praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GPS receiver.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade sntpUpgrade ntp-debuginfoUpgrade ntpdateUpgrade ntpUpgrade ntp-perlUpgrade ntp-doc | Feb 21, 2024 | Apr 11, 2023 |
| Debian | — | No solution exists | May 15, 2025 | Apr 11, 2023 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | Jul 9, 2025 | Apr 11, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ntp | Jul 18, 2023 | Apr 11, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade ntpUpgrade ntp-help | Jan 10, 2024 | Apr 11, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade ntp | Aug 9, 2023 | Apr 11, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 11, 2023 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Jun 23, 2023 | Apr 11, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 11, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub