NTP BUG 3389: Denial of Service via Malformed Config
Last update: November 3, 2025 16:09 UTC (9cbb45cb6)
Summary
Description
A vulnerability found in the NTP server makes it possible for an authenticated remote user to crash ntpd via a malformed mode configuration directive.
Mitigation
- Implement BCP-38.
- Upgrade to 4.2.8p10 or later.
- Properly monitor your
ntpd instances, and auto-restart ntpd (without -g) if it stops running.
Credit
This weakness was discovered by Cure53.
Timeline