CVE Vulnerabilities

CVE-2015-1822

Published: Apr 16, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

chrony before 1.31.1 does not initialize the last next pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian7.0 (including)7.0 (including)
Red Hat Enterprise Linux 7RedHatchrony-0:2.1.1-1.el7*
ChronyUbuntuesm-infra-legacy/trusty*
ChronyUbuntulucid*
ChronyUbuntuprecise*
ChronyUbuntutrusty*
ChronyUbuntutrusty/esm*
ChronyUbuntuupstream*
ChronyUbuntuutopic*
ChronyUbuntuvivid*
ChronyUbuntuwily*
ChronyUbuntuyakkety*
ChronyUbuntuzesty*

References