{"id":"GHSA-4855-q42w-5vr4","summary":"DoS Vulnerability in ntpd-rs","details":"# Summary\n\nA denial of service vulnerability was discovered in ntpd-rs where an attacker can induce a message storm between two NTP servers running ntpd-rs.\n\n# Details\n\nSince ntpd-rs version 1.2.0, when configured as a server, incorrectly responded to all NTP messages sent to the server's port with a time reply, including to responses from other servers. As a consequence, a message with a spoofed IP address of another server could cause two servers running ntpd-rs to continually respond to each other, consuming significant amounts of resources.\n\n# Impact\n\nAny time server running ntpd-rs with version between 1.2.0 and 1.6.1 inclusive which allows non-NTS traffic is affected. Client-only configurations are not affected. Affected users are recommended to upgrade to version 1.6.2 as soon as possible.\n\n# Workarounds\n\nShould upgrading not be possible, the impact of the issue can be mitigated by:\n - Whitelisting access to only IP addresses of clients using the server, using the ignore filter method.\n - Blocking incoming non-request traffic on the NTP server port using a firewall.\n - Disabling public access to the vulnerable NTP server\n - Disabling the server functionality by removing any [server] sections from the configuration.\n\n# Acknowledgements\n\nThe ntpd-rs authors thank Eric Sesterhenn from X41 D-Sec GmbH for finding and reporting this issue.","aliases":["CVE-2025-58066"],"modified":"2025-08-29T21:58:17Z","published":"2025-08-29T20:07:27Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-08-29T20:07:27Z","nvd_published_at":"2025-08-29T21:15:36Z","cwe_ids":["CWE-406"]},"references":[{"type":"WEB","url":"https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58066"},{"type":"WEB","url":"https://github.com/pendulum-project/ntpd-rs/commit/da37cf167736cbd4d7804b1ed7ceb572468298e0"},{"type":"PACKAGE","url":"https://github.com/pendulum-project/ntpd-rs"}],"affected":[{"package":{"name":"ntpd-rs","ecosystem":"crates.io","purl":"pkg:cargo/ntpd-rs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.2.0"},{"fixed":"1.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4855-q42w-5vr4/GHSA-4855-q42w-5vr4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}