CVE-2018-7182: High severity NTP ntp vulnerability
Last updated 25 August 2025
Other sources
The ctlgetitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntpto a version that resolves this vulnerability.Fixed in 1:4.2.8p15+dfsg-1 - Upgrade
Upgrade
debian/ntpsecto a version that resolves this vulnerability.Fixed in 1.2.0+dfsg1-4Fixed in 1.2.2+dfsg1-1+deb12u1Fixed in 1.2.3+dfsg1-8Fixed in 1.2.4+dfsg-1 - Upgrade
Upgrade
ntp/ntpdto a version that resolves this vulnerability.Fixed in 4.2.8p11 - Compensating control
Apply compensating controls for exposed NTP service (e.g., restrict/limit inbound access to the NTP/ntpd port to trusted sources) while upgrading from ntp-4.2.8p6 through ntp-4.2.8p10 to ntp-4.2.8p11.
Event History
Frequently Asked Questions
What is CVE-2018-7182?
CVE-2018-7182 is a vulnerability in ntpd that allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet.
How does CVE-2018-7182 affect ntpd?
CVE-2018-7182 affects ntpd versions 4.2.8p6 through 4.2.8p10.
What is the severity of CVE-2018-7182?
CVE-2018-7182 has a severity rating of high (7.5).
How can I fix the CVE-2018-7182 vulnerability?
To fix the CVE-2018-7182 vulnerability, update your ntpd instance to version 4.2.8p11 or higher.
Where can I find more information about CVE-2018-7182?
You can find more information about CVE-2018-7182 at the following references: [1] [2] [3].