Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10722

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

A flaw was found in the cilium/ebpf Go library (versions up to 0.21.0). An integer overflow in the loadRawSpec function (btf/btf.go) when parsing BTF collection specs can cause excessive memory allocation or parsing failure. A local attacker who can supply a crafted eBPF collection spec to an application using this library could trigger a denial of service.

Отчет

The cilium/ebpf library is vulnerable to an integer overflow in loadRawSpec when loading BTF collection specifications. A local attacker with low privileges who can provide a malicious collection spec to a process that uses LoadCollectionSpec or LoadCollectionSpecFromReader can cause denial of service (availability impact only). CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (5.5). Affects Red Hat products that bundle github.com/cilium/ebpf, including OpenShift, CNV, bpfman, network observability, and other container/runtime components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Under investigation
Multiarch Tuning Operatormultiarch-tuning/multiarch-tuning-operator-bundleUnder investigation
Multiarch Tuning Operatormultiarch-tuning/multiarch-tuning-rhel9-operatorUnder investigation
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Under investigation
Network Observability Operatornetwork-observability/network-observability-ebpf-agent-rhel9Under investigation
Network Observability Operatornetwork-observability/network-observability-flowlogs-pipeline-rhel9Under investigation
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Under investigation
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Under investigation
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Under investigation
Red Hat Advanced Cluster Management for Kubernetes 2redhat-user-workloads/prometheus-acm-211Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2484348github.com/cilium/ebpf: Cilium ebpf: Denial of Service via integer overflow

EPSS

Процентиль: 8%
0.00179
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

CVSS3: 3.3
nvd
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

msrc
2 месяца назад

cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow

CVSS3: 3.3
debian
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affec ...

CVSS3: 3.3
github
2 месяца назад

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

EPSS

Процентиль: 8%
0.00179
Низкий

5.5 Medium

CVSS3