cbcvebase.
CVE-2016-4957
published 2016-07-05

CVE-2016-4957: ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because…

PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
44.94%
98.6th percentile
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianntp< ntp 1:4.2.8p8+dfsg-1 (bullseye)ntp 1:4.2.8p8+dfsg-1 (bullseye)
novellsuse_manager
ntpntp
ntpntp
ntpntp>= 0 < 1:4.2.8p8+dfsg-11:4.2.8p8+dfsg-1
opensuseleap
opensuseopensuse
oraclesolaris
oraclesolaris
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server
susemanager_proxy
suseopenstack_cloud

Detection & IOCsextracted from sources · hover to see the quote

otherNetwork.Time.Protocol.Daemon.crypto-NAK.Packet.Handling.DoS
  • A malicious crypto-NAK packet sent to a target running NTPD (NTP versions before 4.2.8p8, specifically 4.2.8p7) triggers a null pointer dereference in the valid_NAK() function, causing a segfault/daemon crash. No authentication is required to exploit this vulnerability.
  • The vulnerable code path is in the valid_NAK() function in ntpd 4.2.8p7, which dereferences the peer pointer without null-checking it. Detect crashes/segfaults in ntpd processes as a sign of exploitation.
  • The attack is unauthenticated — no valid NTP association needs to exist between attacker and target. Crypto-NAK packets from unknown/unassociated peers targeting ntpd should be treated as suspicious.
  • The vulnerability was introduced specifically in ntp-4.2.8p7 (the fix for CVE-2016-1547 / NTP bug 3007). Systems running exactly 4.2.8p7 are the primary target; scan for this version in your environment.
  • ·Red Hat Enterprise Linux (versions 5, 6, and 7) are NOT affected because Red Hat's own fix for CVE-2016-1547 did not include the upstream change that introduced this bug.
  • ·The vulnerability cannot be escalated to remote code execution; impact is limited to denial of service (ntpd crash).
  • ·No workaround is available for affected systems; the only mitigation is patching to ntp-4.2.8p8 or later.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.