CVE-2015-5300: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 9.1% chance of exploitation in the next 30 days.
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fedoraproject Fedora: version 21 only; version 22 only
- Ntp Ntp: up to and including 4.2.8
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Hpc Node Eus: version 7.1 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Eus: version 6.7.z only; version 7.1 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Server: version 10 only; version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 12 only
- Suse Manager: version 2.1 only
- Suse Manager Proxy: version 2.1 only
- Suse Openstack Cloud: version 5 only
- Suse Suse Linux Enterprise Server: version 12 only
Published 2017-07-21. Last modified 2026-06-17.