6.5
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.
Basic Information
ID
CVE-2025-68383
Source
elastic
Published
Dec 18, 2025 at 22:00
Affected Product
Vendor
Elastic
Product
Filebeat
Version
7.0.0
Affected Versions
Elastic Filebeat 7.0.0
Elastic Filebeat 8.0.0
Elastic Filebeat 9.0.0
Elastic Filebeat 9.2.0
Elastic Filebeat 8.0.0
Elastic Filebeat 9.0.0
Elastic Filebeat 9.2.0