The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.
| Software | From | Fixed in |
|---|---|---|
| tuxfamily / chrony | 1.19 | 1.19.x |
| tuxfamily / chrony | 1.20 | 1.20.x |
| tuxfamily / chrony | - | 1.23-pre1.x |
| tuxfamily / chrony | 1.19.99.3 | 1.19.99.3.x |
| tuxfamily / chrony | 1.19-1 | 1.19-1.x |
| tuxfamily / chrony | 1.19.99.2 | 1.19.99.2.x |
| tuxfamily / chrony | 1.21-pre1 | 1.21-pre1.x |
| tuxfamily / chrony | 1.18 | 1.18.x |
| tuxfamily / chrony | 1.24-pre1 | 1.24-pre1.x |
| tuxfamily / chrony | 1.19.99.1 | 1.19.99.1.x |
| tuxfamily / chrony | 1.21 | 1.21.x |