CVE-2018-7183: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 10.2% chance of exploitation in the next 30 days.

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Freebsd Freebsd: version 10.3 only; version 10.4 only; version 11.1 only
  • Netapp Element Software: affected versions not specified
  • Ntp Ntp: version 4.2.8 only

Published 2018-03-08. Last modified 2026-06-17.