High severity8.1NVD Advisory· Published Jan 26, 2016· Updated May 6, 2026
CVE-2016-1567
CVE-2016-1567
Description
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Affected products
5cpe:2.3:a:tuxfamily:chrony:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:tuxfamily:chrony:*:*:*:*:*:*:*:*range: <=1.31.1
- cpe:2.3:a:tuxfamily:chrony:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:tuxfamily:chrony:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:tuxfamily:chrony:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:tuxfamily:chrony:2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.