CVE-2026-35233Disclosure(oracle / linux)

LOWCVSS 4.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch oracle linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-01); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux

3 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-05-01: 3Technical Details · 2026-05-02: 105-0105-0205-18
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-021
Disclosure1
2026-05-181
General1
Full discourse5 posts
  • gujjuboy10x00@vis_hacker
    Disclosure

    Two CVEs just patched by @Oracle , credited to me: CVE-2026-21996 , CVE-2026-35233 Root-privileged parser eating attacker-supplied ELF. Classic trust-boundary bugs. Advisory: https://linux.oracle.com/errata/ELSA-2026-50250.html Write-up: https://medium.com/@vis_hacker/hunting-bugs-in-oracles-userspace-dtrace-cve-2026-21996-and-cve-2026-35233-56e3704c9c0b

    Post summary

    Oracle has announced patches for two privilege‑escalation bugs involving attacker‑supplied ELF files, providing an advisory, a write‑up link, and high‑level technical details, but no active exploitation or exploit code is mentioned.

    01045588
    6.2K followersView on X
  • BBWriteup@bbwriteup
    General

    "Hunting Bugs in Oracle’s Userspace dtrace using AI: CVE-2026–21996 and CVE-2026–35233" by Gujjuboy10x00 #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@vis_hacker/hunting-bugs-in-oracles-userspace-dtrace-cve-2026-21996-and-cve-2026-35233-56e3704c9c0b

    Post summary

    The text merely references two CVEs and a Medium article without providing detailed evidence of exploitation, patches, or technical specifics.

    0000078
    644 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35233 Out-of-Bounds Heap Read in DTrace ELF Parser via Malicious sh_link Field https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35233

    Post summary

    A new vulnerability (CVE-2026-35233) involving an out-of-bounds heap read in DTrace’s ELF parser triggered by a malformed sh_link field has been announced, with no PoC, exploit, patch, or active exploitation details provided.

    0000054
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35233 An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or… https://www.cve.org/CVERecord?id=CVE-2026-35233 ----- Traducción: CVE-2026-35233 Un … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑35233, noting that an unprivileged attacker can craft a malicious ELF binary with an out-of-range sh_link field, but does not mention any PoC, exploit, patch, or active exploitation.

    0000030
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35233 An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or… https://www.cve.org/CVERecord?id=CVE-2026-35233

    Post summary

    The excerpt details CVE-2026-35233, describing how an unprivileged attacker can craft a malicious ELF binary with an out-of-range sh_link field that may affect root-level dtrace usage.

    00000168
    57.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSoraclelinux10--
OSoraclelinux8--
OSoraclelinux9--

Explore more