CVE-2021-3570 is a critical vulnerability in the ptp4l program of the linuxptp package, affecting versions prior to 3.1.1 and several earlier releases across Debian, Fedora, and Red Hat. This flaw, stemming from a missing length check during PTP message forwarding, allows a remote attacker to achieve information leaks, system crashes, or potentially remote code execution. With a CVSS score of 8.8 (HIGH), it presents a significant threat to data confidentiality, integrity, and system availability, requiring no user interaction or complex attack conditions. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
>= 1.7.0, < 1.7.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
>= 1.8.0, < 1.8.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
>= 1.9.0, < 1.9.3CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.