Impact
Inspektor Gadget is a collection of tools for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The USDT note parser located in pkg/uprobetracer/usdt.go was vulnerable in releases 0.28.0 through 0.53.1; an unprivileged container can provide a custom gadget with a SEC("usdt/...") eBPF section that attaches to a crafted ELF binary. In this scenario, the getUsdtInfo() function reads the .note.stapsdt section without checking that DescSize is large enough for the three required address fields, allowing an out‑of‑bounds slice operation that triggers a panic; it also uses untrusted NameSize and DescSize values for memory allocations that can consume gigabytes. Because the parser invokes the debug/elf package without panic recovery, additional malformed ELF structures can terminate the Inspektor Gadget process. The flaw permits denial of service—crashing or exhausting memory of the privileged Inspektor Gadget process—without enabling code execution or privilege escalation. No bundled gadget shipped by Inspektor Gadget uses USDT probes, so only deployments that explicitly use custom USDT gadgets are affected. The fix is available in version 0.53.1.
Affected Systems
The issue affects the inspektor-gadget:inspektor-gadget product in all releases from 0.28.0 up to and including 0.53.1. Only deployments that include custom USDT gadgets with SEC("usdt/...") eBPF sections are impacted; default gadgets shipped with Inspektor Gadget do not use USDT probes.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity. EPSS is < 1%, reflecting an exceedingly low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local to the Kubernetes cluster: an unprivileged container that can supply a crafted ELF file via a custom USDT gadget can trigger a panic or excessive memory allocation, causing the privileged Inspektor Gadget process to crash or become unresponsive. No privilege escalation or remote code execution is possible, but the denial of service could disrupt cluster monitoring and telemetry services.
OpenCVE Enrichment
Github GHSA