Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vvmg-8mjr-g6q3 | OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy length. When log injection is enabled, a crafted multi-segment writev call can make OBI read and overwrite memory beyond the first segment. This issue has been patched in version 0.9.0. | |
| Title | OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers | |
| Weaknesses | CWE-126 CWE-787 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T15:25:32.538Z
Reserved: 2026-05-12T21:59:25.667Z
Link: CVE-2026-45684
Updated: 2026-06-02T15:55:24.083Z
Status : Received
Published: 2026-06-02T16:16:43.187
Modified: 2026-06-02T16:16:43.187
Link: CVE-2026-45684
No data.
OpenCVE Enrichment
No data.
Github GHSA