Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268 . # Security update for iputils Announcement ID: SUSE-SU-2025:1771-1 Release Date: 2025-10-31T09:58:22Z Rating: moderate References: * bsc#1242300 * bsc#1243284 Cross-References: * CVE-2025-47268 CVSS scores: * CVE-2025-47268 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-47268 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-47268 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for iputils fixes the following issues: Security fixes: * CVE-2025-47268: Fixed integer overflow in RTT calculation can lead to undefined behavior (bsc#1242300). Other bug fixes: * Fixed incorrect IPV4 TTL value when using SOCK_DGRAM on big endian systems (bsc#1243284). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-1771=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-1771=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-1771=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-1771=1 ## Package List: * SUSE Linux Enterprise Server 15 SP3 LTSS(aarch64 ppc64le s390x x86_64) * rarpd-s20161105-150000.8.11.1 * iputils-debuginfo-s20161105-150000.8.11.1 * rarpd-debuginfo-s20161105-150000.8.11.1 * iputils-s20161105-150000.8.11.1 * iputils-debugsource-s20161105-150000.8.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * rarpd-s20161105-150000.8.11.1 * iputils-debuginfo-s20161105-150000.8.11.1 * rarpd-debuginfo-s20161105-150000.8.11.1 * iputils-s20161105-150000.8.11.1 * iputils-debugsource-s20161105-150000.8.11.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * rarpd-s20161105-150000.8.11.1 * iputils-debuginfo-s20161105-150000.8.11.1 * rarpd-debuginfo-s20161105-150000.8.11.1 * iputils-s20161105-150000.8.11.1 * iputils-debugsource-s20161105-150000.8.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * rarpd-s20161105-150000.8.11.1 * iputils-debuginfo-s20161105-150000.8.11.1 * rarpd-debuginfo-s20161105-150000.8.11.1 * iputils-s20161105-150000.8.11.1 * iputils-debugsource-s20161105-150000.8.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47268.html * https://bugzilla.suse.com/show_bug.cgi?id=1242300 * https://bugzilla.suse.com/show_bug.cgi?id=1243284 . Update for iputils on SUSE fixes a critical integer overflow vulnerability with moderate severity and installation instructions.. iputils security fix, SUSE patch updates, integer overflow vulnerability, Linux package manager. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-17558 http://linux.oracle.com/errata/ELSA-2025-17558.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: iputils-20210202-11.0.1.el9_6.3.x86_64.rpm iputils-ninfod-20210202-11.0.1.el9_6.3.x86_64.rpm aarch64: iputils-20210202-11.0.1.el9_6.3.aarch64.rpm iputils-ninfod-20210202-11.0.1.el9_6.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/iputils-20210202-11.0.1.el9_6.3.src.rpm Related CVEs: CVE-2025-48964 Description of changes: [20210202-11.0.1.3] - Upstream backport 'ping: Add SA_RESTART to sa_flags' [Orabug: 34573399] [20210202-11.3] - Bump release [20210202-11.2] - Fix CVE-2025-48964 iputils: iputils integer overflow (RHEL-112001) [20210202-11.1] - Fix CVE-2025-47268 iputils: Signed Integer Overflow in Timestamp Multiplication in iputils ping (RHEL-94335) [20210202-11] - ping: Fix ping6 binding to VRF and address (RHEL-57734) [20210202-10] - arping: Fix 1s delay on exit for unsolicited arpings (RHEL-34110) - arping: exit 0 if running in deadline mode and we see replies (RHEL-27718) - ping: Print reply with wrong source with warning & some follow-up fixes (RHEL-12789, RHEL-13480) - ping: Fix socket error reporting (RHEL-4608) _______________________________________________ El-errata mailing list
* bsc#1243284 * bsc#1243772 Cross-References: * CVE-2025-48964 . # Security update for iputils Announcement ID: SUSE-SU-2025:02797-1 Release Date: 2025-08-14T14:35:59Z Rating: moderate References: * bsc#1243284 * bsc#1243772 Cross-References: * CVE-2025-48964 CVSS scores: * CVE-2025-48964 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-48964 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2025-48964 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-48964 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for iputils fixes the following issues: * CVE-2025-48964: Fixed integer overflow in ping statistics via zero timestamp (bsc#1243772). Other bugfixes: * Fixed ping on s390x that printed invalid ttl (bsc#1243284). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-2797=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2797=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2797=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * iputils-debugsource-s20161105-150000.8.14.1 * iputils-s20161105-150000.8.14.1 * iputils-debuginfo-s20161105-150000.8.14.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * iputils-debugsource-s20161105-150000.8.14.1 * iputils-s20161105-150000.8.14.1 * iputils-debuginfo-s20161105-150000.8.14.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * iputils-debugsource-s20161105-150000.8.14.1 * iputils-s20161105-150000.8.14.1 * iputils-debuginfo-s20161105-150000.8.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48964.html * https://bugzilla.suse.com/show_bug.cgi?id=1243284 * https://bugzilla.suse.com/show_bug.cgi?id=1243772 . SUSE's latest iputils patch addresses significant integer overflow issues that may jeopardize system integrity and safety. Ensure you update promptly.. SUSE iputils update security patch integer overflow. . Severity: Important. LinuxSecurity.com Team
Update to 20250602 with fixes for CVE-2025-48964. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-885e731f6f 2025-08-07 01:11:45.458396+00:00 -------------------------------------------------------------------------------- Name : iputils Product : Fedora 41 Version : 20250602 Release : 3.fc41 URL : https://github.com/iputils/iputils Summary : Network monitoring tools including ping Description : The iputils package contains basic utilities for monitoring a network, including ping. The ping command sends a series of ICMP protocol ECHO_REQUEST packets to a specified network host to discover whether the target machine is alive and receiving network traffic. -------------------------------------------------------------------------------- Update Information: Update to 20250602 with fixes for CVE-2025-48964 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 25 2025 Jan Macku - 20250602-3 - remove build dependency on openssl-devel removed in s20200821 * Thu Jul 24 2025 Fedora Release Engineering - 20250602-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun Jul 13 2025 Kevin Fenzi - 20250602-1 - Update to 20250602. Fixes rhbz#2369782 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2382663 - CVE-2025-48964 iputils: iputils integer overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2382663 [ 2 ] Bug #2382664 - CVE-2025-48964 iputils: iputils integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2382664 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-885e731f6f' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 20250602 with fixes for CVE-2025-48964. