Oracle Linux DTrace Component Arbitrary File Creation Vulnerability

Vulnerability

A vulnerability in the DTrace component 'dtprobed' of Oracle Linux allows for arbitrary file creation by exploiting crafted USDT provider names. This issue affects Oracle Linux versions 8, 9, and 10.

Impact

Exploitation of this vulnerability could lead to unauthorized file creation, potentially allowing for further exploitation or manipulation of the system.

Remediation

Users can refer to the Oracle Linux CVE repository for patch details. Specific errata information is available for Oracle Linux versions 8, 9, and 10.

Added: Mar 16, 2026, 10:19 PM
Updated: Mar 16, 2026, 10:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
3.5
remediation
7.7
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.