CVE-2026-21991
CVE-2026-21991 is a medium-severity vulnerability in Oracle Linux with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-12522
- Weakness: CWE-22
- Affected product: Oracle Linux
- Published:
- Last modified:
Description
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Frequently asked questions
- What is CVE-2026-21991?
- A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
- How severe is CVE-2026-21991?
- CVE-2026-21991 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-21991 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-21991?
- CVE-2026-21991 primarily affects Oracle Linux. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-21991?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-21991 have an EU (EUVD) identifier?
- Yes. CVE-2026-21991 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-12522.
- When was CVE-2026-21991 published?
- CVE-2026-21991 was published on 2026-03-16 and last updated on 2026-06-17.
References
Affected products (3)
- cpe:2.3:o:oracle:linux:8:-:*:*:*:*:*:*
- cpe:2.3:o:oracle:linux:9:0:*:*:*:*:*:*
- cpe:2.3:o:oracle:linux:10:0:*:*:*:*:*:*
More vulnerabilities in Oracle Linux
- CVE-2015-0235 — Critical (CVSS 10.0): Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,…
- CVE-2016-1908 — Critical (CVSS 9.8): The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the…
- CVE-2016-2182 — Critical (CVSS 9.8): The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results,…
- CVE-2016-5408 — Critical (CVSS 9.8): Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before…
- CVE-2016-5254 — Critical (CVSS 9.8): Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR…
- CVE-2016-2177 — Critical (CVSS 9.8): OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote…
All CVEs affecting Oracle Linux →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.