CVE-2026-21991
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-21991 is a path traversal vulnerability in the DTrace component dtprobed on Oracle Linux that allows arbitrary file creation through crafted USDT (Userspace Statically Defined Tracing) provider names. It affects Oracle Linux versions 8, 9, and 10. The vulnerability was published on March 16, 2026, with Oracle releasing errata patches on March 13, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Oracle Linux CVE, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The dtprobed daemon, part of the DTrace tracing framework, fails to properly sanitize USDT provider names supplied by local users, allowing path traversal sequences (e.g., ../) to be embedded in provider names. This enables a low-privileged local attacker to cause the daemon to create files at arbitrary filesystem locations outside the intended directory, without requiring user interaction. No public proof-of-concept exploit code has been identified (Oracle Linux CVE, ENISA EUVD).

Impact

Successful exploitation allows a low-privileged local attacker to create arbitrary files anywhere on the filesystem accessible to the dtprobed process. The primary impact is high availability — an attacker could exhaust disk space, overwrite or corrupt critical system files, or disrupt normal system operations. Confidentiality and integrity impacts are rated None in the CVSS scoring, though file creation in sensitive directories could indirectly enable privilege escalation or persistence in certain configurations. The vulnerability affects Oracle Linux 8, 9, and 10 (Oracle Linux CVE).

Exploitation steps

  1. Gain local access: Obtain a low-privileged shell on an Oracle Linux 8, 9, or 10 system running an unpatched version of the dtrace/dtprobed package.
  2. Craft a malicious USDT provider name: Construct a USDT provider name containing path traversal sequences (e.g., ../../tmp/malicious) that, when processed by dtprobed, resolves to a target directory outside the intended scope.
  3. Trigger dtprobed processing: Register or submit the crafted USDT provider name to the dtprobed daemon through the appropriate DTrace interface or API call, causing the daemon to process the malicious name.
  4. Arbitrary file creation: The daemon creates a file at the attacker-controlled path, which could be used to fill disk space (denial of service), plant files in sensitive directories, or set up conditions for further exploitation (Oracle Linux CVE).

Indicators of compromise

  • File System: Unexpected files created in directories outside normal DTrace working paths (e.g., /tmp, /etc, /var) with ownership or timestamps consistent with the dtprobed process.
  • Logs: System logs (/var/log/messages, journald) showing unusual dtprobed activity or errors related to file creation in unexpected paths.
  • Process: Unusual invocations of DTrace-related utilities (dtrace, dtprobed) by non-root, low-privileged users, particularly with non-standard provider name arguments.
  • File System: Rapid growth in disk usage on partitions accessible to dtprobed, potentially indicating disk exhaustion attempts.

Mitigation and workarounds

Oracle has released patches for all affected Oracle Linux versions via the following errata: ELSA-2026-50151 and ELSA-2026-50152 for Oracle Linux 8, ELSA-2026-50152 and ELSA-2026-50153 for Oracle Linux 9, and ELSA-2026-50153 for Oracle Linux 10, all released on March 13, 2026. Administrators should apply the updated dtrace packages immediately using yum update dtrace or the equivalent package manager command. As interim mitigations, restrict local system access to trusted users, apply the principle of least privilege, and monitor filesystem creation activity for anomalous patterns (Oracle Linux CVE).

Community reactions

The vulnerability received coverage from Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org, which reported on the Oracle Linux and Gentoo DTrace updates. A Gentoo GLSA (GLSA-202604-04) was also issued, indicating the vulnerability affects the upstream DTrace package used across multiple Linux distributions. Community reaction has been muted given the moderate severity and local-only attack vector (LinuxSecurity Oracle Advisory, LinuxSecurity Gentoo Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management