CVE-2026-21991: Path Traversal
Published Mar 16, 2026
·Updated
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Affected Software
3 affected components
Oracle Linux=8
Oracle Linux=9-0
Oracle Linux=10-0
Event History
Mar 16, 2026
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21991?
CVE-2026-21991 is classified as a critical vulnerability due to its ability to allow arbitrary file creation.
2
How do I fix CVE-2026-21991?
To mitigate CVE-2026-21991, it is recommended to apply the latest security patches provided by Oracle for affected versions of Oracle Linux.
3
What versions of Oracle Linux are affected by CVE-2026-21991?
CVE-2026-21991 affects Oracle Linux 8, 9, and 10.
4
Can CVE-2026-21991 lead to further vulnerabilities?
Yes, the arbitrary file creation capability in CVE-2026-21991 could potentially lead to escalation of privileges or other attacks.
5
How can I determine if I am impacted by CVE-2026-21991?
You can determine if you are impacted by checking your version of Oracle Linux against the known affected versions for CVE-2026-21991.