PT-2026-51617 · Unknown · Opentelemetry-Ebpf-Profiler

CVE-2026-48496

·

Published

2026-06-23

·

Updated

2026-09-11

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions opentelemetry-ebpf-profiler versions prior to 0.0.202622
Description An unprivileged process can cause a denial of service on the ebpf-profiler agent by triggering the processPIDEvents goroutine to block indefinitely. This occurs when the goroutine remains stuck in the openat2 syscall, preventing the analysis of new ELF (Executable and Linkable Format) files and rendering the profiler non-functional.
Recommendations Update to version 0.0.202622.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-MA24172
CVE-2026-48496
GHSA-F2R5-5M7W-P5CX
GO-2026-5343
OPENSUSE-SU-2026:21483-1

Affected Products

Opentelemetry-Ebpf-Profiler