{
  "threat_severity" : "Moderate",
  "public_date" : "2025-05-05T00:00:00Z",
  "bugzilla" : {
    "description" : "iputils: Signed Integer Overflow in Timestamp Multiplication in iputils ping",
    "id" : "2364090",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2364090"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-190",
  "details" : [ "ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.", "A flaw was found in iputils ping, where a signed integer overflow occurs in timestamp multiplication. This issue could lead to incorrect timestamp calculations or denial of service when processing crafted ICMP Echo Reply packets." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2025-06-24T00:00:00Z",
    "advisory" : "RHSA-2025:9421",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.0",
    "package" : "iputils-0:20240905-2.el10_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-06-24T00:00:00Z",
    "advisory" : "RHSA-2025:9432",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "iputils-0:20210202-11.el9_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-06-24T00:00:00Z",
    "advisory" : "RHSA-2025:9432",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "iputils-0:20210202-11.el9_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2025-07-16T00:00:00Z",
    "advisory" : "RHSA-2025:11321",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "iputils-0:20210202-8.el9_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Extended Update Support",
    "release_date" : "2025-07-16T00:00:00Z",
    "advisory" : "RHSA-2025:11320",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.4",
    "package" : "iputils-0:20210202-9.el9_4.3"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "iputils",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "iputils",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "iputils",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-47268\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-47268\nhttps://github.com/Zephkek/ping-rtt-overflow/\nhttps://github.com/iputils/iputils/issues/584" ],
  "name" : "CVE-2025-47268",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}