CVE-2018-7183

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-7183

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-7183.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201803-11

OS impact

OSVersionStatusFixed in
arch archfixed4.2.8.p11-1
suse slesaffected
debian debianbullseyefixed1:4.2.8p11+dfsg-1
debian debianbookwormfixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

References

Verify integrity in audit chain (admin only). AS-IS.