3.3 CVE-2026-10722
Enriched by CISA Patch Exploit
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
https://nvd.nist.gov/vuln/detail/CVE-2026-10722
Categories
CWE-189
References
cna@vuldb.com Patch Exploit
| https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 Exploit Issue Tracking Mitigation Third Party Advisory |
| https://github.com/cilium/ebpf/ Product |
| https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa Patch |
| https://github.com/cilium/ebpf/issues/2019 Issue Tracking |
| https://github.com/cilium/ebpf/pull/2021 Issue Tracking Patch |
| https://vuldb.com/cve/CVE-2026-10722 Third Party Advisory VDB Entry |
| https://vuldb.com/submit/818291 Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/368091 Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/368091/cti Permissions Required VDB Entry |
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| cilium | ebpf |
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|---|---|
| Configuration 1 | ||
| cpe:2.3:a:cilium:ebpf:*:*:*:*:*:go:*:* | <= 0.21.0 | |
REMEDIATION
Patch
| Url |
|---|
| https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa |
| https://github.com/cilium/ebpf/pull/2021 |
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815 |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| No entry | ||
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
