Resource exhaustion in ntpd-rs - CVE-2026-26076
Published: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the NTS packet handling functionality when processing malformed NTS packets that request a large number of cookies. A remote attacker can send specially crafted packets to cause a denial of service.
Only servers with NTS enabled are vulnerable.
Affected software
Fedora
ntpd-rs
How to mitigate CVE-2026-26076
ntpd-rs - addressed in versions 1.7.1-1.el10_1, 1.7.1-1.el10_2, 1.7.1-1.el10_3, 1.7.1-1.fc42, 1.7.1-1.fc43, 1.7.1-1.fc44