CVE-2025-47268
MEDIUM EPSS 67.9%
Published May 5, 20251y ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Published May 5, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability Low
Threat Intelligence
EPSS Exploit Probability
67.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-190 Integer Overflow or Wraparound Numeric Error
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| iputils | iputils | * | <20250602 |
References 6
- bugzilla.suse.com https://bugzilla.suse.com/show_bug.cgi?id=1242300
- github.com https://github.com/Zephkek/ping-rtt-overflow/
- github.com https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40
- github.com https://github.com/iputils/iputils/issues/584
- github.com https://github.com/iputils/iputils/pull/585
- github.com https://github.com/iputils/iputils/releases/tag/20250602
Remediation
- github.com https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40
- github.com https://github.com/iputils/iputils/issues/584
- github.com https://github.com/iputils/iputils/pull/585