Impact
OpenTelemetry eBPF Profiler is a production‑scale agent used for tracing application behavior across multiple languages. Beginning with version 0.0.202527 and continuing until the release of v0.0.202622, an unprivileged process can sabotage the profiling workflow by requesting that the agent open a nonregular mapping file, such as a FIFO. The agent then blocks indefinitely while attempting to perform ELF analysis, resulting in a denial of service that halts further profiling activity. This flaw is categorized as a resource exhaustion vulnerability.
Affected Systems
The flaw is present in the OpenTelemetry eBPF Profiler for all operating systems where the agent is deployed. Vulnerable releases span 0.0.202527 up to but excluding 0.0.202622; deployments running these versions can be impacted if the attacker has the ability to create arbitrary files in the agent’s working directory.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity that is accessible when the attacker can execute a local process and write to the profiler’s directory. The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalog, it has not yet been widely exploited, but the local denial of service could disrupt operational observability for systems relying on continuous profiling.
OpenCVE Enrichment
Github GHSA