← Back

CVE-2021-3570

nvd nist
Published: Jul 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.

Affected (19)

Show all products
Linuxptp
4 products
Enterprise Linux
Enterprise Linux Aus
Enterprise Linux Eus
Enterprise Linux Tus
1 product
Fedora
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linuxptp Project
Before 1.5.1
From 1.6.0 to 1.6.1
From 1.7.0 to 1.7.1
From 1.8.0 to 1.8.1
From 1.9.0 to 1.9.3
From 2.0.0 to 2.0.1
From 3.0.0 to 3.1.1
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Version 8.0
Redhat
Version 8.2
Version 8.4
Redhat
Version 8.1
Version 8.2
Redhat
Version 8.2
Version 8.4
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

Timeline

No history available yet.