CVE-2025-48964: Iputils

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).

Affected products

  • Iputils Iputils: before 20250602 (fixed in 20250602)

Published 2025-07-22. Last modified 2026-06-17.