Red Hat and SUSE disclosed DHCP-related command injection flaws that can let an attacker on the same or adjacent network execute code during system boot. CVE-2026-6893 affects dracut's legacy networking path, where DHCP-supplied values such as host-name are written into temporary shell scripts by modules.d/35network-legacy/dhclient-script.sh and later sourced as root inside initramfs. On systems booting with configurations such as ip=dhcp and rd.neednet=1, a malicious DHCP server can abuse the legacy dhclient flow to achieve root code execution before the operating system fully starts.
SUSE separately assigned CVE-2026-44932 to wicked, which writes DHCP option values into /run/wicked/leaseinfo.* files without sufficient sanitization. Although wicked does not directly source those files, downstream scripts and components that do can execute attacker-controlled shell metacharacters delivered in DHCP responses, creating an indirect remote shell injection path that SUSE said can reach root-level execution in components including dracut's network-legacy module on SLE 15 SP7. Both disclosures tie the risk to unsafe handling of untrusted DHCP data in early-boot networking, and SUSE said it issued security updates across affected product lines.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A SUSE Bugzilla report disclosed CVE-2026-44932 in wicked, where insufficiently sanitized DHCP option values written to leaseinfo files could lead to indirect shell command injection when sourced by downstream scripts or modules. The report states SUSE published multiple important security updates across affected product lines to address the issue.
A Red Hat Bugzilla report documented CVE-2026-6893 in dracut's legacy DHCP path, describing how DHCP-supplied values could be written into temporary shell scripts and later sourced as root in initramfs, enabling root code execution from a malicious DHCP server on the same Layer 2 segment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
bugzilla.suse.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.