


Perceptive Security
SOC/SIEM Consultancy

Packetbeat 8.19.9, 9.1.9, and 9.2.3 Security Update (ESA-2025-30)
Published:
18 December 2025 at 21:15:08
Alert date:
18 December 2025 at 22:04:21
Source:
discuss.elastic.co
A buffer overflow vulnerability (CVE-2025-68381) in Packetbeat allows remote unauthenticated attackers to crash the application or cause resource exhaustion via crafted UDP packets. The vulnerability affects all 7.x versions, 8.x versions up to 8.19.8, and multiple 9.x version ranges. It specifically impacts users with memcached collection enabled and has a CVSS score of 6.5 (Medium). The issue is resolved in versions 8.19.9, 9.1.9, and 9.2.3. Users who cannot upgrade can disable memcached collection as a mitigation.
Technical details
Mitigation steps:
Affected products:
Packetbeat
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
