CVE-2025-68388

Aliases:GHSA-fj69-23m4-ccvvGO-2025-4253CGA-24h3-www6-2jgpCGA-26r6-4v9g-3vmfCGA-2836-ppr7-h6qjCGA-2cm2-qch3-8484CGA-2f5g-59fc-846cCGA-2g3w-f8r9-92j5CGA-2gq5-q54m-f2xhCGA-2gxp-cj2f-6jqjCGA-2jqh-58p8-wgpxCGA-2jx7-v78q-gfgfCGA-2mqq-rcfp-78hqCGA-2rm8-7qp9-j8g3CGA-2vq9-x23h-m7g7CGA-2vrm-c9vj-x46jCGA-2vxm-v27g-qxf7CGA-32hq-q5q7-vjgjCGA-33fq-9rj5-84fhCGA-33mr-j66g-mmpvCGA-33pp-xrgg-jrp8CGA-37mw-mhfx-6f8rCGA-38cg-qph4-cg4jCGA-38xv-3vp3-mrghCGA-3c2q-j837-3hpwCGA-3cx8-xc3j-fhhgCGA-3gpm-99v6-v3w7CGA-3gpr-p2w3-jrv9CGA-3hvf-wpg7-fx2jCGA-3p89-gp5q-h7vqCGA-3pm8-p33v-982fCGA-3pp8-7pcw-h4fjCGA-3vcx-x439-m9hmCGA-3x3q-rgvw-f4ffCGA-3xj2-rq4m-j2rxCGA-456q-cfgf-7pg7CGA-473h-3g23-ww3cCGA-47wr-2fg4-xxm7CGA-498q-whgj-hrv3CGA-49q5-crv9-wpr8CGA-4f3g-f8c8-j55xCGA-4frx-mxvv-wcx3CGA-4gh6-m7xv-pmwvCGA-4gqm-ww92-pq9rCGA-4hqw-c5h6-g63mCGA-4j94-8qv8-3j2pCGA-4mh9-g99m-rx7xCGA-4q2g-qwwf-44cwCGA-4r52-rcmq-8394CGA-4r7g-642h-6m84CGA-4vhx-wr9v-2qq7CGA-4whf-xmp6-v4g8CGA-4xjg-pqxv-8h9wCGA-525p-4hxw-pf9pCGA-529q-x3h9-3m4fCGA-5462-2vh5-m2wwCGA-565m-6mf8-23vcCGA-56wr-2jx6-25m5CGA-589r-gggj-6mvmCGA-59px-rqr7-wrc6CGA-5fpv-m4c7-vwghCGA-5g92-v88g-7xcpCGA-5j79-36r2-94hgCGA-5jxv-vwcm-gpphCGA-5wpf-g9pp-jg85CGA-5x2g-5rpw-h46fCGA-64rr-86r5-wvrwCGA-67fj-w6p9-43vpCGA-6cj8-g75x-f73qCGA-6fvp-h3ff-fm9wCGA-6m4m-6w6p-f2fmCGA-6p5q-5943-hhf7CGA-6qp6-p3vr-pp5gCGA-6v8c-9542-9rfvCGA-6xrv-qh7v-frrpCGA-7226-f64w-p3w8CGA-76vx-cp7c-h338CGA-7736-vjr5-jgg9CGA-7829-fg59-4x3cCGA-794m-72vc-42hpCGA-794p-xf37-q7v6CGA-7hh6-r6fr-jgp9CGA-7ph5-w43m-pc94CGA-7qpp-2463-r9f3CGA-7rq6-vfgj-6r4hCGA-7rqg-hhpg-wrvpCGA-7rqq-63fh-jc5gCGA-7v84-5gmp-xv6xCGA-7v8p-3373-rx5wCGA-7xw7-4jx6-hxrmCGA-8237-r5p3-p89hCGA-82q3-prjw-94wxCGA-8389-3jjg-m94rCGA-85jr-x84p-5f4qCGA-868x-2q97-8wmxCGA-8832-9chj-9xm4CGA-8989-rrr2-8qhmCGA-89vc-vjjj-3cw3CGA-8cq7-9g9f-vwmqCGA-8m9c-r4j7-gf2wCGA-8ppc-5qm7-9f2xCGA-8pv7-5mvm-8h98CGA-8r87-68gw-5mr8CGA-8v9x-wx6q-vcpfCGA-8w5r-9hxj-7mj8CGA-8xgh-w4vf-cm8pCGA-93hw-q7xr-c5mwCGA-959q-9wgx-gf2mCGA-95pm-v598-3937CGA-96pv-5xjm-784pCGA-98h8-4gg4-f9pjCGA-9963-999v-823vCGA-9gh9-f6qg-3wmmCGA-9gjj-wwwx-x9hcCGA-9h5v-g67m-qpchCGA-9hr7-7m85-mmfgCGA-9jvj-2j4c-qmcxCGA-9mqp-c8vm-mhmxCGA-9q89-5x3q-6g5mCGA-9w5w-qf7j-m27jCGA-9wm6-hx4x-gvcwCGA-9xj8-x365-qfqrCGA-9xr7-26jv-frh8CGA-9xrc-2gqp-528gCGA-c2pf-cq7c-6cp8CGA-c2qp-9233-8wv8CGA-c2xx-hh73-v9gxCGA-c344-fqx2-g5xqCGA-c48j-29j5-gfwgCGA-c5qg-8vwv-cp74CGA-c7mh-jxvr-rjrpCGA-c7rf-7mw2-7pjrCGA-c7v3-xq4g-pf7wCGA-cc6w-v6gf-9r4xCGA-cmqx-v5q8-hhm7CGA-cqw2-h7hc-9f8hCGA-crw6-53pp-3qh5CGA-cwjq-3hvq-wqpwCGA-f2c6-7j7j-h3v9CGA-f3fp-59j5-qh4pCGA-f3h5-3fwr-3xgpCGA-f4gq-w976-36wjCGA-f5pv-8hq6-j8vgCGA-f62w-w5fh-jrc9CGA-f76j-hm3v-phjwCGA-f9qh-7w6v-6cp8CGA-ff5f-xhcm-xfpjCGA-ffv7-h74g-537vCGA-fghm-mchv-vr8gCGA-fgmh-vrfp-6mf2CGA-fgpq-6j24-gjw5CGA-fm85-924p-6222CGA-fqcc-97ch-hxq5CGA-fqcv-8xfx-mgfvCGA-g28v-c6f8-2v55CGA-g2c5-g5vf-jfhfCGA-g4vq-wcf5-gg7jCGA-g67j-q8p4-pwqpCGA-g6vf-8h79-3xw2CGA-g83m-xv9h-cgp9CGA-g96p-fxhv-7g4jCGA-g9m8-6rww-jgfqCGA-gfcv-g2x4-qrfgCGA-ggfq-xf4x-8hvhCGA-gmj5-8w2c-ghj7CGA-gqf5-4g55-v5mhCGA-gr2p-qq2r-4c48CGA-grxg-c7h4-22q7CGA-gvfw-735g-wf6pCGA-gx75-69mv-c7m6CGA-h2w7-2jvw-gpq9CGA-h6j4-w7xj-v7mrCGA-h7pg-6mvv-fp95CGA-h83w-636h-h43rCGA-h98p-j2c3-74mcCGA-hf67-ffqp-w9j7CGA-hfm3-c82w-j3vmCGA-hj8q-cgm6-wh2cCGA-hjcf-5mcf-c2vqCGA-hjpq-v4pg-8f8pCGA-hvh5-2g5v-7qjvCGA-j273-7mhj-wq53CGA-j3hp-h4j7-9p74CGA-j4xc-hv4m-29r7CGA-j5pw-v3pv-9w5cCGA-j6c6-hrxg-4762CGA-jcgw-gmg9-gv6hCGA-jfx8-7g2c-pf8qCGA-jg7j-w7xh-x6wqCGA-jhrh-r83c-r28mCGA-jjqw-376g-w8vmCGA-jmxq-8rff-hqwxCGA-jpcp-99pp-64rfCGA-jpfm-mff7-f92vCGA-jqw2-x7qr-8rxrCGA-jr7q-8524-r5cmCGA-jv8m-75pr-wjm9CGA-jx6x-7286-m9qpCGA-jxjv-4cmg-9m8rCGA-m2rg-fv66-5q7xCGA-m399-xhc9-46q9CGA-m43g-fx49-x36mCGA-m4g9-j3xf-9m2jCGA-m569-vj9p-38pvCGA-m795-6fm3-whwvCGA-mcw8-78ff-h2v8CGA-mffw-qvcc-43g6CGA-mg3h-2cw3-5rwvCGA-mgh9-vq5w-62g4CGA-mh97-mg4m-p7qrCGA-mj39-m7gh-7h98CGA-mjj4-77hh-5c85CGA-mq6c-hv9q-f6p9CGA-mqh5-x788-rq33CGA-mx48-cg89-4wjxCGA-mxc9-m3pj-8g27CGA-p478-67rj-c9mhCGA-p5m8-r4jp-4qpmCGA-p5p9-7945-22g2CGA-p6r5-9m56-hr5vCGA-p73r-g762-rm47CGA-p967-9997-jjxrCGA-p9cv-hwpg-6c58CGA-pc26-ffrg-72q2CGA-pcv3-f4hm-g75mCGA-ppjw-qmjw-p47pCGA-prwv-3732-944qCGA-pv8p-95w7-m288CGA-pvhr-mpp7-qxrwCGA-q325-hfjj-5pqvCGA-q65x-xc9c-3p9cCGA-q95q-9fjq-vqm3CGA-qf2q-cr2c-38cfCGA-qf53-5wrh-pp3vCGA-qhc8-m78j-2pmrCGA-qhqc-v8mw-69r6CGA-qjmv-7v3j-mrrjCGA-qpf4-v6g3-q3j5CGA-qr3q-cmcq-cqpjCGA-qwj9-f63q-9xwfCGA-r4w3-45vw-6qghCGA-r59h-wcfw-w5pxCGA-r5g4-jwrq-v22gCGA-r6rp-79g5-gvrpCGA-r79v-226w-q8r8CGA-r89h-p7rr-g4qhCGA-r9gv-wf4p-p5mqCGA-rhm8-gchr-c64xCGA-rjhm-6pvc-hwm4CGA-rm7c-7wf7-r9chCGA-rph4-h244-x8vjCGA-rqgq-xp73-9m6hCGA-rr2j-9f8w-84gvCGA-rvfm-mc2w-75f5CGA-rvm7-9f8m-p4mcCGA-rw26-2v52-7g28CGA-rw9h-m3pw-72pwCGA-v2cj-m9v8-q449CGA-v2h5-hhgm-29mwCGA-v3p2-8929-82pmCGA-v55c-m9jm-g84gCGA-v84g-89x5-6vhrCGA-v9f6-2xjw-54wqCGA-vg37-2w7f-x48pCGA-vj6v-c6hx-xqqpCGA-vwww-3474-wvqxCGA-vx44-q8f2-8h98CGA-vxpv-mxqm-7jmmCGA-w329-w8pp-jmvmCGA-w4fv-vxqh-jcgmCGA-w6f9-fvgp-3w5fCGA-w78f-53h7-3g99CGA-w834-m3xf-hjccCGA-w98g-2p24-93rgCGA-wc28-475x-xpwmCGA-wf4f-j324-5xxcCGA-wfmr-mfq7-phm5CGA-wj77-hpr8-mq6fCGA-wv66-vhwx-w3hgCGA-x258-rx6r-38pqCGA-x2v7-x8p2-77c9CGA-x55q-xvvp-p6j9CGA-x5rh-gvrg-rfj8CGA-x5rx-rx8m-xcjcCGA-x6qv-6hx7-4ff7CGA-x6v7-f5jr-43vpCGA-xc3r-h2v9-q5j9CGA-xfwp-r7v6-wjmqCGA-xgcv-3h32-9qmvCGA-xj2r-w5p9-c46hCGA-xm6q-254x-mq55CGA-xpqx-485h-73mcCGA-xpv8-75pq-5wqj
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 18 Dec 2025, 21:33
Last modified:19 Dec 2025, 11:46

