cbcvebase.
CVE-2021-3571
published 2021-07-09

CVE-2021-3571: A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote…

PriorityP339high7.1CVSS 3.1
AVNACLPRLUINSUCLINAH
EPSS
1.90%
77.3th percentile
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinuxptp< linuxptp 3.1-2.1 (bookworm)linuxptp 3.1-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxptp_projectlinuxptp< 2.0.12.0.1
linuxptp_projectlinuxptp
linuxptp_projectlinuxptp>= 0 < 3.1-2.13.1-2.1
linuxptp_projectlinuxptp>= 0 < 3.1-2.13.1-2.1
linuxptp_projectlinuxptp>= 0 < 3.1-2.13.1-2.1
linuxptp_projectlinuxptp>= 0 < 3.1-2.13.1-2.1
linuxptp_projectlinuxptp>= 3.0 < 3.1.13.1.1
msrccbl2_linuxptp_on_cbl_mariner_2.0
redhatenterprise_linux

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.