CVE-2018-7184: High severity NTP ntp vulnerability
Last updated 25 August 2025
Other sources
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-7184?
CVE-2018-7184 is a vulnerability in the ntpd service in ntp version 4.2.8p4 before 4.2.8p11.
What is the severity of CVE-2018-7184?
CVE-2018-7184 has a severity rating of 7.5 (high).
How does CVE-2018-7184 affect ntpd?
CVE-2018-7184 allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent peer despite being a bad packet.
Which software versions are affected by CVE-2018-7184?
CVE-2018-7184 affects ntp versions 4.2.8-p4 to 4.2.8-p10.
How can I fix CVE-2018-7184?
To fix CVE-2018-7184, you should update to ntp version 4.2.8p11 or later.