Executive brief
OpenTelemetry eBPF Instrumentation is a tool used to monitor and collect data from running applications. A security flaw in its log enrichment feature could allow a local attacker to cause memory corruption or data leakage in an instrumented application. This could lead to application crashes, service instability, or the accidental exposure of sensitive information in system logs.
Technical details
A vulnerability exists in the OBI log enricher's eBPF code (specifically in the __fill_iov and __write functions) where it mishandles writev buffers. The code resolves only the first iovec entry but uses the total byte count (iov_iter.count) from all segments as the length for copy operations. When log injection is enabled, a local attacker can trigger a crafted multi-segment writev call, causing OBI to read and overwrite memory beyond the first segment using bpf_probe_read_user and bpf_probe_write_user. This results in a buffer over-read (CWE-126) and out-of-bounds write (CWE-787), potentially leading to memory disclosure in logs or process corruption. The issue is fixed in version 0.9.0.
Affected products
- OpenTelemetry OpenTelemetry eBPF Instrumentation (OBI) 0.7.0 to 0.8.x (before 0.9.0)
Timeline
- 2026-05-11: patched: Version 0.9.0 released
- 2026-05-12: advisory: GitHub Security Advisory GHSA-vvmg-8mjr-g6q3 published
- 2026-06-02: disclosed: CVE-2026-45684 published to NVD