Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-10722

Опубликовано: 03 июн. 2026
Источник: debian
EPSS Низкий

Описание

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-cilium-ebpffixed0.22.0+ds1-1package
golang-github-cilium-ebpfno-dsatrixiepackage
golang-github-cilium-ebpfno-dsabookwormpackage
golang-github-cilium-ebpfignoredbullseyepackage

Примечания

  • https://github.com/cilium/ebpf/issues/2019

  • https://github.com/cilium/ebpf/pull/2021

  • Fixed by: https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa (v0.22.0)

EPSS

Процентиль: 8%
0.00179
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

CVSS3: 5.5
redhat
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

CVSS3: 3.3
nvd
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

msrc
2 месяца назад

cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow

suse-cvrf
21 день назад

Security update for alloy

EPSS

Процентиль: 8%
0.00179
Низкий