First published: Mon May 31 2021(Updated: )
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linuxptp | 1.9.2-1+deb10u1 3.1-2.1 3.1.1-4 4.0-1 | |
Linuxptp Project Linuxptp | <1.5.1 | |
Linuxptp Project Linuxptp | >=1.6.0<1.6.1 | |
Linuxptp Project Linuxptp | >=1.8.0<1.8.1 | |
Linuxptp Project Linuxptp | >=1.9.0<1.9.3 | |
Linuxptp Project Linuxptp | >=2.0.0<2.0.1 | |
Linuxptp Project Linuxptp | >=3.0.0<3.1.1 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Aus | =8.2 | |
Redhat Enterprise Linux Aus | =8.4 | |
Redhat Enterprise Linux Eus | =8.1 | |
Redhat Enterprise Linux Eus | =8.2 | |
Redhat Enterprise Linux Tus | =8.2 | |
Redhat Enterprise Linux Tus | =8.4 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =10.0 | |
debian/linuxptp | <=3.1-2<=1.9.2-1 | 3.1-2.1 1.9.2-1+deb10u1 |
redhat/linuxptp | <3.1.1 | 3.1.1 |
redhat/linuxptp | <2.0.1 | 2.0.1 |
redhat/linuxptp | <1.9.3 | 1.9.3 |
redhat/linuxptp | <1.8.1 | 1.8.1 |
redhat/linuxptp | <1.7.1 | 1.7.1 |
redhat/linuxptp | <1.6.1 | 1.6.1 |
redhat/linuxptp | <1.5.1 | 1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3570 is high (8.8).
CVE-2021-3570 can potentially lead to data confidentiality breaches.
The affected software for CVE-2021-3570 includes Linuxptp Project Linuxptp, Redhat Enterprise Linux, and Fedora.
To fix CVE-2021-3570, it is recommended to update the linuxptp package to version 1.9.2-1+deb10u1 (for Debian) or 3.1-2.1 (for other distributions).
You can find more information about CVE-2021-3570 at the following references: [reference 1](https://security-tracker.debian.org/tracker/CVE-2021-3570), [reference 2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3570), [reference 3](https://security-tracker.debian.org/tracker/CVE-2021-3571).