NTP BUG 2853: ntpd control message crash: Crafted NUL-byte in configuration directive
Last update: September 3, 2026 14:42 UTC (1eec487e7)
Summary
Description
Under limited and specific circumstances an attacker can send a crafted packet to cause a vulnerable ntpd instance to crash. This requires each of the following to be true:
ntpd set up to allow for remote configuration (not allowed by default), and
- knowledge of the configuration password, and
- access to a computer entrusted to perform remote configuration.
Mitigation
- Upgrade to 4.2.8p3 or later.
- Be prudent when deciding what IP addresses can perform remote configuration of an
ntpd instance.
- Monitor your
ntpd instances.
Credit
This weakness was discovered by Aleksis Kauppinen of Codenomicon.
Timeline