← Vulnerability feed

Vulnerability record · CVE-2025-68137 · published 21 January 2026

CVE-2025-68137: Linuxfoundation everest classic buffer overflow vulnerability

Linuxfoundation · Everest

EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. The remaining length to read is computed using the current length subtracted by the header length which results in a negative value. This value is then interpreted as `SIZE_MAX` (or slightly less) because the expected type of the argument is `size_t`. Depending on whether the server is plain TCP or TLS, this leads to either an infinite loop or a stack buffer overflow. Version 2025.10.0 fixes the issue.

8.3 CVSS 3.1 High EPSS 1.3% · top 31.4% CWE-120 · Classic buffer overflowCWE-835 · CWE-835
8.3CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. The remaining length to read is computed using the current length subtracted by the header length which results in a negative value. This value is then interpreted as `SIZE_MAX` (or slightly less) because the expected type of the argument is `size_t`. Depending on whether the server is plain TCP or TLS, this leads to either an infinite loop or a stack buffer overflow. Version 2025.10.0 fixes the issue.

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-68137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-22790Linuxfoundation everest stack-based buffer overflow vulnerabilityEVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release bui…EPSS 0.53%7.8CVE-2026-23995Linuxfoundation everest stack-based buffer overflow vulnerabilityEVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interfa…EPSS 0.21%7.8CVE-2026-22593Linuxfoundation everest vulnerabilityEVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-base…EPSS 0.14%7.5CVE-2026-26008Linuxfoundation everest out-of-bounds read vulnerabilityEVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/…EPSS 0.46%7.4CVE-2025-68141Linuxfoundation everest null pointer dereference vulnerabilityEVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receip…EPSS 0.27%7.4CVE-2025-68136Linuxfoundation everest allocation without limits vulnerabilityEVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects l…EPSS 0.30%7.4CVE-2025-68134Linuxfoundation everest improper input validation vulnerabilityEVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module …EPSS 0.17%7.4CVE-2025-68133Linuxfoundation everest allocation without limits vulnerabilityEVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module …EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2025-68137), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.