Description
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a crafted /etc/ld.so.cache file while an uprobe-based gadget is active. The parser in pkg/uprobetracer/ldcache_parser.go trusts EntryCount enough to perform excessive iteration, computes cache1Len with overflowing uint32 arithmetic, and repeatedly calls readStringFromBytes in pkg/uprobetracer/bytes.go, where byte-by-byte immutable string concatenation produces quadratic work. While this processing occurs, pkg/container-hook holds the fanotify container-start pause, allowing a crafted cache to delay startup for roughly a minute, prevent Docker from starting other containers, and degrade monitoring. Processing caches from already-running containers can still consume CPU but does not hold the new-container startup pause, and the advisory establishes no confidentiality or integrity impact. This issue is fixed in version 0.53.1.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: High-CPU utilization and container startup denial of service
Action: Immediate Patch
AI Analysis

Impact

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From versions 0.27.0 through 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a crafted /etc/ld.so.cache file while an uprobe‑based gadget is active. The parser in pkg/uprobetracer/ldcache_parser.go trusts the EntryCount field, performs excessive iteration, and uses overflowing uint32 arithmetic to compute cache1Len, repeatedly calling readStringFromBytes where byte‑by‑byte immutable string concatenation produces quadratic work. While this processing occurs, pkg/container-hook holds the fanotify container‑start pause, allowing a crafted cache to delay startup for roughly a minute, prevent Docker from starting other containers, and degrade monitoring. Processing caches from already‑running containers can still consume CPU but does not hold the new‑container startup pause. This issue poses no confidentiality or integrity impact and is fixed in version 0.53.1.

Affected Systems

Inspektor Gadget versions 0.27.0 through 0.53.1 on Kubernetes clusters and Linux hosts. All included packages have the uprobe library resolver that can be triggered by a crafted /etc/ld.so.cache. The CVE affects the stated version range.

Risk and Exploitability

The CVSS score of 6.9 reflects a moderate severity. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to run an unprivileged container that can write a malicious /etc/ld.so.cache file while an uprobe‑based gadget is active. Successful exploitation pauses the startup of new containers for roughly a minute, preventing Docker from starting other containers and causing a denial of service for workloads on the node. Processing caches from already‑running containers can still consume CPU but does not hold the confidentiality or integrity impact is reported, so the threat is limited to availability degradation.

Generated by OpenCVE AI on September 20, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Inspektor Gadget to v0.53.1 or later to address the uprobe resolver issue.
  • Limit unprivileged containers' ability to write to /etc/ld.so.cache by enforcing strict security contexts.
  • Enable user namespace isolation for containers to prevent them from modifying host files such as /etc/ld.so.cache.

Generated by OpenCVE AI on September 20, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vjhx-2cqw-3q6q Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Inspektor-gadget
Inspektor-gadget inspektor-gadget
Vendors & Products Inspektor-gadget
Inspektor-gadget inspektor-gadget

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a crafted /etc/ld.so.cache file while an uprobe-based gadget is active. The parser in pkg/uprobetracer/ldcache_parser.go trusts EntryCount enough to perform excessive iteration, computes cache1Len with overflowing uint32 arithmetic, and repeatedly calls readStringFromBytes in pkg/uprobetracer/bytes.go, where byte-by-byte immutable string concatenation produces quadratic work. While this processing occurs, pkg/container-hook holds the fanotify container-start pause, allowing a crafted cache to delay startup for roughly a minute, prevent Docker from starting other containers, and degrade monitoring. Processing caches from already-running containers can still consume CPU but does not hold the new-container startup pause, and the advisory establishes no confidentiality or integrity impact. This issue is fixed in version 0.53.1.
Title Inspektor Gadget Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Inspektor-gadget Inspektor-gadget
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:09:02.083Z

Reserved: 2026-06-11T15:46:12.318Z

Link: CVE-2026-53941

cve-icon Vulnrichment

Updated: 2026-09-16T15:08:57.802Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:22.267

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling