CVE-2021-3570

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3570

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:2660

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3570.html

OS impact

OSVersionStatusFixed in
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed3.1-2.1
debian debianbullseyefixed3.1-2.1
debian debianforkyfixed3.1-2.1
debian debiansidfixed3.1-2.1
debian debiantrixiefixed3.1-2.1

References

Verify integrity in audit chain (admin only). AS-IS.