PT-2025-52355 · Elastic+1 · Packetbeat+1

·

CVE-2025-68388

·

Published

2025-12-18

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Packetbeat (affected versions not specified)
Description An unauthenticated remote attacker can cause excessive allocation of memory and CPU resources in Packetbeat through the manipulation of malicious IPv4 fragments. This resource exhaustion can lead to a degradation in the performance of the software. The issue involves a lack of limits or throttling during resource allocation, as described by CWE-770 and CAPEC-130.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03567
CVE-2025-68388
GHSA-FJ69-23M4-CCVV
GO-2025-4253
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0292-1

Affected Products

Packetbeat
Red Os