[CLSA-2026:1777453146] ntp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-02 00:51:53 UTC
Description:
- CVE-2018-7185: unauthenticated packet with a zero-origin timestamp can reset an authenticated interleave association leading to denial of service. - CVE-2019-8936: NULL pointer dereference triggered by an authenticated mode 6 control packet with no value field.
Updated packages:
  • ntp-4.2.6p5-16.el6.tuxcare.els2.x86_64.rpm
    sha:21ffac68a726a3e07d00b3d12a824155ae24c686c227e899a535345b14d514f9
  • ntp-doc-4.2.6p5-16.el6.tuxcare.els2.noarch.rpm
    sha:2f0311edd37ee1d69eecf0a0b397872954218c67c16a4344443f33aac4dca62c
  • ntp-perl-4.2.6p5-16.el6.tuxcare.els2.x86_64.rpm
    sha:b32aff50cf1974a0df2d348982d1cb69803a8de7a96ed6b0653e4f1a590a940a
  • ntpdate-4.2.6p5-16.el6.tuxcare.els2.x86_64.rpm
    sha:772056f99896882c28d18182c8532ff68f2b5412b3c39100c9efbef40531436d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.