Security Advisory

CVE-2026-45683

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 15:25:11
Last updated 2026-06-02 17:48:08
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at kernel memory and cause that memory to be copied into telemetry. This issue has been patched in version 0.9.0.