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-38be836506 2025-07-28 01:26:46.086235+00:00 -------------------------------------------------------------------------------- Name : iputils Product : Fedora 42 Version : 20250602 Release : 3.fc42 URL : https://github.com/iputils/iputils Summary : Network monitoring tools including ping Description : The iputils package contains basic utilities for monitoring a network, including ping. The ping command sends a series of ICMP protocol ECHO_REQUEST packets to a specified network host to discover whether the target machine is alive and receiving network traffic. -------------------------------------------------------------------------------- Update Information: Update to 20250602 with fixes for CVE-2025-48964 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 25 2025 Jan Macku - 20250602-3 - remove build dependency on openssl-devel removed in s20200821 * Thu Jul 24 2025 Fedora Release Engineering - 20250602-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun Jul 13 2025 Kevin Fenzi - 20250602-1 - Update to 20250602. Fixes rhbz#2369782 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2382663 - CVE-2025-48964 iputils: iputils integer overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2382663 [ 2 ] Bug #2382664 - CVE-2025-48964 iputils: iputils integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2382664 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-38be836506' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1243772 Cross-References: * CVE-2025-48964 . # Security update for iputils Announcement ID: SUSE-SU-2025:20502-1 Release Date: 2025-07-21T10:04:38Z Rating: moderate References: * bsc#1243772 Cross-References: * CVE-2025-48964 CVSS scores: * CVE-2025-48964 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-48964 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2025-48964 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-48964 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for iputils fixes the following issues: * CVE-2025-48964: Fixed integer overflow in ping statistics via zero timestamp (bsc#1243772) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-390=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * iputils-20221126-6.1 * iputils-debugsource-20221126-6.1 * iputils-debuginfo-20221126-6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48964.html * https://bugzilla.suse.com/show_bug.cgi?id=1243772 . The Ubuntu Core 20 security notice tackles CVE-2025-48965, a moderate buffer overflow vulnerability found in netutils.. SUSE Linux Micro, iputils, security patch, moderate threat, CVE-2025-48964. . LinuxSecurity.com Team
iputils could be made to consume resources and crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7670-1 July 24, 2025 iputils vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: iputils could be made to consume resources and crash if it received specially crafted network traffic. Software Description: - iputils: Small utilities for Linux Networking Details: It was discovered that the iputils ping utility incorrectly handled certain ICMP Echo Reply packets. A remote attacker could possibly use this issue to cause iputils to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 iputils-ping 3:20240905-1ubuntu1.1 Ubuntu 24.04 LTS iputils-ping 3:20240117-1ubuntu0.1 Ubuntu 22.04 LTS iputils-ping 3:20211215-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7670-1 CVE-2025-47268, CVE-2025-48964 Package Information: https://launchpad.net/ubuntu/+source/iputils/3:20240905-1ubuntu1.1 https://launchpad.net/ubuntu/+source/iputils/3:20240117-1ubuntu0.1 https://launchpad.net/ubuntu/+source/iputils/3:20211215-1ubuntu0.1 . Debian Security Advisory DSA-5012-1 addresses a critical libcurl vulnerability that may lead to data exposure.. Ubuntu Security, iputils, Denial of Service, network security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for iputils Announcement ID: SUSE-SU-2025:02430-1 Release Date: 2025-07-21T11:23:28Z Rating: moderate References: * bsc#1243772 Cross-References: * CVE-2025-48964 CVSS scores: * CVE-2025-48964 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-48964 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for iputils fixes the following issues: * CVE-2025-48964: Fixed integer overflow in ping statistics via zero timestamp (bsc#1243772). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-2430=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2430=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2430=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2430=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2430=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * iputils-20221126-150500.3.14.1 *iputils-debugsource-20221126-150500.3.14.1 * iputils-debuginfo-20221126-150500.3.14.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * iputils-20221126-150500.3.14.1 * iputils-debugsource-20221126-150500.3.14.1 * iputils-debuginfo-20221126-150500.3.14.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * iputils-20221126-150500.3.14.1 * iputils-debugsource-20221126-150500.3.14.1 * iputils-debuginfo-20221126-150500.3.14.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * iputils-20221126-150500.3.14.1 * iputils-debugsource-20221126-150500.3.14.1 * iputils-debuginfo-20221126-150500.3.14.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * iputils-20221126-150500.3.14.1 * iputils-debugsource-20221126-150500.3.14.1 * iputils-debuginfo-20221126-150500.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48964.html * https://bugzilla.suse.com/show_bug.cgi?id=1243772 . Attention openSUSE users: A vital update for iputils has been released to fix the CVE-2025-48964 integer overflow vulnerability. Act quickly to reduce risks and update your systems immediately. openSUSE, iputils, security update, integer overflow, Linux patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.