CVE-2016-4954: Ntp

High severity, CVSS 7.5. EPSS: 13.2% chance of exploitation in the next 30 days.

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.

Affected products

  • Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.93 (fixed in 4.3.93); version 4.2.8 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Solaris: version 10 only; version 11.3 only
  • Siemens SIMATIC Net CP 443-1 Opc Ua Firmware: any version
  • Siemens Tim 4r-Ie DNP3 Firmware: any version
  • Siemens Tim 4r-Ie Firmware: any version
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Manager: version 2.1 only
  • Suse Manager Proxy: version 2.1 only
  • Suse Openstack Cloud: version 5 only

Published 2016-07-05. Last modified 2026-06-17.