Impact
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From versions 0.27.0 through 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a crafted /etc/ld.so.cache file while an uprobe‑based gadget is active. The parser in pkg/uprobetracer/ldcache_parser.go trusts the EntryCount field, performs excessive iteration, and uses overflowing uint32 arithmetic to compute cache1Len, repeatedly calling readStringFromBytes where byte‑by‑byte immutable string concatenation produces quadratic work. While this processing occurs, pkg/container-hook holds the fanotify container‑start pause, allowing a crafted cache to delay startup for roughly a minute, prevent Docker from starting other containers, and degrade monitoring. Processing caches from already‑running containers can still consume CPU but does not hold the new‑container startup pause. This issue poses no confidentiality or integrity impact and is fixed in version 0.53.1.
Affected Systems
Inspektor Gadget versions 0.27.0 through 0.53.1 on Kubernetes clusters and Linux hosts. All included packages have the uprobe library resolver that can be triggered by a crafted /etc/ld.so.cache. The CVE affects the stated version range.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to run an unprivileged container that can write a malicious /etc/ld.so.cache file while an uprobe‑based gadget is active. Successful exploitation pauses the startup of new containers for roughly a minute, preventing Docker from starting other containers and causing a denial of service for workloads on the node. Processing caches from already‑running containers can still consume CPU but does not hold the confidentiality or integrity impact is reported, so the threat is limited to availability degradation.
OpenCVE Enrichment
Github GHSA