dracut project dracut是dracut project团队开源的一个Linux内核initramfs生成工具。 dracutdevs dracut存在命令注入漏洞,该漏洞源于基于NetworkManager的initrd网络模块对特制DHCP选项处理不当,未正确转义就写入临时shell脚本,导致命令注入,使得相邻网络的远程攻击者可在系统启动期间在initramfs中实现root代码执行。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 0:049-244.git20260529.el8_10 ~ * |
cpe:/o:redhat:enterprise_linux:8::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:049-138.git20220131.el8_4.1 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:049-138.git20220131.el8_4.1 ~ * |
cpe:/o:redhat:rhel_aus:8.4::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:049-203.git20220511.el8_6.1 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:049-203.git20220511.el8_6.1 ~ * |
cpe:/o:redhat:rhel_aus:8.6::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:049-223.git20230119.el8_8.1 ~ * |
cpe:/o:redhat:rhel_e4s:8.8::baseos
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:049-223.git20230119.el8_8.1 ~ * |
cpe:/o:redhat:rhel_e4s:8.8::baseos
|
|
| Red Hat | Red Hat Hardened Images | 109-7.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
| CVE-2026-59851 | 8.8 HIGH | libssh 授权问题漏洞 |
| CVE-2026-16493 | 7.8 HIGH | ansible 命令注入漏洞 |
| CVE-2026-15927 | 6.8 MEDIUM | Red Hat Quay 服务端请求伪造漏洞 |
| CVE-2026-15370 | 6.7 MEDIUM | libssh 缓冲区错误漏洞 |
| CVE-2026-59843 | 6.5 MEDIUM | libssh 资源管理错误漏洞 |
| CVE-2026-16461 | 6.5 MEDIUM | rpcbind project rpcinfo 缓冲区错误漏洞 |
| CVE-2026-59844 | 6.5 MEDIUM | libssh 资源管理错误漏洞 |
| CVE-2026-59847 | 5.9 MEDIUM | libssh 硬件供应链问题漏洞 |
| CVE-2026-15811 | 5.8 MEDIUM | Kronosnet 信息泄露漏洞 |
| CVE-2026-59845 | 5.3 MEDIUM | libssh 安全漏洞 |
| CVE-2026-59848 | 5.3 MEDIUM | libssh 安全漏洞 |
| CVE-2026-15812 | 4.8 MEDIUM | Kronosnet 授权问题漏洞 |
| CVE-2026-59850 | 4.3 MEDIUM | libssh 资源管理错误漏洞 |
| CVE-2026-12548 | 4.2 MEDIUM | GNOME libsoup 缓冲区错误漏洞 |
| CVE-2026-59846 | 3.9 LOW | libssh 安全漏洞 |
| CVE-2026-59842 | 3.7 LOW | libssh 缓冲区错误漏洞 |
| CVE-2026-12547 | 3.4 LOW | libsoup 信息泄露漏洞 |
| CVE-2026-59849 | 3.1 LOW | libssh 资源管理错误漏洞 |
| CVE-2026-16517 | 2.9 LOW | libarchive 数字错误漏洞 |
暂无评论