yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-26551
Component Overview
Vulnerability Overview
Name
CVE-2023-26551
Source
NVD (
link
)
Debian (
link
)
Description
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
CWEs
CWE-787
CWE-787
Published Date
Apr 11, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26551
Third Party Advisory
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321
Third Party Advisory
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26551
Third Party Advisory
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321
Third Party Advisory
Analysis
#
Affected Component
Analysis
ntp
Patched
Vulnerability Ratings
#
5.6
CVSSv31
5.6
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ntp
buildroot
2025.02.x
4.2.8p18
Not Affected
ntp
buildroot
master
4.2.8p18
Not Affected
ntpd
openwrt
master
4.2.8_p18-r3
Not Affected
ntpd
openwrt
openwrt-25.12
4.2.8_p18-r3
Not Affected
ntp
yocto
master
4.2.8p18
Not Affected
ntp
yocto
scarthgap
4.2.8p17
Not Affected
Resolved with patches
#
ntp (yocto:kirkstone)
#
Title
Author
Resolve
1
Patch #1
Peter Marko <peter.marko@siemens.com>
CVE-2023-26551
CVE-2023-26552
CVE-2023-26553
CVE-2023-26554
CVE-2023-26555