Executive brief
A security vulnerability has been identified in NTPsec, a suite of tools used to synchronize time across computer networks. A local user with limited access could trigger a system crash by exploiting a flaw in how the software handles specific hardware clock data. This could lead to a denial of service, disrupting time-sensitive operations and network stability.
Technical details
A classic buffer overflow (CWE-120) exists in the Zyfer reference clock (refclock) driver within NTPsec. The vulnerability is caused by a buffer copy operation that does not properly check the size of the input data. A local attacker with low privileges can exploit this flaw to trigger a crash of the ntpd daemon. The attack requires specific conditions (high complexity) but results in a partial impact on system availability. The issue is addressed in NTPsec version 1.2.5.
Affected products
- NTPsec ntpsec < 1.2.5
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory