MEDIUM GitHub
CVE-2026-53941
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
## Summary
An unprivileged container can block all other containers from starting on the
same host by placing a crafted `/etc/ld.so.cache` file in its filesystem. When
Inspektor Gadget attaches any uprobe-based gadget, it parses this file in the
container startup path. A malicious cache causes ~53 seconds of CPU burn,
during which Docker cannot start any other container. No special capabilities
are required.
## Severity
To be assessed — Availability impact, no confidentiality or integrity imp
Affected Products
- go/github.com/inspektor-gadget/inspektor-gadget >= 0.27.0, < 0.53.1
References
- https://github.com/advisories/GHSA-vjhx-2cqw-3q6q
- https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-vjhx-2cqw-3q
- https://github.com/inspektor-gadget/inspektor-gadget/releases/tag/v0.53.1
- https://github.com/advisories/GHSA-vjhx-2cqw-3q6q
This medium severity vulnerability was published on 2026-08-19 via GitHub. Affected: go/github.com/inspektor-gadget/inspektor-gadget >= 0.27.0, < 0.53.1.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.