← Vulnerability feed

Vulnerability record · CVE-2016-4957 · published 5 July 2016

CVE-2016-4957: NTP ntpd NULL pointer dereference via crypto-NAK packet

Ntp · Ntp

ntpd in NTP before 4.2.8p8 crashes when it receives a crafted crypto-NAK packet, a NULL pointer dereference (CWE-476). The flaw was introduced by an incorrect fix for CVE-2016-1547, so systems patched for that earlier issue may still be exposed. It matters because a single unauthenticated packet can take down a time daemon that many hosts depend on.

7.5 CVSS 3.1 High EPSS 45% · top 1.3% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
26References
17 Jun 2026Last modified by NVD

Description

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated remote crash of a widely deployed daemon with a high EPSS percentile, though no KEV listing or known exploit reference.

What it is

ntpd in NTP before 4.2.8p8 crashes when it receives a crafted crypto-NAK packet, a NULL pointer dereference (CWE-476). The flaw was introduced by an incorrect fix for CVE-2016-1547, so systems patched for that earlier issue may still be exposed. It matters because a single unauthenticated packet can take down a time daemon that many hosts depend on.

Impact

An attacker gains a remote denial of service: the ntpd daemon crashes, disrupting time synchronization on the affected host. There is no confidentiality or integrity impact per the CVSS vector.

Attack surface

Reachable over the network via UDP NTP traffic; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Any host that can send a packet to the ntpd service can attempt it.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.44936, 98.7th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory, patch and issue-tracking only; no public exploit reference is supplied.

What to do

  • Upgrade ntpd to 4.2.8p8 or later, or apply the vendor patch referenced in NtpBug3046.
  • If patching is delayed, restrict UDP/123 access to trusted time sources and clients using firewall or ACL rules.
  • Check whether the earlier CVE-2016-1547 fix is present, since this flaw stems from an incorrect fix for it, and re-verify the daemon version.
  • Apply distribution vendor updates for Oracle Solaris, SUSE/openSUSE and other listed products rather than relying on upstream NTP alone.
  • Monitor ntpd process restarts and consider a redundant or authenticated time source to limit impact of a crash.

Detection

  • Alert on unexpected ntpd process termination or restart events on NTP servers.
  • Monitor for repeated or malformed crypto-NAK packets and abnormal NTP request patterns from single sources.
  • Correlate NTP service outages with inbound UDP/123 traffic spikes in firewall or flow logs.
  • Verify running ntpd versions against the 4.2.8p8 baseline during vulnerability scans.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.ntp.org/3046 Issue TrackingVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.html Mailing ListThird Party Advisory
http://support.ntp.org/bin/view/Main/NtpBug3046 PatchVendor Advisory
http://support.ntp.org/bin/view/Main/SecurityNotice Release NotesVendor Advisory
http://www.kb.cert.org/vuls/id/321640 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
http://www.securitytracker.com/id/1036037 Third Party AdvisoryVDB Entry
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.asc Third Party Advisory
https://security.gentoo.org/glsa/201607-15 Third Party Advisory
http://bugs.ntp.org/3046 Issue TrackingVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.html Mailing ListThird Party Advisory
http://support.ntp.org/bin/view/Main/NtpBug3046 PatchVendor Advisory
http://support.ntp.org/bin/view/Main/SecurityNotice Release NotesVendor Advisory
http://www.kb.cert.org/vuls/id/321640 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
http://www.securitytracker.com/id/1036037 Third Party AdvisoryVDB Entry
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.asc Third Party Advisory
https://security.gentoo.org/glsa/201607-15 Third Party Advisory

Track CVE-2016-4957 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14871Oracle Solaris PAM out-of-bounds write allows remote unauthenticated takeoverOracle Solaris 10 and 11 contain an out-of-bounds write (CWE-787) in the Pluggable Authentication Module component, reachable over the network withou…KEVEPSS 80%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2016-4957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.