Resource Exhaustion Vulnerability in Inspektor Gadget by Open-Source Vendor
CVE-2026-53941

6.9MEDIUM

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-53941?

A resource exhaustion vulnerability exists in Inspektor Gadget from versions 0.27.0 to 0.53.1. An unprivileged container may exploit this issue by providing a specially crafted /etc/ld.so.cache file while an uprobe-based gadget is active. This leads to excessive CPU consumption, potentially blocking the startup of other containers. The underlying problem lies in the uprobe library's improper handling of EntryCount during cache parsing, resulting in inefficient processing that can degrade system performance significantly. Though existing containers handle cache parsing without blocking new containers, they can still consume CPU resources. The issue has been resolved in version 0.53.1.

Affected Version(s)

inspektor-gadget >= 0.27.0, < 0.53.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.