OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large <bytes> values and adds the payload delimiter length without checking for overflow. A crafted request with <bytes> set to math.MaxInt or math.MaxInt-1 causes the computed payload length to wrap negative and triggers a runtime panic in LargeBufferReader.Peek. This issue has been patched in version 0.9.0.
References
| Link | Resource |
|---|---|
| https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0 | Product Release Notes |
| https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-43g7-cwr8-q3jh | Exploit Vendor Advisory |
| https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-43g7-cwr8-q3jh | Exploit Vendor Advisory |
Configurations
History
03 Jun 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/releases/tag/v0.9.0 - Product, Release Notes | |
| References | () https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-43g7-cwr8-q3jh - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:opentelemetry:ebpf_instrumentation:*:*:*:*:*:go:*:* | |
| First Time |
Opentelemetry ebpf Instrumentation
Opentelemetry |
03 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/security/advisories/GHSA-43g7-cwr8-q3jh - |
02 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 16:16
Updated : 2026-06-03 16:52
NVD link : CVE-2026-45686
Mitre link : CVE-2026-45686
CVE.ORG link : CVE-2026-45686
JSON object : View
Products Affected
opentelemetry
- ebpf_instrumentation
CWE
CWE-190
Integer Overflow or Wraparound
