775 for dracut on Red Hat Enterprise Linux 9.2 E4S, addressing CVE-2026-6893 and CVE-2026-15816. The advisory was rated Important and covered affected dracut and dracut-network packages.
Red Hat published advisory RHSA-2026:57772 for RHEL 9, including RHEL EUS 9.6, providing dracut and dracut-network security updates for CVE-2026-6893 and CVE-2026-15816. The advisory rated the issues Important and addressed root code execution risks in dracut's DHCP handling and emergency hook script logic.
Red Hat published advisory RHSA-2026:57580 for RHEL 10 and RHEL EUS 10.0, providing dracut security updates that address CVE-2026-6893 and CVE-2026-15816. The advisory rated the issues Important and identified affected dracut and dracut-network packages.
A Red Hat Bugzilla report documented CVE-2026-15816 in dracut's die() function, where an unescaped error message written to 01-die.sh could allow DHCP-controlled ROOT_PATH data to trigger root command execution when emergency hook scripts are later sourced. The report states the issue is distinct from CVE-2026-6893 and was reproduced across shipped dracut RPMs from RHEL 6 through RHEL 10.
A SUSE Bugzilla report disclosed CVE-2026-44932 in wicked, where insufficiently sanitized DHCP option values written to leaseinfo files could lead to indirect shell command injection when sourced by downstream scripts or modules. The report states SUSE published multiple important security updates across affected product lines to address the issue.
A Red Hat Bugzilla report documented CVE-2026-6893 in dracut's legacy DHCP path, describing how DHCP-supplied values could be written into temporary shell scripts and later sourced as root in initramfs, enabling root code execution from a malicious DHCP server on the same Layer 2 segment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
13 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.suse.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.