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.41% LOW
0% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Dec 2025, 21:33
Published
Vulnerability first disclosed
19 Dec 2025, 11:46
Last Modified
Vulnerability information updated

Description

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.41% Percentile: 35%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardagentbeat

    < 0

  • chainguardagentbeat-fips

    < 0

  • chainguardapm-server-8.17

    all

  • chainguardapm-server-8.18

    all

  • chainguardapm-server-8.19

    < 8.19.11-r0

  • chainguardapm-server-9.0

    all

  • chainguardapm-server-9.1

    all

  • chainguardapm-server-9.2

    < 9.2.3-r1

  • chainguardapm-server-9.2-compat

    < 9.2.3-r1

  • chainguardapm-server-fips-8.17

    all

  • chainguardapm-server-fips-8.18

    all

  • chainguardapm-server-fips-8.19

    < 8.19.11-r0

  • chainguardapm-server-fips-9.0

    all

  • chainguardapm-server-fips-9.1

    all

  • chainguardapm-server-fips-9.2

    < 9.2.3-r1

  • chainguardapm-server-fips-9.2-compat

    < 9.2.3-r1

  • chainguardauditbeat-8.17

    all

  • chainguardauditbeat-8.18

    all

  • chainguardauditbeat-8.19

    < 0

  • chainguardauditbeat-8.19-oci-entrypoint

    < 0

  • chainguardauditbeat-9.0

    all

  • chainguardauditbeat-9.1

    < 0

  • chainguardauditbeat-9.1-oci-entrypoint

    < 0

  • chainguardauditbeat-9.2

    < 0

  • chainguardauditbeat-9.2-oci-entrypoint

    < 0

  • chainguardauditbeat-9.3

    < 0

  • chainguardauditbeat-9.4

    < 0

  • chainguardauditbeat-fips-8.17

    all

  • chainguardauditbeat-fips-8.18

    all

  • chainguardauditbeat-fips-8.19

    < 0

  • chainguardauditbeat-fips-9.0

    all

  • chainguardauditbeat-fips-9.1

    < 0

  • chainguardauditbeat-fips-9.2

    < 0

  • chainguardauditbeat-fips-9.3

    < 0

  • chainguardauditbeat-fips-9.4

    < 0

  • chainguardauditbeat-fips-9.5

    < 0

  • chainguardbeats-8.19

    < 0

  • chainguardbeats-9.1

    < 0

  • chainguardbeats-9.2

    < 0

  • chainguardbeats-fips-8.19

    < 0

  • chainguardbeats-fips-9.1

    < 0

  • chainguardbeats-fips-9.2

    < 0

  • chainguardcloudbeat-8.17

    all

  • chainguardcloudbeat-8.18

    all

  • chainguardcloudbeat-8.19

    < 8.19.12-r0

  • chainguardcloudbeat-9.0

    all

  • chainguardcloudbeat-9.1

    all

  • chainguardcloudbeat-9.2

    < 9.2.6-r0

  • chainguardcloudbeat-9.3

    < 0

  • chainguardcloudbeat-fips-8.17

    all

Showing first 50 affected entries in server-rendered view.

References (6)