A AegiFlow
LOWCVSS 1.9EPSS 0.2%

CVE-2026-10722

CVE-2026-10722 updated by NVD

Published
2026-06-03
Modified
2026-08-17
EPSS percentile
8%
Sources
github-advisory, nvd

Summary

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/cilium/ebpf0.22.0

Remediation: Upgrade to 0.22.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.