
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68381 is a buffer overflow vulnerability (CWE-787: Out-of-bounds Write) in Elastic's Packetbeat network packet analyzer that allows a remote unauthenticated attacker to crash the application or cause significant resource exhaustion by sending a single crafted UDP packet with an invalid fragment sequence number. It was published on December 18, 2025, and affects Packetbeat versions 7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, and 9.2.0–9.2.2. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), with the attack vector limited to adjacent network (Elastic Advisory, Red Hat CVE).
The root cause is an improper bounds check (CWE-787) in Packetbeat's UDP packet processing logic, specifically when handling fragment sequence numbers. An attacker can send a single malformed UDP packet containing an invalid fragment sequence number, triggering an out-of-bounds write (CAPEC-100: Buffer Overflow) that reliably crashes the application or causes severe resource exhaustion. No authentication or user interaction is required, and the attack complexity is low, though exploitation is constrained to the adjacent network segment. No public proof-of-concept code has been identified at this time (Elastic Advisory).
Successful exploitation results in a reliable crash of the Packetbeat process or significant resource exhaustion, directly impacting availability with no effect on confidentiality or integrity. Because Packetbeat is a network monitoring and security logging component within the Elastic Stack, its disruption can blind security operations teams to network-level threats and degrade observability pipelines. The impact is scoped to the affected Packetbeat instance and does not directly enable lateral movement or data exfiltration (Elastic Advisory, Red Hat CVE).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.043%, indicating a low probability of exploitation in the near term. The attack is constrained to adjacent network access, which limits the attacker pool to those with network adjacency to the Packetbeat instance (Elastic Advisory).
packetbeat process; repeated restarts of the Packetbeat service in a short time window.journalctl, Windows Event Log) recording abnormal Packetbeat process exits.packetbeat process prior to crash, indicative of resource exhaustion attempts.Elastic has released patched versions of Packetbeat: 8.19.9, 9.1.9, and 9.2.3. Users running versions 7.0.0–7.17.29, 8.0.0–8.19.8, 9.0.0–9.1.8, or 9.2.0–9.2.2 should upgrade immediately. As interim mitigations, restrict network access to Packetbeat instances using network segmentation, implement firewall rules to block malformed or unexpected UDP traffic from untrusted adjacent network sources, and monitor for unexpected application crashes or resource exhaustion (Elastic Advisory).
The vulnerability received standard coverage across vulnerability tracking platforms and security aggregators shortly after disclosure in December 2025. Red Hat published a CVE advisory, and Tenable added detection support via Nessus plugin 281874. No notable researcher commentary or significant social media discussion beyond routine CVE tracking has been identified (Red Hat CVE, Tenable Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."