A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade linuxptp | May 4, 2022 | Jul 9, 2021 |
| Amazon Linux Ami 2 | — | Upgrade linuxptpUpgrade linuxptp-debuginfo | Aug 6, 2021 | Jul 9, 2021 |
| Centos_linux | — | Upgrade linuxptpUpgrade linuxptp-debugsourceUpgrade linuxptp-debuginfo | Jul 8, 2021 | Jul 6, 2021 |
| Debian | — | Upgrade linuxptp | Jul 15, 2021 | Jul 9, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade linuxptp | Oct 26, 2021 | Jul 9, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade linuxptp | Sep 29, 2021 | Jul 9, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade linuxptp | Sep 24, 2021 | Jul 9, 2021 |
| Oracle_linux | — | Upgrade linuxptp | Jul 7, 2021 | Jul 5, 2021 |
| Redhat_linux | — | Upgrade linuxptpUpgrade linuxptp-debuginfoNo solution existsUpgrade linuxptp-debugsource | Jul 8, 2021 | Jul 6, 2021 |
| