NTP BUG 2671: vallen is not validated in several places in ntp_crypto.c, leading to a potential info leak or possibly crashing ntpd
Last update: February 15, 2022 20:59 UTC (43fbd379b)
vallen packet value is not validated in several code paths in
ntp_crypto.c which can lead to information leakage or a possible crash of
- Upgrade to 4.2.8p1 or later.
- Disable Autokey Authentication by removing, or commenting out, all configuration directives beginning with the
crypto keyword in your
This vulnerability was discovered by Stephen Roettger of the Google Security Team, with additional cases found by Sebastian Krahmer of the SUSE Security Team and Harlan Stenn of Network Time Foundation.