The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 6.1.6 Ntp_advisory5 | — | — | Aug 5, 2016 | Aug 5, 2016 |
| Aix 7.1.0 Ntp_advisory5 | — | — | Aug 5, 2016 | Aug 5, 2016 |
| Centos_linux | — | Upgrade ntpUpgrade sntpUpgrade ntpdateUpgrade ntp-perlUpgrade ntp-doc | Aug 17, 2018 | Oct 26, 2015 |
| Debian | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 17, 2015 |
| Freebsd | — | Upgrade FreeBSDUpgrade ntpUpgrade ntp-devel | Dec 10, 2025 | Jan 8, 2016 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory5 | Nov 30, 2017 | Jul 21, 2017 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Jul 21, 2017 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.6-0.175.3.6.0.1.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade sntpUpgrade ntp-perlUpgrade ntp-docUpgrade ntpUpgrade ntpdate | May 12, 2016 | May 12, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 21, 2015 |
| Suse | — | Upgrade ntp-debuginfoUpgrade ntp-docUpgrade yast2-ntp-clientUpgrade ntpUpgrade ntp-debugsourceUpgrade yast2-ntp-client-devel-doc | Apr 28, 2016 | Oct 27, 2015 |
| Ubuntu | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub