CVE-2025-48964 is a denial-of-service vulnerability affecting the 'ping' utility in iputils versions prior to 20250602. It arises from an incomplete fix for a previous CVE, where a crafted ICMP Echo Reply packet containing a zero timestamp can lead to an integer overflow during statistics calculations in adaptive ping mode. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity to cause a denial of service (application error or incorrect data collection). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 20250602CPE match | cpe:2.3:a:iputils:iputils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025iputils: iputils integer overflow
Jul 22, 2025ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).
Jul 8, 2025