Logo
vulnerabilityCVE-2025-48964
Name
CVE-2025-48964
Source
NVD ( link)Debian ( link)
Description
ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
iputils
Patched

Vulnerability Ratings#


6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
20250605
Not Affected
buildroot
master
20250605
Not Affected
openwrt
master
20250605-r1
Not Affected
openwrt
openwrt-25.12
20250605-r1
Not Affected
yocto
master
20250605
Not Affected
yocto
scarthgap
20240117
Patched

Resolved with patches#


iputils (yocto:kirkstone)

#
Title
Author
Resolve
1
ping: Fix moving average rtt calculation
Cyril Hrubis <metan@ucw.cz>
CVE-2025-48964

iputils (yocto:scarthgap)

#
Title
Author
Resolve
1
ping: Fix moving average rtt calculation
Cyril Hrubis <metan@ucw.cz>
CVE-2025-48964