REDHAT-BUG-2382657: Integer Overflow
ping in iputils through 20240905 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2382657?
The vulnerability REDHAT-BUG-2382657 is classified as a denial of service risk due to an application error in adaptive ping mode.
How do I fix REDHAT-BUG-2382657?
To fix REDHAT-BUG-2382657, update the iputils ping package to a version later than 20240905.
What causes the issue in REDHAT-BUG-2382657?
The issue in REDHAT-BUG-2382657 is caused by a crafted ICMP Echo Reply packet that leads to an integer overflow during statistics calculations.
Which versions of iputils ping are affected by REDHAT-BUG-2382657?
Versions of iputils ping up to and including 20240905 are affected by the vulnerability REDHAT-BUG-2382657.
Is there a workaround for REDHAT-BUG-2382657?
Currently, the recommended approach for REDHAT-BUG-2382657 is to apply the available security update rather than relying on a workaround.