CVE-2025-68383

Aliases:GHSA-2mj3-6grc-px38GO-2025-4252
Advisory lineage Upstream: 0 Downstream: 1
Analyzed
Published: 18 Dec 2025, 22:00
Last modified:19 Dec 2025, 15:15

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.03% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Dec 2025, 22:00
Published
Vulnerability first disclosed
19 Dec 2025, 15:15
Last Modified
Vulnerability information updated

Description

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.03% Percentile: 9%

Techniques & Countermeasures

  • CWE-1284Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Affected Systems

  • elasticfilebeat

    ≥ 8.0.0, ≤ 8.19.8 | ≥ 9.0.0, ≤ 9.1.8 | ≥ 9.2.0, ≤ 9.2.2 | ≥ 7.0.0, ≤ 7.17.29 | ≥ 8.0.0, < 8.19.9 | ≥ 9.0.0, < 9.1.9 | ≥ 9.2.0, < 9.2.3

  • github.com/elasticbeats

    ≤ 7.6.2 | all

  • github.com/elastic/beatsv7

    ≥ 7.7.0, < 8.19.9 | ≥ 9.0.0, < 9.1.9 | ≥ 9.2.0, < 9.2.3 | < 7.0.0-alpha2.0.20251204214633-dd3af18220bf | ≥ 7.7.0, < 7.0.0-alpha2.0.20251204214633-dd3af18220bf

References (7)