An unprivileged process can easily trigger the processPIDEvents goroutine to be blocked indefinitely, preventing the goroutine from analyzing any new ELF file. The goroutine stays blocked in the openat2 syscall forever and the profiler can no longer work properly, it is a denial of service.
The impact is limited to denial-of-service on the ebpf-profiler agent:
Fix is part of v.0.0.202622.
{
"cwe_ids": [
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-23T22:16:14Z",
"nvd_published_at": null,
"severity": "MODERATE"
}