CVE-2018-7185: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 9% chance of exploitation in the next 30 days.

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • HPE Hpux-Ntp: before c.4.2.8.4.0 (fixed in c.4.2.8.4.0)
  • Netapp Hci: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Ntp Ntp: from 4.2.6, before 4.2.8 (fixed in 4.2.8); version 4.2.8 only
  • Oracle Fujitsu m10-1 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Oracle Fujitsu m10-4 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Oracle Fujitsu m10-4s Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Oracle Fujitsu m12-1 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Oracle Fujitsu m12-2 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Oracle Fujitsu m12-2s Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Synology Diskstation Manager: from 5.2, before 6.1.6-15266 (fixed in 6.1.6-15266)
  • Synology Router Manager: from 1.1, before 1.1.6-6931-3 (fixed in 1.1.6-6931-3)
  • Synology Skynas: before 6.1.5-15254 (fixed in 6.1.5-15254)
  • Synology Virtual Diskstation Manager: before 6.1.6-15266 (fixed in 6.1.6-15266)
  • Synology VS960HD Firmware: before 2.2.3-1505 (fixed in 2.2.3-1505)

Published 2018-03-06. Last modified 2026-06-17.