Skip to main content
Vulnerability Database/CVE-2025-68382

CVE-2025-68382: Elasticsearch Packetbeat DOS Vulnerability

CVE-2025-68382 is a denial-of-service vulnerability in Elasticsearch Packetbeat caused by an out-of-bounds read in the NFS protocol dissector. Attackers can crash the process remotely without authentication. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-68382 Overview

CVE-2025-68382 is an out-of-bounds read vulnerability [CWE-125] in Elasticsearch Packetbeat's Network File System (NFS) protocol dissector. An unauthenticated attacker on an adjacent network can send a truncated XDR-encoded Remote Procedure Call (RPC) message to trigger a reliable process crash. The flaw results in a denial-of-service (DoS) condition against the Packetbeat monitoring agent.

Elastic addressed the issue in Packetbeat versions 8.19.9, 9.1.9, and 9.2.3 under advisory ESA-2025-31.

Critical Impact

Remote attackers on the local network segment can reliably crash Packetbeat instances by sending malformed NFS/RPC traffic, disrupting network monitoring and security telemetry pipelines.

Affected Products

  • Elasticsearch Packetbeat versions prior to 8.19.9
  • Elasticsearch Packetbeat 9.1.x versions prior to 9.1.9
  • Elasticsearch Packetbeat 9.2.x versions prior to 9.2.3

Discovery Timeline

  • 2025-12-18 - CVE-2025-68382 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-68382

Vulnerability Analysis

Packetbeat is a real-time network packet analyzer that ships network data into the Elastic Stack. It includes protocol dissectors for common services, including NFS carried over Sun RPC. The vulnerability resides in the code path that parses XDR-encoded RPC messages during NFS traffic inspection.

When Packetbeat receives a truncated RPC packet, the NFS dissector reads past the end of the supplied buffer. The out-of-bounds read triggers a crash in the Packetbeat process, halting all packet capture and log forwarding until the agent restarts.

Because Packetbeat processes traffic passively, no authentication or user interaction is required. Any host that can place NFS-like packets on a network segment observed by Packetbeat can trigger the fault.

Root Cause

The root cause is missing bounds validation in the External Data Representation (XDR) parsing logic used by the NFS dissector. The parser assumes the incoming RPC message contains enough bytes for the declared fields but does not verify buffer length before dereferencing offsets. Truncated messages therefore cause the dissector to read beyond the allocated packet buffer.

Attack Vector

Exploitation requires network adjacency to a segment being monitored by Packetbeat. The attacker crafts an RPC message that advertises XDR fields larger than the actual payload and transmits it toward any host on the observed subnet. Packetbeat captures the frame, invokes the NFS dissector, and crashes.

Repeated packets keep the agent unavailable, producing sustained loss of network visibility. This is significant when Packetbeat feeds security identification and audit logging in the Elastic Stack.

No verified public proof-of-concept is available. Refer to the Elastic Security Update ESA-2025-31 for vendor technical details.

Detection Methods for CVE-2025-68382

Indicators of Compromise

  • Unexpected Packetbeat process crashes or restarts recorded in system service logs (systemd, Windows Service Control Manager).
  • Gaps in Packetbeat-sourced indices in Elasticsearch that correlate with malformed NFS/RPC traffic on monitored segments.
  • Truncated Sun RPC (TCP/UDP port 111) or NFS (TCP/UDP port 2049) packets originating from unexpected hosts.

Detection Strategies

  • Alert on repeated packetbeat service restart events on monitoring collectors.
  • Deploy network intrusion detection signatures that flag RPC messages whose declared XDR field lengths exceed remaining packet bytes.
  • Correlate Packetbeat telemetry outages with concurrent NFS traffic anomalies to identify triggered exploitation.

Monitoring Recommendations

  • Track Packetbeat agent health metrics and forward crash events to the central SIEM.
  • Monitor east-west NFS traffic for unusual sources, especially hosts that do not normally use NFS.
  • Baseline expected RPC/NFS peer relationships and alert on deviations that coincide with agent instability.

How to Mitigate CVE-2025-68382

Immediate Actions Required

  • Upgrade all Packetbeat deployments to 8.19.9, 9.1.9, or 9.2.3 or later, matching the appropriate release branch.
  • Inventory hosts running Packetbeat and confirm the NFS protocol is enabled in the configuration before prioritizing.
  • Restrict which network segments Packetbeat monitors to trusted VLANs where feasible.

Patch Information

Elastic released fixed Packetbeat builds in versions 8.19.9, 9.1.9, and 9.2.3. Details are documented in Elastic Security Update ESA-2025-31. Apply the update through the standard Elastic package repositories or container images used in your environment.

Workarounds

  • Disable the NFS protocol dissector in packetbeat.yml by removing or commenting out the nfs entry under packetbeat.protocols if NFS visibility is not required.
  • Apply network access controls that block untrusted sources from sending RPC (port 111) and NFS (port 2049) traffic across monitored segments.
  • Implement service supervision that automatically restarts Packetbeat after a crash to reduce visibility gaps until patching completes.
bash
# Configuration example: disable the NFS dissector in packetbeat.yml
packetbeat.protocols:
  # - type: nfs
  #   ports: [2049]
  - type: dns
    ports: [53]
  - type: http
    ports: [80, 8080, 8000, 5000, 8002]

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.