On Wed, Jul 22, 2026 at 11:24:41AM +0100, jch@thehaxbys.co.uk wrote:
An icmp timestamp request is classed a a minor security vulnerability
(CVE-1999-0524) due to an information leak. As pretty much everything
uses NTP these days, it's not as though this is an actual problem but
scanners flag this so for everyone's sake, let's just discard timestamp
requests.
The idea was discussed in the past and was rejected:
https://lore.kernel.org/netdev/1557711193-7284-1-git-send-email-chenweilong@huawei.com/ (local)
https://lore.kernel.org/netdev/1557754137-100816-1-git-send-email-chenweilong@huawei.com/ (local)
https://lore.kernel.org/netdev/20240520165335899feIJEvG6iuT4f7FBU6ctk@zte.com.cn/ (local)
I don't see a reason to revisit this.