Description
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the memory of the privileged Inspektor Gadget process when a custom gadget containing a SEC("usdt/...") eBPF section attaches to a crafted ELF binary. The getUsdtInfo() function reads the .note.stapsdt section without validating that DescSize is large enough for three address fields, allowing an out-of-bounds slice operation to panic, and it uses untrusted NameSize and DescSize values for allocations that can consume gigabytes of memory. The parser also invokes debug/elf without panic recovery, allowing other malformed ELF structures to terminate the process. No gadget shipped by Inspektor Gadget uses USDT probes, so only deployments using custom USDT gadgets are affected, and the demonstrated impact is denial of service rather than code execution or privilege escalation. This issue is fixed in version 0.53.1.
Published: 2026-09-15
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Inspektor Gadget is a collection of tools for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The USDT note parser located in pkg/uprobetracer/usdt.go was vulnerable in releases 0.28.0 through 0.53.1; an unprivileged container can provide a custom gadget with a SEC("usdt/...") eBPF section that attaches to a crafted ELF binary. In this scenario, the getUsdtInfo() function reads the .note.stapsdt section without checking that DescSize is large enough for the three required address fields, allowing an out‑of‑bounds slice operation that triggers a panic; it also uses untrusted NameSize and DescSize values for memory allocations that can consume gigabytes. Because the parser invokes the debug/elf package without panic recovery, additional malformed ELF structures can terminate the Inspektor Gadget process. The flaw permits denial of service—crashing or exhausting memory of the privileged Inspektor Gadget process—without enabling code execution or privilege escalation. No bundled gadget shipped by Inspektor Gadget uses USDT probes, so only deployments that explicitly use custom USDT gadgets are affected. The fix is available in version 0.53.1.

Affected Systems

The issue affects the inspektor-gadget:inspektor-gadget product in all releases from 0.28.0 up to and including 0.53.1. Only deployments that include custom USDT gadgets with SEC("usdt/...") eBPF sections are impacted; default gadgets shipped with Inspektor Gadget do not use USDT probes.

Risk and Exploitability

The CVSS score of 2.9 indicates a low severity. EPSS is < 1%, reflecting an exceedingly low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local to the Kubernetes cluster: an unprivileged container that can supply a crafted ELF file via a custom USDT gadget can trigger a panic or excessive memory allocation, causing the privileged Inspektor Gadget process to crash or become unresponsive. No privilege escalation or remote code execution is possible, but the denial of service could disrupt cluster monitoring and telemetry services.

Generated by OpenCVE AI on September 20, 2026 at 15:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Inspektor Gadget to version 0.53.1 or later, where the USDT note parser is fixed.
  • If custom USDT gadgets are required, remove or disable them; otherwise, ensure that no untrusted ELF files can be processed by the parser.
  • Audit Kubernetes deployments to confirm that only trusted, tested eBPF code is used and that containers cannot supply arbitrary ELF binaries to the inspection framework.

Generated by OpenCVE AI on September 20, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7cfq-5mhv-jrp9 Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)
History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Inspektor-gadget
Inspektor-gadget inspektor-gadget
Vendors & Products Inspektor-gadget
Inspektor-gadget inspektor-gadget

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the memory of the privileged Inspektor Gadget process when a custom gadget containing a SEC("usdt/...") eBPF section attaches to a crafted ELF binary. The getUsdtInfo() function reads the .note.stapsdt section without validating that DescSize is large enough for three address fields, allowing an out-of-bounds slice operation to panic, and it uses untrusted NameSize and DescSize values for allocations that can consume gigabytes of memory. The parser also invokes debug/elf without panic recovery, allowing other malformed ELF structures to terminate the process. No gadget shipped by Inspektor Gadget uses USDT probes, so only deployments using custom USDT gadgets are affected, and the demonstrated impact is denial of service rather than code execution or privilege escalation. This issue is fixed in version 0.53.1.
Title Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 2.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Inspektor-gadget Inspektor-gadget
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:19:41.631Z

Reserved: 2026-05-07T19:20:44.689Z

Link: CVE-2026-44778

cve-icon Vulnrichment

Updated: 2026-09-17T16:19:34.459Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T17:17:14.970

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-44778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation