PT-2026-51617 · Go · Go.Opentelemetry.Io/Ebpf-Profiler
Publicado
2026-06-23
·
Atualizado
2026-06-23
·
CVE-2026-48496
CVSS v3.1
6.2
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Summary
An unprivileged process can easily trigger the
processPIDEvents goroutine to be blocked indefinitely, preventing the goroutine from analyzing any new ELF file. The goroutine stays blocked in the openat2 syscall forever and the profiler can no longer work properly, it is a denial of service.Impact
The impact is limited to denial-of-service on the ebpf-profiler agent:
- There has to be a malicious workload albeit unprivileged.
- No exfiltration of data. No loss of data.
Fix
Fix is part of v.0.0.202622.
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Go.Opentelemetry.Io/Ebpf-Profiler