PT-2026-51617 · Go · Go.Opentelemetry.Io/Ebpf-Profiler

Published

2026-06-23

·

Updated

2026-06-23

·

CVE-2026-48496

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

An unprivileged process can easily trigger the processPIDEvents goroutine to be blocked indefinitely, preventing the goroutine from analyzing any new ELF file. The goroutine stays blocked in the openat2 syscall forever and the profiler can no longer work properly, it is a denial of service.

Impact

The impact is limited to denial-of-service on the ebpf-profiler agent:
  • There has to be a malicious workload albeit unprivileged.
  • No exfiltration of data. No loss of data.

Fix

Fix is part of v.0.0.202622.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48496
GHSA-F2R5-5M7W-P5CX

Affected Products

Go.Opentelemetry.Io/Ebpf-Profiler