THE ESSENTIALS
  • Exploitation depends on adjacent-network DHCP control and boot failure.

What changed

Canonical issued USN-8758-1 for Ubuntu 26.04 LTS, addressing CVE-2026-15816 in dracut, which builds the initial filesystem used during startup. Incorrect quoting of emergency-hook messages could let an attacker controlling a rogue DHCP server on an adjacent network inject commands that run as root during boot-failure handling.

Why it matters

The important operational boundary is the combination of network access and a particular startup failure path. Administrators assessing exposure should distinguish that condition from a flaw reachable through any ordinary internet request. Canonical lists dracut-core and dracut-network version 110-11ubuntu0.1 and requires a reboot after updating.

What remains unproven

The notice supplies neither observed attack counts nor evidence of widespread exploitation. It also does not quantify how commonly installations enter the vulnerable failure-handling path.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. Canonical / Ubuntu Security Notices ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