CVE-2026-35233
published 2026-05-01CVE-2026-35233: An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches…
PriorityP418medium4.4CVSS 3.1
AVLACLPRLUINSUCNILAL
EPSS
0.11%
1.4th percentile
An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle_corporation | oracle_linux | — | — |
| oracle_corporation | oracle_linux | — | — |
| oracle_corporation | oracle_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Linux 8/9/10 ELF Parser sh_link null pointer dereference (EUVD-2026-26702)
vuldb·2026-05-01·CVSS 4.4
CVE-2026-35233 [MEDIUM] Oracle Linux 8/9/10 ELF Parser sh_link null pointer dereference (EUVD-2026-26702)
A vulnerability classified as problematic was found in Oracle Linux 8/9/10. This affects an unknown part of the component ELF Parser. The manipulation of the argument sh_link results in null pointer dereference.
This vulnerability is known as CVE-2026-35233. Attacking locally is a requirement. No exploit is available.
GHSA
GHSA-cjc5-j2ff-wq2w: An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field
ghsa_unreviewed·2026-05-01
CVE-2026-35233 [MEDIUM] CWE-125 GHSA-cjc5-j2ff-wq2w: An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field
An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-01
Published