
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21991 is a path traversal vulnerability in the DTrace component dtprobed on Oracle Linux that allows arbitrary file creation through crafted USDT (Userspace Statically Defined Tracing) provider names. It affects Oracle Linux versions 8, 9, and 10. The vulnerability was published on March 16, 2026, with Oracle releasing errata patches on March 13, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Oracle Linux CVE, ENISA EUVD).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The dtprobed daemon, part of the DTrace tracing framework, fails to properly sanitize USDT provider names supplied by local users, allowing path traversal sequences (e.g., ../) to be embedded in provider names. This enables a low-privileged local attacker to cause the daemon to create files at arbitrary filesystem locations outside the intended directory, without requiring user interaction. No public proof-of-concept exploit code has been identified (Oracle Linux CVE, ENISA EUVD).
Successful exploitation allows a low-privileged local attacker to create arbitrary files anywhere on the filesystem accessible to the dtprobed process. The primary impact is high availability — an attacker could exhaust disk space, overwrite or corrupt critical system files, or disrupt normal system operations. Confidentiality and integrity impacts are rated None in the CVSS scoring, though file creation in sensitive directories could indirectly enable privilege escalation or persistence in certain configurations. The vulnerability affects Oracle Linux 8, 9, and 10 (Oracle Linux CVE).
dtrace/dtprobed package.../../tmp/malicious) that, when processed by dtprobed, resolves to a target directory outside the intended scope.dtprobed daemon through the appropriate DTrace interface or API call, causing the daemon to process the malicious name./tmp, /etc, /var) with ownership or timestamps consistent with the dtprobed process./var/log/messages, journald) showing unusual dtprobed activity or errors related to file creation in unexpected paths.dtrace, dtprobed) by non-root, low-privileged users, particularly with non-standard provider name arguments.dtprobed, potentially indicating disk exhaustion attempts.Oracle has released patches for all affected Oracle Linux versions via the following errata: ELSA-2026-50151 and ELSA-2026-50152 for Oracle Linux 8, ELSA-2026-50152 and ELSA-2026-50153 for Oracle Linux 9, and ELSA-2026-50153 for Oracle Linux 10, all released on March 13, 2026. Administrators should apply the updated dtrace packages immediately using yum update dtrace or the equivalent package manager command. As interim mitigations, restrict local system access to trusted users, apply the principle of least privilege, and monitor filesystem creation activity for anomalous patterns (Oracle Linux CVE).
The vulnerability received coverage from Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org, which reported on the Oracle Linux and Gentoo DTrace updates. A Gentoo GLSA (GLSA-202604-04) was also issued, indicating the vulnerability affects the upstream DTrace package used across multiple Linux distributions. Community reaction has been muted given the moderate severity and local-only attack vector (LinuxSecurity Oracle Advisory, LinuxSecurity Gentoo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."