VDB

CVE-2026-10722

CVE-2026-10722 PUBLISHED CVSS 4.8 MEDIUM

Reported by VulDB · Published June 3, 2026

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

Risk Scores

CVSS 4.0
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Affected Products

VendorProductVersions
ciliumebpf0.1, 0.2, 0.3
wolfikuma-2.120, 0, 0
chainguarddocker-280, 0
chainguardgitaly-19.20, 0
chainguardvitess-240, 0
chainguardenvoy-gateway-1.60, 0
chainguardgitaly-19.00, 0
chainguardkubescape-server-fips0, 0
wolfikubescape-operator0, 0, 0
chainguardgitaly-fips-19.20, 0
chainguardkubescape-operator-fips0, 0
chainguardrke2-runtime-fips-1.340, 0
chainguardrunc0
wolfisplunk-otel-collector0, 0, 0
wolfigitaly-19.10, 0, 0
chainguardrke2-runtime-1.350, 0
chainguardgitaly-fips-19.00, 0
github.comcilium/ebpf0
wolfik3s-1.340, 0, 0
chainguardelastic-agent-fips-9.20, 0

…and 93 more

Timeline

  • Jun 3, 2026 CVE Published
  • Jun 5, 2026 EPSS Score
  • Jun 7, 2026 Security Advisory
  • Jun 11, 2026 Coalition ESS Score
  • Jul 22, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›