CVE-2019-8936: Null Pointer Dereference
Published May 15, 2019
·Updated
Last updated 25 August 2025
Other sources
NTP through 4.2.8p12 has a NULL Pointer Dereference.
— MITRE
Affected Software
36 affected componentsFixes available
debian/ntp
1:4.2.8p15+dfsg-1
NetApp Clustered Data ONTAP<9.2
NetApp Data Ontap 7-mode
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Fedoraproject Fedora=30
openSUSE Leap=15.0
openSUSE Leap=42.3
HPE Hpux-ntp<c.4.2.8.4.0
NTP ntp<4.2.8
NTP ntp=4.2.8
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p10
NTP ntp=4.2.8-p11
NTP ntp=4.2.8-p12
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
NTP ntp=4.2.8-p4
NTP ntp=4.2.8-p5
NTP ntp=4.2.8-p6
NTP ntp=4.2.8-p7
NTP ntp=4.2.8-p8
NTP ntp=4.2.8-p9
Remediation
Patch Available
Event History
May 15, 2019
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·05:28 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:29 PM
Description
Frequently Asked Questions
1
What is CVE-2019-8936?
CVE-2019-8936 is a vulnerability in NTP through 4.2.8p12 that allows for a NULL pointer dereference.
2
How severe is CVE-2019-8936?
CVE-2019-8936 has a severity rating of 7.5, which is classified as high.
3
Which software versions are affected by CVE-2019-8936?
CVE-2019-8936 affects NTP versions up to and including 4.2.8p12.
4
How can I fix CVE-2019-8936?
To fix CVE-2019-8936, update to NTP version 4.2.8p15 or later.
5
Where can I find more information about CVE-2019-8936?
You can find more information about CVE-2019-8936 at the following references: [1](http://bugs.ntp.org/show_bug.cgi?id=3565) [2](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html) [3](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html)