CVE-2026-10722

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:cilium:ebpf:*:*:*:*:*:go:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en cilium ebpf hasta 0.21.0. Esto afecta a la función loadRawSpec del archivo btf/btf.go del componente LoadCollectionSpec/LoadCollectionSpecFromReader. Dicha manipulación del argumento offset conduce a un desbordamiento de entero. El ataque solo puede realizarse desde un entorno local. El exploit ha sido divulgado al público y puede ser utilizado. El nombre del parche es 533dfc82fd228bfadf42ea7180c39de7d9af47fa. Debería aplicarse un parche para remediar este problema.

17 Jun 2026, 10:12

Type Values Removed Values Added
References () https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 - Exploit, Issue Tracking, Third Party Advisory, Mitigation () https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 - Exploit, Issue Tracking, Mitigation, Third Party Advisory

10 Jun 2026, 18:28

Type Values Removed Values Added
References () https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 - () https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 - Exploit, Issue Tracking, Third Party Advisory, Mitigation
References () https://github.com/cilium/ebpf/ - () https://github.com/cilium/ebpf/ - Product
References () https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa - () https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa - Patch
References () https://github.com/cilium/ebpf/issues/2019 - () https://github.com/cilium/ebpf/issues/2019 - Issue Tracking
References () https://github.com/cilium/ebpf/pull/2021 - () https://github.com/cilium/ebpf/pull/2021 - Issue Tracking, Patch
References () https://vuldb.com/cve/CVE-2026-10722 - () https://vuldb.com/cve/CVE-2026-10722 - Third Party Advisory, VDB Entry
References () https://vuldb.com/submit/818291 - () https://vuldb.com/submit/818291 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/368091 - () https://vuldb.com/vuln/368091 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/368091/cti - () https://vuldb.com/vuln/368091/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:cilium:ebpf:*:*:*:*:*:go:*:*
First Time Cilium
Cilium ebpf

03 Jun 2026, 14:16

Type Values Removed Values Added
Summary (en) A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue. (en) A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

03 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 13:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-10722

Mitre link : CVE-2026-10722

CVE.ORG link : CVE-2026-10722


JSON object : View

Products Affected

cilium

  • ebpf
CWE
CWE-189

Numeric Errors

CWE-190

Integer Overflow or Wraparound