{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-6893: escape the DHCP-provided hostname, gateway and iSCSI LUN\n  written into the shell scripts that the initramfs later sources",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787307553",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787307553"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/advisories/2026/clsa-2026_1787307553.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T04:45:41Z",
      "generator": {
        "date": "2026-08-28T04:45:41Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787307553",
      "initial_release_date": "2026-08-21T10:19:14Z",
      "revision_history": [
        {
          "date": "2026-08-21T10:19:14Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-28T04:45:41Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "dracut: Fix of CVE-2026-6893"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-config-generic@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-config-rescue@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-fips@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-tools-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-tools-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-tools-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-tools@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-fips-aesni@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-network@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut-caps@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dracut-0:033-572.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "dracut-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_id": "dracut-0:033-572.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dracut@033-572.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-fips-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-fips-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-tools-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-tools-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-tools-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-network-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-network-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-caps-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-caps-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dracut-0:033-572.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:dracut-0:033-572.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "dracut-0:033-572.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-6893",
      "cwe": {
        "id": "CWE-78",
        "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-7:dracut-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
          "CentOS-7:dracut-tools-0:033-572.el7.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-6893"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26532",
          "url": "https://access.redhat.com/errata/RHSA-2026:26532"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26533",
          "url": "https://access.redhat.com/errata/RHSA-2026:26533"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26534",
          "url": "https://access.redhat.com/errata/RHSA-2026:26534"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26713",
          "url": "https://access.redhat.com/errata/RHSA-2026:26713"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57580",
          "url": "https://access.redhat.com/errata/RHSA-2026:57580"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57772",
          "url": "https://access.redhat.com/errata/RHSA-2026:57772"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57775",
          "url": "https://access.redhat.com/errata/RHSA-2026:57775"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57785",
          "url": "https://access.redhat.com/errata/RHSA-2026:57785"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-6893",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6893"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2459963",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2459963"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6893.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6893.json"
        }
      ],
      "release_date": "2026-06-10T20:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-21T10:19:14.797880Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787307553",
          "product_ids": [
            "CentOS-7:dracut-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-caps-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-config-generic-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-config-rescue-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-fips-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-fips-aesni-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-network-0:033-572.el7.tuxcare.els1.x86_64",
            "CentOS-7:dracut-tools-0:033-572.el7.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787307553"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}