CVE-2021-3571 describes a flaw in the linuxptp ptp4l program, specifically affecting little-endian architectures operating as a PTP transparent clock. A remote attacker can exploit this by sending a crafted one-step sync message, potentially leading to an information leak or system crash. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating a low attack complexity and a significant impact on data confidentiality and system availability. While no active exploitation, public exploit code, or significant community discussion has been observed, affected products include various versions of fedoraproject, linuxptp_project, and redhat distributions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.1.1CPE matchmatch criteria | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
Jul 13, 2021linuxptp: wrong length of one-step follow-up in transparent clock
Jul 5, 2021