CVE-2026-45683CWE-127CWE-200

OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

Low · published June 2, 2026

CVSS v3.1
3.8
EPSS
0%
Percentile
7.0
In the wild
Unconfirmed
What it is

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at kernel memory and cause that memory to be copied into telemetry. This issue has been patched in version 0.9.0.

The record
Technical detail
CVSS v3.1
3.8 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00174 · 7.0th percentile
Weaknesses
CWE-127 · Buffer Under-read; CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
Published
2026-06-02T15:25Z
EPSS history
Timeline
  • 02 JUN 15:25Z
    OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
    cvelistv5