ntpd
Activity
- Latest release
- 3mo ago
- Total releases
- 45
- Cadence
- ~15 days
- Last 12 months
- 7
Details
- License
- Apache-2.0 OR MIT
- First release
- Mar 29, 2020
| Version | Released | |
|---|---|---|
1.9.0
unknown
|
1.9.0
unknown
Dependencies (17)
+ 9 more |
|
1.8.0
unknown
|
1.8.0
unknown
Dependencies (16)
+ 8 more |
|
1.7.2
unknown
|
1.7.2
unknown
Dependencies (15)
+ 7 more |
|
1.7.1
unknown
|
1.7.1
unknown
Dependencies (15)
+ 7 more |
|
1.7.0
unknown
|
1.7.0
unknown
Dependencies (15)
+ 7 more |
|
1.7.0-alpha.20260122
unknown
|
1.7.0-alpha.20260122
unknown
Dependencies (15)
+ 7 more |
|
1.7.0-alpha.20251003
unknown
|
1.7.0-alpha.20251003
unknown
Dependencies (15)
+ 7 more |
|
1.6.2
unknown
|
1.6.2
unknown
Dependencies (16)
+ 8 more |
|
1.6.1
unknown
|
1.6.1
unknown
Dependencies (16)
+ 8 more |
|
1.6.0
unknown
|
1.6.0
unknown
Dependencies (16)
+ 8 more |
|
1.5.0
unknown
|
1.5.0
unknown
Dependencies (16)
+ 8 more |
|
1.4.0
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.4.0
unknown
Dependencies (15)
+ 7 more |
|
1.3.1
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.3.1
unknown
Dependencies (17)
+ 9 more |
|
1.3.0
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.3.0
unknown
Dependencies (17)
+ 9 more |
|
1.2.3
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.2.3
unknown
Dependencies (17)
+ 9 more |
|
1.2.2
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.2.2
unknown
Dependencies (17)
+ 9 more |
|
1.2.1
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.2.1
unknown
Dependencies (17)
+ 9 more |
|
1.2.0
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.2.0
unknown
Dependencies (17)
+ 9 more |
|
1.1.3
unknown
1 CVE
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev |
1.1.3
unknown
Dependencies (18)
+ 10 more |
|
1.1.2
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.2
unknown
Dependencies (18)
+ 10 more |
|
1.1.1
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.1
unknown
Dependencies (18)
+ 10 more |
|
1.1.1-alpha.20240119
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.1-alpha.20240119
unknown
Dependencies (18)
+ 10 more |
|
1.1.1-alpha.20231221
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.1-alpha.20231221
unknown
Dependencies (18)
+ 10 more |
|
1.1.0
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.0
unknown
Dependencies (17)
+ 9 more |
|
1.1.0-alpha.20231123
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.1.0-alpha.20231123
unknown
Dependencies (17)
+ 9 more |
|
1.0.0
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-rc.5
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-rc.5
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-rc.4
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-rc.4
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-rc.3
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-rc.3
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-rc.2
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-rc.2
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-rc.1
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-rc.1
unknown
Dependencies (17)
+ 9 more |
|
1.0.0-dev.20230907
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.0.0-dev.20230907
unknown
Dependencies (17)
+ 9 more |
|
0.3.7
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.7
unknown
Dependencies (4)
|
|
0.3.6
unknown
3 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.6
unknown
Dependencies (4)
|
|
0.3.5
unknown
3 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.5
unknown
Dependencies (4)
|
|
0.3.3
unknown
3 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.3
unknown
Dependencies (4)
|
|
0.3.2
unknown
4 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev
CVE-2023-33192
GHSA-qwhm-h7v3-mrjx
May 25, 2023
Improper handling of NTS cookie length that could crash the ntpd-rs server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie shorter than what the server expects. The server also crashes when it is not configured to handle NTS packets. ntpd-rs running purely as an ntp client is not affected. PatchesThe issue was caused by improper slice indexing. The indexing operations were replaced by safer alternatives that do not crash the ntpd-rs server process but instead properly handle the error condition. A patch was released in version 0.3.3 Workaroundsntpd-rs running purely as an ntp client is not affected. By default, ntpd-rs packages are not configured to run as a server. For machines where serving the time is required, there is no known workaround. Users are recommended to upgrade ntpd-rs as soon as possible. Referenceshttps://github.com/pendulum-project/ntpd-rs/pull/752 We would like to thank @mlichvar for identifying this issue Fixed in
