Cloudflare · Cfnts · CVE-2023-3036
**Name of the Vulnerable Software and Affected Versions**
github.com/cloudflare/cfnts versions prior to commit 783490b
**Description**
The issue is related to an unchecked read in the NTP server, which allows a remote attacker to trigger a panic by sending an NTSAuthenticator packet with an extension length longer than the packet contents.
**Recommendations**
For versions prior to commit 783490b, update to a version that includes the fix for this issue, specifically commit 783490b or later. As a temporary workaround, consider restricting access to the NTP server to minimize the risk of exploitation.