chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade chrony | Aug 30, 2017 | Apr 16, 2015 |
| Debian | — | Upgrade chrony | Jul 30, 2024 | Dec 9, 2019 |
| Freebsd | — | Upgrade chrony | Dec 10, 2025 | Apr 18, 2015 |
| Gentoo Linux | — | Upgrade net-misc/chrony. | Oct 30, 2017 | Jul 5, 2015 |
| Oracle_linux | — | Upgrade chrony | Oct 16, 2024 | Dec 9, 2019 |
| Ubuntu | — | Upgrade chrony | Nov 19, 2024 | Dec 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub