- Exploitation depends on adjacent-network DHCP control and boot failure.
What changed
Canonical issued USN-8758-1 for Ubuntu 26.04 LTS, addressing CVE-2026-15816 in dracut, which builds the initial filesystem used during startup. Incorrect quoting of emergency-hook messages could let an attacker controlling a rogue DHCP server on an adjacent network inject commands that run as root during boot-failure handling.
Why it matters
The important operational boundary is the combination of network access and a particular startup failure path. Administrators assessing exposure should distinguish that condition from a flaw reachable through any ordinary internet request. Canonical lists dracut-core and dracut-network version 110-11ubuntu0.1 and requires a reboot after updating.
What remains unproven
The notice supplies neither observed attack counts nor evidence of widespread exploitation. It also does not quantify how commonly installations enter the vulnerable failure-handling path.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
