High severity7.5NVD Advisory· Published May 15, 2019· Updated Jun 17, 2026
CVE-2019-8936
CVE-2019-8936
Description
NTP through 4.2.8p12 has a NULL Pointer Dereference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
57cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*+ 27 more
- cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*range: <4.2.8
- cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta4:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta5:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p10:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p11:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p12:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p4:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p5:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:*
- (no CPE)range: <=4.2.8p12
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:data_ontap:-:*:*:*:*:7-mode:*:*
- NTP/NTPdescription
- osv-coords20 versionspkg:rpm/opensuse/ntp&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/ntp&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ntp&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/ntp&distro=SUSE%20OpenStack%20Cloud%207
< 4.2.8p13-lp150.8.1+ 19 more
- (no CPE)range: < 4.2.8p13-lp150.8.1
- (no CPE)range: < 4.2.8p15-7.2
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-4.6.1
- (no CPE)range: < 4.2.8p13-48.27.1
- (no CPE)range: < 4.2.8p13-64.13.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-46.32.1
- (no CPE)range: < 4.2.8p13-64.13.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
- (no CPE)range: < 4.2.8p13-85.1
Patches
Vulnerability mechanics
References
15- security.netapp.com/advisory/ntap-20190503-0001/nvdPatchThird Party Advisory
- bugs.ntp.org/show_bug.cginvdExploitIssue TrackingVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.htmlnvdMailing ListThird Party Advisory
- packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.htmlnvdThird Party AdvisoryVDB Entry
- support.ntp.org/bin/view/Main/SecurityNoticenvdRelease NotesVendor Advisory
- seclists.org/bugtraq/2019/May/39nvdIssue TrackingMailing ListThird Party Advisory
- security.freebsd.org/advisories/FreeBSD-SA-19:04.ntp.ascnvdMitigationThird Party Advisory
- security.gentoo.org/glsa/201903-15nvdThird Party Advisory
- support.f5.com/csp/article/K61363039nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/nvd
- usn.ubuntu.com/4563-1/nvd
News mentions
0No linked articles in our index yet.