CVE-2021-3571
published 2021-07-09CVE-2021-3571: A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote…
PriorityP339high7.1CVSS 3.1
AVNACLPRLUINSUCLINAH
EPSS
1.90%
77.3th percentile
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linuxptp | < linuxptp 3.1-2.1 (bookworm) | linuxptp 3.1-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxptp_project | linuxptp | < 2.0.1 | 2.0.1 |
| linuxptp_project | linuxptp | — | — |
| linuxptp_project | linuxptp | >= 0 < 3.1-2.1 | 3.1-2.1 |
| linuxptp_project | linuxptp | >= 0 < 3.1-2.1 | 3.1-2.1 |
| linuxptp_project | linuxptp | >= 0 < 3.1-2.1 | 3.1-2.1 |
| linuxptp_project | linuxptp | >= 0 < 3.1-2.1 | 3.1-2.1 |
| linuxptp_project | linuxptp | >= 3.0 < 3.1.1 | 3.1.1 |
| msrc | cbl2_linuxptp_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync
vendor_msrc·2021-07-13·CVSS 7.1
CVE-2021-3571 [HIGH] CWE-119 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
Red Hat
linuxptp: wrong length of one-step follow-up in transparent clock
vendor_redhat·2021-07-05·CVSS 7.1
CVE-2021-3571 [HIGH] CWE-119 linuxptp: wrong length of one-step follow-up in transparent clock
linuxptp: wrong length of one-step follow-up in transparent clock
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and sy
Debian
CVE-2021-3571: linuxptp - A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is ope...
vendor_debian·2021·CVSS 7.1
CVE-2021-3571 [HIGH] CVE-2021-3571: linuxptp - A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is ope...
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
Scope: local
bookworm: resolved (fixed in 3.1-2.1)
bullseye: resolved (fixed in 3.1-2.1)
forky: resolved (fixed in 3.1-2.1)
sid: resolved (fixed in 3.1-2.1)
trixie: resolved (fixed in 3.1-2.1)
GHSA
GHSA-3v9q-m45q-4cr7: A flaw was found in the ptp4l program of the linuxptp package
ghsa_unreviewed·2022-05-24
CVE-2021-3571 [HIGH] CWE-119 GHSA-3v9q-m45q-4cr7: A flaw was found in the ptp4l program of the linuxptp package
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
OSV
CVE-2021-3571: A flaw was found in the ptp4l program of the linuxptp package
osv·2021-07-09·CVSS 7.1
CVE-2021-3571 [HIGH] CVE-2021-3571: A flaw was found in the ptp4l program of the linuxptp package
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1966241https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RHRUVSDP673LXJ5HGIPQPWPIYUPWYQA7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUBKTRCMJ6VKS7DIBSZQB4ATSKVCJYXJ/https://bugzilla.redhat.com/show_bug.cgi?id=1966241https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RHRUVSDP673LXJ5HGIPQPWPIYUPWYQA7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUBKTRCMJ6VKS7DIBSZQB4ATSKVCJYXJ/
2021-07-09
Published