CVE-2024-42861: High severity Linuxptp Project Linuxptp vulnerability
Published Sep 23, 2024
·Updated
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted PdelayReq message to the time synchronization function
Affected Software
3 affected componentsFixes available
Linuxptp Project Linuxptp<=4.2
Microsoft azl3 linuxptp 3.1.1-1<3.1.1-1
3.1.1-1
Microsoft cbl2 linuxptp 3.1.1-1<3.1.1-1
3.1.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.1.1-1
Event History
Sep 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityAffected Software
Oct 2, 2025
Data Sourced
via Microsoft·06:11 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·06:11 AM
Affected Software
Updated
via Microsoft·06:11 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-42861?
The severity of CVE-2024-42861 is classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2024-42861?
To fix CVE-2024-42861, update the linuxptp package to a version later than 4.2.
3
Who is affected by CVE-2024-42861?
CVE-2024-42861 affects users of linuxptp versions 4.2 and earlier.
4
What type of attack does CVE-2024-42861 facilitate?
CVE-2024-42861 facilitates a remote denial of service attack through a crafted Pdelay_Req message.
5
Can CVE-2024-42861 be exploited without authentication?
Yes, CVE-2024-42861 can be exploited remotely without authentication.