CVE-2016-7426: High severity NTP ntp vulnerability

Published Jan 13, 2017
·
Updated

Last updated 25 August 2025

Other sources

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Launchpad

Affected Software

93 affected componentsFixes available
debian/ntp
1:4.2.8p15+dfsg-1
NTP ntp>=4.2.6<4.2.8
NTP ntp>=4.3.0<4.3.94
NTP ntp=4.2.5-p203
NTP ntp=4.2.5-p204
NTP ntp=4.2.5-p205
NTP ntp=4.2.5-p206
NTP ntp=4.2.5-p207
NTP ntp=4.2.5-p208
NTP ntp=4.2.5-p209
NTP ntp=4.2.5-p210
NTP ntp=4.2.5-p211
NTP ntp=4.2.5-p212
NTP ntp=4.2.5-p213
NTP ntp=4.2.5-p214
NTP ntp=4.2.5-p215
NTP ntp=4.2.5-p216
NTP ntp=4.2.5-p217
NTP ntp=4.2.5-p218
NTP ntp=4.2.5-p219
NTP ntp=4.2.5-p220
NTP ntp=4.2.5-p221
NTP ntp=4.2.5-p222
NTP ntp=4.2.5-p223
NTP ntp=4.2.5-p224
NTP ntp=4.2.5-p225
NTP ntp=4.2.5-p226
NTP ntp=4.2.5-p227
NTP ntp=4.2.5-p228
NTP ntp=4.2.5-p229
NTP ntp=4.2.5-p230
NTP ntp=4.2.5-p231_rc1
NTP ntp=4.2.5-p232_rc1
NTP ntp=4.2.5-p233_rc1
NTP ntp=4.2.5-p234_rc1
NTP ntp=4.2.5-p235_rc1
NTP ntp=4.2.5-p236_rc1
NTP ntp=4.2.5-p237_rc1
NTP ntp=4.2.5-p238_rc1
NTP ntp=4.2.5-p239_rc1
NTP ntp=4.2.5-p240_rc1
NTP ntp=4.2.5-p241_rc1
NTP ntp=4.2.5-p242_rc1
NTP ntp=4.2.5-p243_rc1
NTP ntp=4.2.5-p244_rc1
NTP ntp=4.2.5-p245_rc1
NTP ntp=4.2.5-p246_rc1
NTP ntp=4.2.5-p247_rc1
NTP ntp=4.2.5-p248_rc1
NTP ntp=4.2.5-p249_rc1
NTP ntp=4.2.5-p250_rc1
NTP ntp=4.2.8
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
NTP ntp=4.2.8-p4
NTP ntp=4.2.8-p5
NTP ntp=4.2.8-p6
NTP ntp=4.2.8-p7
NTP ntp=4.2.8-p8
Canonical Ubuntu Linux=12.04
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Eus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
HPE Hpux-ntp>=b.11.31<c.4.2.8.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/ntp to a version that resolves this vulnerability.

    Fixed in 1:4.2.8p15+dfsg-1
  2. Upgrade

    Upgrade NTP to a version that resolves this vulnerability.

    Fixed in 4.2.8p9

Event History

Jan 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·06:26 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·06:26 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-7426?

CVE-2016-7426 has a severity rating that can vary but is generally classified as medium to high due to its potential to cause denial of service.

2

How do I fix CVE-2016-7426?

To mitigate CVE-2016-7426, upgrade to NTP version 4.2.8p15 or later.

3

What systems are affected by CVE-2016-7426?

CVE-2016-7426 affects NTP versions earlier than 4.2.8p9, including several distributions such as Debian and Red Hat.

4

What type of attack does CVE-2016-7426 enable?

CVE-2016-7426 allows remote attackers to perform denial of service attacks by sending spoofed responses to NTP servers.

5

Is there a patch available for CVE-2016-7426?

Yes, a patch is available and users should update to NTP version 4.2.8p15 or higher to eliminate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203