CVE-2015-1853: Tuxfamily Chrony

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.

Affected products

  • Tuxfamily Chrony: before 1.31.1 (fixed in 1.31.1)

Published 2019-12-09. Last modified 2026-06-17.