PT-2026-7912 · Ntpd-Rs · Ntpd-Rs

Lamz

·

Published

2026-02-12

·

Updated

2026-03-31

·

CVE-2026-26076

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ntpd-rs versions prior to 1.7.1
Description ntpd-rs is a full-featured implementation of the Network Time Protocol. An attacker can remotely cause moderate increases in CPU usage (2-4 times above normal). When Network Time System (NTS) is enabled on an ntpd-rs server, an attacker can create malformed NTS packets that require significantly more server effort to respond to by requesting a large number of cookies. This can lead to degraded server performance.
Recommendations Update to version 1.7.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-26076
GHSA-C7J7-RMVR-FJMV

Affected Products

Ntpd-Rs