NTP BUG 3010: remote configuration trustedkey/requestkey/controlkey values are not properly validated
Last update: September 3, 2026 14:42 UTC (1eec487e7)
Summary
Description
If ntpd was expressly configured to allow for remote configuration, a malicious user who knows the controlkey for ntpq or the requestkey for ntpdc (if mode7 is expressly enabled) can create a session with ntpd and then send a crafted packet to ntpd that will change the value of the trustedkey, controlkey, or requestkey to a value that will prevent any subsequent authentication with ntpd until ntpd is restarted.
Mitigation
Credit
This weakness was discovered by Yihan Lian of the Cloud Security Team, Qihoo 360.
Timeline