VDB
CVE-2025-68388
CVE-2025-68388
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.
EPSS 0.13% · 31.9th percentile
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.13%
31.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| elasticsearch | packetbeat | 8.6.0, 9.0.0, 9.2.0 |
| Elastic | Packetbeat | 9.2.0, 8.6.0, 9.0.0 |
| github.com | elastic/beats/v7 | 0, 0 |
| github.com | elastic/beats | 8.6.0, 9.0.0, 9.2.0 |
Timeline
- Dec 16, 2025 CVE ID Reserved
- Dec 18, 2025 CVE Published
- Dec 19, 2025 EPSS Score
- Dec 19, 2025 PoC Published
- Dec 20, 2025 CVE Updated
- Dec 23, 2025 EPSS Score
- Dec 27, 2025 EPSS Score
- Dec 30, 2025 EPSS Score
- Jan 3, 2026 EPSS Score
- Jan 7, 2026 EPSS Score
- Jan 11, 2026 EPSS Score
- Jan 15, 2026 EPSS Score
References
- https://discuss.elastic.co/t/packetbeat-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-29/384177 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-68388 advisory
- https://github.com/elastic/beats/commit/28cfc80d2f4e80bfd1c72eb3f849d777751ab870 url
- https://github.com/elastic/beats package
- https://discuss.elastic.co/t/kibana-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-38/384186 advisory
- https://discuss.elastic.co/t/kibana-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-34/384182 advisory
- https://discuss.elastic.co/t/packetbeat-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-31/384179 advisory
- https://discuss.elastic.co/t/packetbeat-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-30/384178 advisory
- https://discuss.elastic.co/t/kibana-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-36/384184 advisory
- https://discuss.elastic.co/t/kibana-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-35/384183 advisory
- https://discuss.elastic.co/t/filebeat-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-32/384180 advisory
- https://discuss.elastic.co/t/elasticsearch-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-33/384181 advisory
- https://discuss.elastic.co/t/kibana-8-19-7-9-1-7-and-9-2-1-security-update-esa-2025-39/384187 advisory
- https://discuss.elastic.co/t/elasticsearch-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-37/384185 advisory