Linuxptp Project maintains a specialized precision-time-synchronization implementation for Linux systems, a narrowly scoped but operationally critical component in environments requiring sub-microsecond clock accuracy across networked hosts. Its observed vulnerabilities center on the memory-safety challenges inherent to a C-based network daemon, clustering around buffer-boundary issues and out-of-bounds access patterns that emerge from parsing untrusted timing packets. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxptp Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3570HIGH A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information l | Jul 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-3571HIGH A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a cr | Jul 9, 2021 | 7.1 | 24 | NO | NO |
CVE-2024-42861HIGH An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function | Sep 23, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxptp Project.
Media articles that mention a CVE ID that affects a product developed by Linuxptp Project — matched by CVE ID, not by vendor name.