CVE-2026-45681

MEDIUM

OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

Title source: cna
STIX 2.1

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch occurs, OBI can read beyond the fallback buffer and leak adjacent memory into telemetry. This issue has been patched in version 0.9.0.

Scores

CVSS v3 5.9
EPSS 0.0024
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-130
Status published
Products (3)
go.opentelemetry.io/obi 0 - 0.9.0Go
open-telemetry/opentelemetry-ebpf-instrumentation < 0.9.0
opentelemetry/ebpf_instrumentation < 0.9.0
Published Jun 02, 2026
Tracked Since Jun 02, 2026