Resource exhaustion in ntpd-rs - CVE-2026-26076
Published: April 24, 2026
ntpd-rs
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the NTS packet handling functionality when processing malformed NTS packets that request a large number of cookies. A remote attacker can send specially crafted packets to cause a denial of service.
Only servers with NTS enabled are vulnerable.