CVE-2026-21996Disclosure(oracle / linux)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oracle linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-369

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-01); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux

3 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-05-01: 3Technical Details · 2026-05-02: 105-0105-0205-18
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure2General1
2026-05-021
Patch1
2026-05-181
General1
Full discourse5 posts
  • gujjuboy10x00@vis_hacker
    Patch

    Two CVEs just patched by @Oracle , credited to me: CVE-2026-21996 , CVE-2026-35233 Root-privileged parser eating attacker-supplied ELF. Classic trust-boundary bugs. Advisory: https://linux.oracle.com/errata/ELSA-2026-50250.html Write-up: https://medium.com/@vis_hacker/hunting-bugs-in-oracles-userspace-dtrace-cve-2026-21996-and-cve-2026-35233-56e3704c9c0b

    Post summary

    Oracle has released patches for CVE‑2026‑21996 and CVE‑2026‑35233, with the vulnerability involving a root‑privileged parser that improperly processes attacker‐supplied ELF binaries—details and a write‑up are available via the provided links.

    01045588
    6.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21996 An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab() https://www.cve.org/CVERecord?id=CVE-2026-21996

    Post summary

    The post announces CVE-2026-21996, describing an integer divide‑by‑zero flaw in dtrace's Pbuild_file_symtab() that lets an unprivileged attacker crash the process, with no PoC, exploit tools, or patch details mentioned.

    00010180
    57.4K followersView on X
  • BBWriteup@bbwriteup
    General

    "Hunting Bugs in Oracle’s Userspace dtrace using AI: CVE-2026–21996 and CVE-2026–35233" by Gujjuboy10x00 #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@vis_hacker/hunting-bugs-in-oracles-userspace-dtrace-cve-2026-21996-and-cve-2026-35233-56e3704c9c0b

    Post summary

    The tweet announces a Medium article discussing newly identified Oracle vulnerabilities, but the text itself lacks technical, exploit, or patch information.

    0000078
    644 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-21996 Integer Divide-by-Zero Denial of Service in dtrace via Malicious ELF Binary https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21996

    Post summary

    The message briefly identifies CVE‑2026‑21996 as an integer divide‑by‑zero denial of service in dtrace triggered by a malicious ELF binary, but offers no PoC, exploit, or patch details.

    0000046
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21996 An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab() https://www.cve.org/CVERecord?id=CVE-2026-21996 ----- Traducción: CVE-2026-21996 Un atacante… http://infoflow.cloud`

    Post summary

    CVE‑2026‑21996 has been disclosed, describing a divide‑by‑zero error that allows an unprivileged attacker to crash the dtrace process using a crafted ELF binary.

    0000031
    75 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSoraclelinux10--
OSoraclelinux8--
OSoraclelinux9--

Explore more