Red Hat Product Errata RHSA-2026:62269 - Security Advisory Issued: 2026-09-01 Updated: 2026-09-01 RHSA-2026:62269 - Security Advisory Overview Updated Packages Synopsis Important: dracut security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for dracut is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The dracut packages contain an event-driven initial RAM file system (initramfs) generator infrastructure based on the udev device manager. The virtual file system, initramfs, is loaded together with the kernel at boot time and initializes the system, so it can read and boot from the root partition. Security Fix(es): dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2459963 - CVE-2026-6893 dracut: dracut: Root code execution via DHCP options command injection BZ - 2500889 - CVE-2026-15816 dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() CVEs CVE-2026-6893 CVE-2026-15816 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM dracut-033-577.el7_9.src.rpm SHA-256: b15fde5c2e50ef02f3267d8257d630a5e3af9c62243d6c72da802d804e85cb44 x86_64 dracut-033-577.el7_9.x86_64.rpm SHA-256: 01f31903738b8643621f801374019e0f774e8d8c8065c0467ae0dd14835f0755 dracut-caps-033-577.el7_9.x86_64.rpm SHA-256: cbc2b585b287bc1da262f09106be031dbb57d8da84503e4d7013043cf82b3ff7 dracut-config-generic-033-577.el7_9.x86_64.rpm SHA-256: edd82ad3c70c7fab3fb2389d4e1f61ec896e892c543f99bf4572e8f22bf185a1 dracut-config-rescue-033-577.el7_9.x86_64.rpm SHA-256: a84dce043e530c6c3034e9ddcbd71962a6db1b4864932afe8c0485b537e44a2f dracut-debuginfo-033-577.el7_9.x86_64.rpm SHA-256: 1f95e844aa222d3a745f58ba72aaf3972b34f639c94bfe22f76513e2769d0f38 dracut-debuginfo-033-577.el7_9.x86_64.rpm SHA-256: 1f95e844aa222d3a745f58ba72aaf3972b34f639c94bfe22f76513e2769d0f38 dracut-fips-033-577.el7_9.x86_64.rpm SHA-256: ea8d9afb373018655f5574301ccd7351313b82243ab0bcd389a496a728022015 dracut-fips-aesni-033-577.el7_9.x86_64.rpm SHA-256: b52860e6ff0f21c88a6609b88aa25b10c824595d1d3ad65a1bc9b5ac880287e2 dracut-network-033-577.el7_9.x86_64.rpm SHA-256: 46100382429dfc2f5e93c88c4901c153c8b0e9b830bf04d2b558580c81e187a9 dracut-tools-033-577.el7_9.x86_64.rpm SHA-256: e88e18d513c252346cb48c009202c24a8708b39dad513a02ec7e67131e6a0627 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM dracut-033-577.el7_9.src.rpm SHA-256: b15fde5c2e50ef02f3267d8257d630a5e3af9c62243d6c72da802d804e85cb44 s390x dracut-033-577.el7_9.s390x.rpm SHA-256: 9073068a0010639f46dd605c3956ee2f42d6da3e87da71ef17618405faaa491a dracut-caps-033-577.el7_9.s390x.rpm SHA-256: 5b5657180c240cfe6711cc89522e59e5c0802a32d4fefd2e49b58507a6ee60d6 dracut-config-generic-033-577.el7_9.s390x.rpm SHA-256: fbed2122d911849de21ee1d7b4b43ff7886fe59220ae182689f500e31d27d5a9 dracut-config-rescue-033-577.el7_9.s390x.rpm SHA-256: 8848647d29cf8118cab39670791fc7c4a6d203e2566c2e925c8b143260679b36 dracut-debuginfo-033-577.el7_9.s390x.rpm SHA-256: 4376fdb468ddcb849e20623c5ded46006aaacf08db71c252ccf8079a73e1803e dracut-debuginfo-033-577.el7_9.s390x.rpm SHA-256: 4376fdb468ddcb849e20623c5ded46006aaacf08db71c252ccf8079a73e1803e dracut-fips-033-577.el7_9.s390x.rpm SHA-256: 968e52910bd577808869a81b16923d27b6a588d911611f56e5bcaf06f1fb76ff dracut-fips-aesni-033-577.el7_9.s390x.rpm SHA-256: e6443fd446da65d5c8d4f4ea15c4f178a3f7339340797b2503aa901964c243e8 dracut-network-033-577.el7_9.s390x.rpm SHA-256: 