Generated remediation guidance and an executive summary. No account required.
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Cite this page
CVE-2016-8637. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-8637
Use CWE-732, Dracut Project vendor hub and Dracut product page to widen CVE-2016-8637 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2010-4176, CVE-2015-0794 and CVE-2012-4453 for nearby disclosures in the same product family.