6.5
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.
Basic Information
ID
CVE-2025-68381
Source
elastic
Published
Dec 18, 2025 at 21:51
Modified
Dec 18, 2025 at 22:03
Affected Product
Vendor
Elastic
Product
Packetbeat
Version
7.0.0
Affected Versions
Elastic Packetbeat 7.0.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0