CVE-2025-68382

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*
cpe:2.3:a:elasticsearch:packetbeat:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-18 22:16

Updated : 2025-12-23 17:43


NVD link : CVE-2025-68382

Mitre link : CVE-2025-68382

CVE.ORG link : CVE-2025-68382


JSON object : View

Products Affected

elasticsearch

  • packetbeat
CWE
CWE-125

Out-of-bounds Read