Skip to content

[Deepin Integration]~[v25-Release] fix: CVE-2026-6893 - DHCP command injection via printf %q escaping by deepin-ci-robot@deepin-community/dracut by deepin-community-ci-bot[bot] #13795

Description

@deepin-bot

Package information | 软件包信息

包名 版本
dracut 103-1deepin2

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4280/testing/ ./

Changelog | 更新信息

dracut (103-1deepin2) unstable; urgency=medium

  • Fix CVE-2026-16445: DHCP command injection in NetworkManager-based initrd
    • Backport upstream commit to fix improper shell escaping in nm-run.sh
    • CVE-2026-16445: remote attacker on adjacent network can exploit
      specially crafted DHCP options for root code execution

Metadata

Metadata

Assignees

Type

No type

Projects

Status
In progress

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions