chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade chrony | Aug 30, 2017 | Apr 16, 2015 |
| Debian | — | Upgrade chrony | Jul 30, 2024 | Apr 16, 2015 |
| Freebsd | — | Upgrade chrony | Dec 10, 2025 | Apr 18, 2015 |
| Gentoo Linux | — | Upgrade net-misc/chrony. | Oct 30, 2017 | Apr 16, 2015 |
| Oracle_linux | — | Upgrade chrony | Oct 16, 2024 | Apr 16, 2015 |
| Ubuntu | — | Upgrade chrony | Nov 19, 2024 | Apr 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub