Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65886.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-65886
Upstream
Published
2025-07-22T18:15:36Z
Modified
2026-04-01T05:20:39.686677Z
Summary
CVE-2025-48964 affecting package iputils for versions less than 20211215-4
Details

ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).

References

Affected packages

Azure Linux:2 / iputils

Package

Name
iputils
Purl
pkg:rpm/azure-linux/iputils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20211215-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65886.json"