Dracut is a widely embedded initramfs-generation framework used across Linux distributions to construct early-boot root filesystems, where its core role in system initialization gives disclosed vulnerabilities outsized structural significance despite the small disclosed volume. The vendor's exposure centers on permission and information-handling weaknesses—including incorrect default permissions, sensitive data exposure, improper link resolution, and critical resource access-control flaws—that arise from the framework's direct manipulation of system files and boot-time file operations. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dracut Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8637HIGH A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when includi | Aug 1, 2018 | 7.8 | 25 | NO | NO |
CVE-2010-4176MEDIUM plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read | Dec 7, 2010 | 4.0 | 17 | NO | NO |
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might all | Oct 9, 2012 | 2.1 | 14 | NO | NO |
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_ | Nov 19, 2015 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dracut Project.
Media articles that mention a CVE ID that affects a product developed by Dracut Project — matched by CVE ID, not by vendor name.