Red Hat Dracut Updates Protect RHEL 8.4 and 8.6 Network Boot

P1 — VALIDATE AND UPDATEHigh · 7.5 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:69119 and RHSA-2026:69118 for three Important dracut vulnerabilities in entitled RHEL 8.6 and 8.4 extended-support streams. Red Hat assigns each CVE a 7.5 High CVSS v3.1 score and supplies fixed package builds.

Protect RHEL Network-Boot And Initramfs Paths

What to do now: Match systems to the exact RHEL 8.4 or 8.6 extended-support entitlement and dracut stream, apply the corresponding Red Hat package, secure DHCP and provisioning networks, and validate the resulting package and network-boot workflow.

Open the authoritative advisory

Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.

Scope And Authority

Product scopeRHEL 8.4 and 8.6 extended-support dracut packages
AdvisoryRHSA-2026:69119 / RHSA-2026:69118
CVEsCVE-2026-6893, CVE-2026-15816, CVE-2026-16445
Authoritative release dateRHSA-2026:69119 at 2026-09-21 03:04:36 UTC; RHSA-2026:69118 at 03:05:06 UTC
Authority revision date2026-09-21 03:05:59 UTC and 03:06:05 UTC, respectively
Affected versionsEntitled RHEL 8.4 and 8.6 AUS/EUS Extension dracut streams before the advisory-listed builds
Fixed versiondracut 049-203.git20220511.el8_6.1 (RHEL 8.6) / 049-138.git20220131.el8_4.1 (RHEL 8.4)
CVSS base score7.5 (CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

The three flaws concern untrusted DHCP or network-root data reaching dracut initramfs processing. Red Hat's supported workarounds restrict adjacent DHCP control and avoid DHCP-derived root targets. The advisories list no required restart category, so activation steps must follow the current Red Hat package and operational guidance rather than an inferred reboot rule.

What To Validate Now

  1. Inventory. Identify entitled RHEL 8.4 and 8.6 AUS/EUS Extension systems, their dracut packages, initramfs network configuration, PXE or provisioning role, and DHCP trust boundary.
  2. Establish applicability. Match the exact advisory product stream; establish whether DHCP-supplied network settings or root paths are used during initramfs rather than assuming every RHEL host is exposed.
  3. Remediate. Apply the advisory-listed dracut build from the correct entitled repository. Until complete, use trusted provisioning networks, DHCP snooping or dedicated VLANs, static settings where feasible, and explicit netroot values as Red Hat describes.
  4. Validate. Confirm the installed NVR, follow Red Hat's package activation guidance, exercise representative boot and recovery paths, and verify DHCP, storage, networking, and rollback readiness.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

These advisories target specific paid extended-support streams. Do not apply one branch's NVR to another branch, and do not describe network adjacency or a High score as evidence of compromise.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.