CVE-2026-18321

NameCVE-2026-18321
DescriptionBuffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntpsec (PTS)bullseye1.2.0+dfsg1-4vulnerable
bookworm, bookworm (security)1.2.2+dfsg1-1+deb12u1vulnerable
trixie1.2.3+dfsg1-8vulnerable
forky, sid1.2.4+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntpsecsource(unstable)(unfixed)

Notes

https://gitlab.com/NTPsec/ntpsec/-/work_items/890
check details, upstream work item not public at 2026-07-31

Search for package or bug name: Reporting problems