PatchSiren cyber security CVE debrief
CVE-2016-2516 Ntp CVE debrief
CVE-2016-2516 is a denial-of-service issue in NTP’s ntpd daemon. On affected releases, if mode7 is enabled, a remote attacker can cause ntpd to abort by using the same IP address multiple times in an unconfig directive. The issue was published by NVD on 2017-01-30 and later marked modified on 2026-05-13.
- Vendor
- Ntp
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-30
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-30
- Advisory updated
- 2026-05-13
Who should care
Administrators running NTP/ntpd on exposed systems, especially environments that still enable mode7 or rely on older NTP 4.2.8/4.3.x builds. This also matters to distro and appliance maintainers who may have inherited vulnerable versions or backports.
Technical summary
The supplied CVE description identifies a remotely triggerable ntpd abort in NTP before 4.2.8p7 and 4.3.x before 4.3.92, but only when mode7 is enabled. NVD classifies the weakness as CWE-20 and rates it CVSS 3.0 5.3 (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating an availability impact rather than confidentiality or integrity loss. The attack condition is configuration-dependent, so exposure is highest where mode7 remains enabled and the daemon is reachable by an attacker with the ability to send the relevant request.
Defensive priority
Medium. This is not an information disclosure or code execution issue, but it can crash a time service daemon and disrupt dependent systems. Prioritize if ntpd is Internet-facing, mission-critical, or still using legacy mode7 features.
Recommended defensive actions
- Upgrade NTP/ntpd to a fixed release at or above 4.2.8p7 or 4.3.92, or install the vendor/package update that backports the fix.
- Review whether mode7 is enabled anywhere in your fleet; if it is not required, disable or restrict it according to vendor guidance.
- Check vendor and distribution advisories for any packaged mitigation or backport status before assuming a version string alone is sufficient.
- Monitor ntpd crash logs and service restarts so repeated aborts are detected quickly.
- If you operate multiple NTP deployments, inventory them now to confirm which hosts are running affected branches and whether mode7 exposure exists.
Evidence notes
All claims above are drawn from the supplied CVE/NVD corpus and linked references. The key evidence is the CVE description stating affected versions (before 4.2.8p7 and 4.3.x before 4.3.92), the mode7 requirement, and the ntpd abort/DoS impact. NVD also supplies the CVSS v3.0 vector AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H and CWE-20. References include the NTP vendor advisory page, plus distro and third-party advisories that corroborate remediation context.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-2516 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-2516
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-2516 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-2516
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.freebsd.org/advisories/FreeBSD-SA-16:16.ntp.asc
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201607-15
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.