漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
Vulnerability Description
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
dracutdevs dracut 命令注入漏洞
Vulnerability Description
dracut project dracut是dracut project团队开源的一个Linux内核initramfs生成工具。 dracutdevs dracut存在命令注入漏洞,该漏洞源于基于NetworkManager的initrd网络模块对特制DHCP选项处理不当,未正确转义就写入临时shell脚本,导致命令注入,使得相邻网络的远程攻击者可在系统启动期间在initramfs中实现root代码执行。
CVSS Information
N/A
Vulnerability Type
N/A