Vulnerability Description
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elasticsearch | Packetbeat | >= 7.0.0, <= 7.17.29 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-68382?
CVE-2025-68382 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable ...
How severe is CVE-2025-68382?
CVE-2025-68382 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-68382?
Check the references section above for vendor advisories and patch information. Affected products include: Elasticsearch Packetbeat.