yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-47268
Component Overview
Vulnerability Overview
Name
CVE-2025-47268
Source
NVD (
link
)
Debian (
link
)
Description
ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.
CWEs
CWE-190
Published Date
May 5, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.suse.com/show_bug.cgi?id=1242300
Issue Tracking
https://github.com/Zephkek/ping-rtt-overflow/
Exploit
https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40
Patch
https://github.com/iputils/iputils/issues/584
Exploit
https://github.com/iputils/iputils/pull/585
Exploit
https://github.com/iputils/iputils/releases/tag/20250602
Release Notes
https://github.com/Zephkek/ping-rtt-overflow/
Exploit
Analysis
#
Affected Component
Analysis
iputils
Patched
Vulnerability Ratings
#
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
iputils
buildroot
2025.02.x
20250605
Not Affected
iputils
buildroot
master
20250605
Not Affected
iputils
openwrt
master
20250605-r1
Not Affected
iputils
openwrt
openwrt-25.12
20250605-r1
Not Affected
iputils
yocto
kirkstone
20211215
Patched
iputils
yocto
master
20250605
Not Affected
Resolved with patches
#
iputils (yocto:kirkstone)
#
Title
Author
Resolve
1
ping: Fix signed 64-bit integer overflow in RTT calculation
Petr Vorel <pvorel@suse.cz>
CVE-2025-47268
iputils (yocto:scarthgap)
#
Title
Author
Resolve
1
ping: Fix signed 64-bit integer overflow in RTT calculation
Petr Vorel <pvorel@suse.cz>
CVE-2025-47268