Database/Control plane, storage & DevOps
ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worse
Impact
A remote attacker who can predict transmit timestamps can crash ntpd or, worse, change the system time. Changing the time on a cluster node is a more interesting attack than crashing it: certificates become valid or invalid, log timestamps stop lining up with reality, and scheduled jobs fire at the wrong moment.
Who can reach it
Remote attacker able to predict the client's transmit timestamps for outgoing packets.
What to do
Upgrade ntp to 4.2.8p14 or later, or move to chrony/NTS. Package upgrade and service restart. Monitor for step changes in system time as a detection control — most fleets do not alert on this and should.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.