CVE-2021-3570
Description
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3570
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:2660
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3570.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| rocky | 8 | fixed | |
| debian | bookworm | fixed | 3.1-2.1 |
| debian | bullseye | fixed | 3.1-2.1 |
| debian | forky | fixed | 3.1-2.1 |
| debian | sid | fixed | 3.1-2.1 |
| debian | trixie | fixed | 3.1-2.1 |
References
Verify integrity in audit chain (admin only). AS-IS.