NULL pointer dereference in ntp - CVE-2019-8936
Published: August 20, 2019 / Updated: October 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when processing authenticated mode 6 packets. A remote attacker can send malicious authenticated mode 6 (ntpq) packet from a permitted network address, trigger a NULL pointer dereference error and crash ntpd.
Affected software
Gentoo Linux
Amazon Linux AMI
IBM AIX
Junos OS
Slackware Linux
Opensuse
Ubuntu
Junos OS Evolved
Fedora
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
sntp (Ubuntu package)
ntpdate (Ubuntu package)
ntp (Ubuntu package)
ntp
How to mitigate CVE-2019-8936
Junos OS - addressed in versions 12.3X48-D95, 12.3R12-S15, 12.3R12-S19, 13.2X51-D40, 14.1X53-D30, 14.1X53-D53, 14.1X53-D140, 15.1x49-D190, 15.1X49-D200, 15.1X53-D593, 15.1R7-S6, 15.1R7-S9, 15.1R7-S10, 16.1R7-S6, 16.1R7-S7, 16.2R2-S11, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.1R3-S2, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.3R3-S7, 17.3R3-S11, 17.3R3-S12, 17.4R2-S7, 17.4R2-S9, 17.4R2-S12, 17.4R2-S13, 17.4R3, 17.4R3-S3, 17.4R3-S5, 18.1R3-S8, 18.1R3-S9, 18.1R3-S11, 18.1R3-S13, 18.2R2-S6, 18.2R2-S7, 18.2R2-S8, 18.2R3-S1, 18.2R3-S3, 18.2R3-S7, 18.2R3-S8, 18.3R1-S5, 18.3R1-S7, 18.3R2-S2, 18.3R2-S3, 18.3R3, 18.3R3-S1, 18.3R3-S4, 18.3R3-S5, 18.4R1-S4, 18.4R1-S5, 18.4R1-S8, 18.4R2-S1, 18.4R2-S4, 18.4R2-S7, 18.4R2-S10, 18.4R3, 18.4R3-S6, 18.4R3-S8, 18.4R3-S10, 19.1R1-S3, 19.1R1-S4, 19.1R1-S6, 19.1R2, 19.1R2-S1, 19.1R3, 19.1R3-S4, 19.1R3-S5, 19.1R3-S7, 19.1R3-S9, 19.2R1-S1, 19.2R1-S3, 19.2R1-S6, 19.2R1-S7, 19.2R1-S8, 19.2R1-S9, 19.2R2, 19.2R3-S1, 19.2R3-S2, 19.2R3-S4, 19.2R3-S5, 19.3R1, 19.3R1-S1, 19.3R2-S1, 19.3R2-S5, 19.3R2-S6, 19.3R3, 19.3R3-S1, 19.3R3-S2, 19.3R3-S4, 19.3R3-S5, 19.3R3-S6, 19.4R1, 19.4R1-S4, 19.4R2, 19.4R2-S2, 19.4R2-S4, 19.4R2-S6, 19.4R2-S7, 19.4R2-S8, 19.4R3, 19.4R3-S3, 19.4R3-S6, 19.4R3-S7, 19.4R3-S8, 19.4R3-S9, 19.4R3-S10, 20.1R1, 20.1R2, 20.1R2-S2, 20.1R3, 20.1R3-S3, 20.1R3-S4, 20.2R1-S3, 20.2R2, 20.2R2-S3, 20.2R3, 20.2R3-S3, 20.2R3-S4, 20.2R3-S5, 20.2R3-S6, 20.3R1, 20.3R2, 20.3R3-S2, 20.3R3-S3, 20.3R3-S4, 20.3R3-S5, 20.3R3-S6, 20.4R1-S1, 20.4R2, 20.4R3, 20.4R3-S1, 20.4R3-S3, 20.4R3-S4, 20.4R3-S5, 20.4R3-S8, 21.1R1, 21.1R2, 21.1R3-S1, 21.1R3-S3, 21.1R3-S4, 21.2R1, 21.2R2-S1, 21.2R2-S2, 21.2R3, 21.2R3-S1, 21.2R3-S2, 21.2R3-S4, 21.2R3-S6, 21.3R2, 21.3R3-S1, 21.3R3-S3, 21.3R3-S5, 21.4R1, 21.4R1-S1, 21.4R2, 21.4R2-S1, 21.4R3, 21.4R3-S1, 21.4R3-S4, 22.1R1, 22.1R1-S2, 22.1R2, 22.1R2-S2, 22.1R3, 22.1R3-S3, 22.2R1, 22.2R1-S1, 22.2R2, 22.2R2-S1, 22.2R3, 22.2R3-S1, 22.3R1, 22.3R1-S1, 22.3R2, 22.3R2-S2, 22.3R3, 22.4R1, 22.4R2-S1, 22.4R3, 23.2R1
Junos OS Evolved - addressed in versions 20.4R2-S2-EVO, 21.1R2-EVO, 21.2R1-EVO
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
sntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntpdate (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp - addressed in versions 4.2.8p13-1.fc28, 4.2.8p13-1.fc29, 4.2.8p13-1.fc30
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
External References
- http://support.ntp.org/bin/view/Main/NtpBug3565
- http://bugs.ntp.org/show_bug.cgi?id=3565
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html
- http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.html
- http://support.ntp.org/bin/view/Main/SecurityNotice
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/
- https://seclists.org/bugtraq/2019/May/39
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.asc
- https://security.gentoo.org/glsa/201903-15
- https://security.netapp.com/advisory/ntap-20190503-0001/
- https://support.f5.com/csp/article/K61363039
Related Security Bulletins
- IBM AIX update for NTP
- OpenSUSE Linux update for ntp
- OpenSUSE Linux update for ntp
- Amazon Linux AMI update for ntp
- Gentoo update for NTP
- Slackware Linux update for ntp
- Denial of service in ntpd
- Denial of service in Juniper Junos OS ntpd
- Denial of service in Junos OS Evolved ntpd
- Ubuntu update for ntp
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Ubuntu update for ntp
- Fedora 28 update for ntp
- Fedora 29 update for ntp
- Fedora 30 update for ntp