NTP BUG 3046: CRYPTO_NAK crash
Last update: April 22, 2024 18:49 UTC (7e7bd5857)
Summary
Description
The fix for 3007 in ntp-4.2.8p7 contained a bug that could cause ntpd
to crash.
Mitigation
- Implement BCP-38.
- Upgrade to 4.2.8p8 or later.
- If you cannot upgrade from 4.2.8p7, the only other alternatives are to patch your code or filter
CRYPTO_NAK
packets.
- Properly monitor your
ntpd
instances, and auto-restart ntpd
(without -g
) if it stops running.
Credit
This weakness was discovered by Nicolas Edet of Cisco.
Timeline