VDB
CVE-2026-10722
CVE-2026-10722
PUBLISHED
CVSS 4.8 MEDIUM
Reported by VulDB · Published June 3, 2026
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
Risk Scores
CVSS 4.0
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cilium | ebpf | 0.1, 0.2, 0.3 |
| wolfi | kuma-2.12 | 0, 0, 0 |
| chainguard | docker-28 | 0, 0 |
| chainguard | gitaly-19.2 | 0, 0 |
| chainguard | vitess-24 | 0, 0 |
| chainguard | envoy-gateway-1.6 | 0, 0 |
| chainguard | gitaly-19.0 | 0, 0 |
| chainguard | kubescape-server-fips | 0, 0 |
| wolfi | kubescape-operator | 0, 0, 0 |
| chainguard | gitaly-fips-19.2 | 0, 0 |
| chainguard | kubescape-operator-fips | 0, 0 |
| chainguard | rke2-runtime-fips-1.34 | 0, 0 |
| chainguard | runc | 0 |
| wolfi | splunk-otel-collector | 0, 0, 0 |
| wolfi | gitaly-19.1 | 0, 0, 0 |
| chainguard | rke2-runtime-1.35 | 0, 0 |
| chainguard | gitaly-fips-19.0 | 0, 0 |
| github.com | cilium/ebpf | 0 |
| wolfi | k3s-1.34 | 0, 0, 0 |
| chainguard | elastic-agent-fips-9.2 | 0, 0 |
…and 93 more
Timeline
- Jun 3, 2026 CVE Published
- Jun 5, 2026 EPSS Score
- Jun 7, 2026 Security Advisory
- Jun 11, 2026 Coalition ESS Score
- Jul 22, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
References
- VDB-368091 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow vdb-entrytechnical-description
- VDB-368091 | CTI Indicators (IOB, IOC, IOA) signaturepermissions-required
- CVE-2026-10722 | CVE Analysis and Report third-party-advisory
- Submit #818291 | Cilium cilium/ebpf v0.19.0-v0.21.0 Denial of Service third-party-advisory
- issue-tracking
- issue-trackingpatch
- exploit
- patch
- product
- https://nvd.nist.gov/vuln/detail/CVE-2026-10722 advisory
- https://github.com/advisories/GHSA-xhgw-qwwf-pg32 advisory
- https://github.com/cilium/ebpf url