CVE-2016-7426: High severity NTP ntp vulnerability
Last updated 25 August 2025
Other sources
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntpto a version that resolves this vulnerability.Fixed in 1:4.2.8p15+dfsg-1 - Upgrade
Upgrade
NTPto a version that resolves this vulnerability.Fixed in 4.2.8p9
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7426?
CVE-2016-7426 has a severity rating that can vary but is generally classified as medium to high due to its potential to cause denial of service.
How do I fix CVE-2016-7426?
To mitigate CVE-2016-7426, upgrade to NTP version 4.2.8p15 or later.
What systems are affected by CVE-2016-7426?
CVE-2016-7426 affects NTP versions earlier than 4.2.8p9, including several distributions such as Debian and Red Hat.
What type of attack does CVE-2016-7426 enable?
CVE-2016-7426 allows remote attackers to perform denial of service attacks by sending spoofed responses to NTP servers.
Is there a patch available for CVE-2016-7426?
Yes, a patch is available and users should update to NTP version 4.2.8p15 or higher to eliminate the vulnerability.