← Back

Dracut

dracut

Vendor: Dracut Project • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dracut Project
1Dracut
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can...Show more
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.Show less
1Dracut Project
1Dracut
May 6, 2026
Nov 19, 2015
N/A· v4
N/A· v3
3.6 LOW· v2
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
3Dracut Project
FedoraprojectRedhat
5Dracut
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive infor...Show more
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.Show less
2Dracut Project
Udev Project
2Dracut
Udev
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.