7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to denial-of-service in Packetbeat.
Basic Information
ID
CVE-2025-68388
Source
elastic
Published
Dec 18, 2025 at 21:33
Modified
Dec 18, 2025 at 21:48
Affected Product
Vendor
Elastic
Product
Packetbeat
Version
7.0.0
Affected Versions
Elastic Packetbeat 7.0.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0
Elastic Packetbeat 8.0.0
Elastic Packetbeat 9.0.0
Elastic Packetbeat 9.2.0