362563ef164515bf40d3b68c4bcdf044aa641b13234ac0ea685290ee509865bb dracut-tools-033-577.el7_9.s390x.rpm SHA-256: abc8df0faf63f6d69cfcdb280abdc370f1c6282e63898ca2935505bd7e4d8422 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM dracut-033-577.el7_9.src.rpm SHA-256: b15fde5c2e50ef02f3267d8257d630a5e3af9c62243d6c72da802d804e85cb44 ppc64 dracut-033-577.el7_9.ppc64.rpm SHA-256: 0ee71534daf41996eb8b83241923f277605191a3dbba520357dac8acf47018c3 dracut-caps-033-577.el7_9.ppc64.rpm SHA-256: ab11fac97ee996d51f7f399e74f652169cfb53cd25506be5912682736cd58766 dracut-config-generic-033-577.el7_9.ppc64.rpm SHA-256: 83a17fc40d3832d3442e6aebac71d070ecea3b74416cc7f7686cd2bc00362bf3 dracut-config-rescue-033-577.el7_9.ppc64.rpm SHA-256: 1cd299bfd6825c3280ea769266748d1f52f08c78d9c982fc7c9dd3e8f9e9fc58 dracut-debuginfo-033-577.el7_9.ppc64.rpm SHA-256: dff25d7068bb191cb5a1c458c695120276712b17498535762d829c4eabd3c1a5 dracut-debuginfo-033-577.el7_9.ppc64.rpm SHA-256: dff25d7068bb191cb5a1c458c695120276712b17498535762d829c4eabd3c1a5 dracut-fips-033-577.el7_9.ppc64.rpm SHA-256: a0abf8b29b4d4949d3c43ffdedc70fe5c982c00d9e7452dd19b33c80237d10ca dracut-fips-aesni-033-577.el7_9.ppc64.rpm SHA-256: 71f22b2e4672e4bfc63fe32c54a294a1ee1dd5ac40978b1ea0e06da8adedcaf4 dracut-network-033-577.el7_9.ppc64.rpm SHA-256: 7cbc4e368cf17b438d3d6237635e61630d748a10286ee3ad7aef8b3b098da464 dracut-tools-033-577.el7_9.ppc64.rpm SHA-256: 967acd22b28bb83a9a14de2bd54cf6899e4e62ce7afb3c986b125d0718644f2f Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM dracut-033-577.el7_9.src.rpm SHA-256: b15fde5c2e50ef02f3267d8257d630a5e3af9c62243d6c72da802d804e85cb44 ppc64le dracut-033-577.el7_9.ppc64le.rpm SHA-256: e70621a4ab57268bdc304cc666ea5f3547d258b444e000be95d3e7a2bfc2cf5c dracut-caps-033-577.el7_9.ppc64le.rpm SHA-256: 14fe2ac7560557440fb9519ec18d928814236fe4e8ddd2a19bea72e4e5e2eac7 dracut-config-generic-033-577.el7_9.ppc64le.rpm SHA-256: e1c5aedabd1a87e244c72be7de3347dc4e97773c2f40a487390db2d3f1da0274 dracut-config-rescue-033-577.el7_9.ppc64le.rpm SHA-256: ad79a9b1096ee5f024bf5bb4610fdff0ba9242c136d8f02be6adc02a41f3dfa6 dracut-debuginfo-033-577.el7_9.ppc64le.rpm SHA-256: a292a425a5123a3387c941739fcfe872e033b5cec4b0e54332a93a105d0c26b8 dracut-debuginfo-033-577.el7_9.ppc64le.rpm SHA-256: a292a425a5123a3387c941739fcfe872e033b5cec4b0e54332a93a105d0c26b8 dracut-fips-033-577.el7_9.ppc64le.rpm SHA-256: f03424a8d90d89548368f018ee7da09cef6f814c12be0b9376fb5ff85d6d16ff dracut-fips-aesni-033-577.el7_9.ppc64le.rpm SHA-256: eaa4fa0c0a78fc51a29d8bfb7c21244dd1c4aacbf5d466c5187662ba95b3adb3 dracut-network-033-577.el7_9.ppc64le.rpm SHA-256: 6d8dca40a1ddf0239e120e7a0dc578a35d2872c215486380e44ef45662d44386 dracut-tools-033-577.el7_9.ppc64le.rpm SHA-256: 6ffcc6dcd4bfbbb509a6185e98ddb1a9ec54d6cce2ae4d2740e8e6ae2524f6cf The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This Important advisory addresses two vulnerabilities (CVE-2026-6893 and CVE-2026-15816, both CVSS 7.5 HIGH) in the dracut initramfs generator for Red Hat Enterprise Linux 7 ELS, allowing root code execution via DHCP option command injection and unescaped error messages in emergency hooks. The update provides fixed packages, such as dracut-033-577.el7_9.x86_64.rpm, to remediate the issue. Systems running the affected dracut packages on RHEL 7 Extended Lifecycle Support should be patched immediately.