QSearchQSearch

CVE-2026-45676

5.5 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard

Published: 2026-06-02 · Last updated: 2026-06-03

Severity and scoring

CVSS
5.5 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-20, CWE-248

Affected products

VendorProduct
opentelemetryebpf_instrumentation

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string offsets from the executable file. A crafted local ELF can make OBI dereference invalid section pointers or slice past string tables, causing the agent to panic while determining the process language. This issue has been patched in version 0.9.0.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-45686 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard (7.5 HIGH)
  • CVE-2026-45685 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard (7.5 HIGH)
  • CVE-2026-45684 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard (4.9 MEDIUM)
  • CVE-2026-45683 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard (3.8 LOW)
  • CVE-2026-45682 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard (5.1 MEDIUM)

Same CWE

  • CVE-2026-45329 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (7.1 HIGH)
  • CVE-2026-45328 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework (9.3 CRITICAL)
  • CVE-2026-46545 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm (7.5 HIGH)
  • CVE-2026-46411 FlashMQ is a MQTT broker/server, designed for multi-CPU environments (6.5 MEDIUM)
  • CVE-2026-41727 Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them (6.5 MEDIUM)