Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42: ntpd-rs 1.5.0 critical: Denial of Service Fix

fedora
Calendar Grey May 3, 2025
Dist Fedora Esm H88
Fedora 42 enhances chrony to version 4.2.1, addressing time synchronization vulnerabilities by improving data handling and additional measures.
Update to version 1.5.0 (for now, without PPS feature enabled due to potential correctness issues in the code)

Summary

Full-featured implementation of NTP with NTS support.

Update Information:

Update to version 1.5.0 (for now, without PPS feature enabled due to potential correctness issues in the code). Release notes: https://github.com/pendulum-project/ntpd-rs/releases/tag/v1.5.0 Also contains the fix for GHSA-v83q-83hj-rw38.

Change Log

* Thu Apr 24 2025 Fabio Valentini - 1.5.0-1 - Update to version 1.5.0; Fixes RHBZ#2329317

References


[ 1 ] Bug #2349338 - ntpd-rs: ntpd NTS client denial of service via wrongly sized cookies [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2349338 [ 2 ] Bug #2349339 - ntpd-rs: ntpd NTS client denial of service via wrongly sized cookies [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2349339

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c480cf7e5e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ntpd-rs
Product: Fedora 42
Version: 1.5.0
Release: 1.fc42
Summary: Full-featured implementation of NTP with NTS support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here