Vulnerability record · CVE-2016-4957 · published 5 July 2016
CVE-2016-4957: NTP ntpd NULL pointer dereference via crypto-NAK packet
Ntp · Ntp
ntpd in NTP before 4.2.8p8 crashes when it receives a crafted crypto-NAK packet, a NULL pointer dereference (CWE-476). The flaw was introduced by an incorrect fix for CVE-2016-1547, so systems patched for that earlier issue may still be exposed. It matters because a single unauthenticated packet can take down a time daemon that many hosts depend on.
Description
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote crash of a widely deployed daemon with a high EPSS percentile, though no KEV listing or known exploit reference.
What it is
ntpd in NTP before 4.2.8p8 crashes when it receives a crafted crypto-NAK packet, a NULL pointer dereference (CWE-476). The flaw was introduced by an incorrect fix for CVE-2016-1547, so systems patched for that earlier issue may still be exposed. It matters because a single unauthenticated packet can take down a time daemon that many hosts depend on.
Impact
An attacker gains a remote denial of service: the ntpd daemon crashes, disrupting time synchronization on the affected host. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network via UDP NTP traffic; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Any host that can send a packet to the ntpd service can attempt it.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.44936, 98.7th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory, patch and issue-tracking only; no public exploit reference is supplied.
What to do
- Upgrade ntpd to 4.2.8p8 or later, or apply the vendor patch referenced in NtpBug3046.
- If patching is delayed, restrict UDP/123 access to trusted time sources and clients using firewall or ACL rules.
- Check whether the earlier CVE-2016-1547 fix is present, since this flaw stems from an incorrect fix for it, and re-verify the daemon version.
- Apply distribution vendor updates for Oracle Solaris, SUSE/openSUSE and other listed products rather than relying on upstream NTP alone.
- Monitor ntpd process restarts and consider a redundant or authenticated time source to limit impact of a crash.
Detection
- Alert on unexpected ntpd process termination or restart events on NTP servers.
- Monitor for repeated or malformed crypto-NAK packets and abnormal NTP request patterns from single sources.
- Correlate NTP service outages with inbound UDP/123 traffic spikes in firewall or flow logs.
- Verify running ntpd versions against the 4.2.8p8 baseline during vulnerability scans.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4957 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4957), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.