0.3.3
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.2
unknown
Dependencies (4)
|
|
0.3.1
unknown
4 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
CVE-2024-38528
GHSA-2xpx-vcmq-5f72
Jun 28, 2024
Unlimited number of NTS-KE connections can crash ntpd-rs server
High
Network
Low
None
None
SummaryMissing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. DetailsOperating systems have a limit for the number of open file descriptors (which includes sockets) in a single process, e.g. 1024 on Linux by default. When ntpd-rs is configured as an NTS server, it accepts TCP connections for the NTS-KE service. If the process has reached the descriptor limit and tries to accept a new TCP connection, the accept() system call will return with the EMFILE error and cause ntpd-rs to abort. A remote attacker can open a large number of parallel TCP connections to the server to trigger this crash. The connections need to be opened quickly enough to avoid the ImpactOnly NTS-KE server configuration are affected. Those without an NTS-KE server configuration such as NTS client only or NTP only configuration are unaffected. For affected configurations the ntpd-rs daemon can made completely unavailable by crashing the service. If ntpd-rs is automatically restarted, an attacker can repeat the attack to prevent ntpd-rs from doing anything useful. Workarounds
Fixed in
1.1.3
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev
CVE-2023-33192
GHSA-qwhm-h7v3-mrjx
May 25, 2023
Improper handling of NTS cookie length that could crash the ntpd-rs server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Impactntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie shorter than what the server expects. The server also crashes when it is not configured to handle NTS packets. ntpd-rs running purely as an ntp client is not affected. PatchesThe issue was caused by improper slice indexing. The indexing operations were replaced by safer alternatives that do not crash the ntpd-rs server process but instead properly handle the error condition. A patch was released in version 0.3.3 Workaroundsntpd-rs running purely as an ntp client is not affected. By default, ntpd-rs packages are not configured to run as a server. For machines where serving the time is required, there is no known workaround. Users are recommended to upgrade ntpd-rs as soon as possible. Referenceshttps://github.com/pendulum-project/ntpd-rs/pull/752 We would like to thank @mlichvar for identifying this issue Fixed in
0.3.3
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (4)
|
|
0.3.0-alpha.4
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.0-alpha.4
unknown
Dependencies (4)
|
|
0.3.0-alpha.3
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.0-alpha.3
unknown
Dependencies (4)
|
|
0.3.0-alpha.2
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.0-alpha.2
unknown
Dependencies (4)
|
|
0.3.0-alpha.1
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.0-alpha.1
unknown
Dependencies (4)
|
|
0.3.0-alpha.0
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.3.0-alpha.0
unknown
Dependencies (4)
|
|
0.1.1
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.1.1
unknown
Dependencies (4)
|
|
0.1.0
unknown
2 CVEs
GHSA-v83q-83hj-rw38
Feb 28, 2025
ntpd NTS client denial of service via wrongly sized cookies
Medium
Network
Low
None
Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities. For zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero. For large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes. Users of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug. Fixed in
1.5.0
References
Updated Feb 28, 2025 · Source: OSV.dev
GHSA-37xq-q42p-rv3p
Aug 24, 2023
ntpd has Dependency on Vulnerable Third-Party Component
2.6
/ 10
Low
Adjacent
High
None
Required
Unchanged
None
None
Low
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ImpactThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS PatchesAffected users are recommended to upgrade to version 0.3.7 ReferencesSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md Fixed in
0.3.7
References
Updated Jun 26, 2024 · Source: OSV.dev |
0.1.0
unknown
Dependencies (4)
|