CVE-2014-9751

medium
Published 2015-10-06 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-9751

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulne

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://bugs.ntp.org/show_bug.cgi?id=2672

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-9751.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbullseyefixed1:4.2.6.p5+dfsg-4
linux linux-kernel-not-affected
macos macos-not-affected
debian debian7.0affected
debian debian8.0affected
debian debian9.0affected
redhat rhel6.0affected

Application impact

VendorProductVersionsFixed
ntpntp{"startIncluding":"4.2.0","endExcluding":"4.2.8"}4.2.8
ntpntp4.2.8

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.