loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow.This vulnerability is referenced as CVE-2026-10722. The attack can only be performed from a local environment. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.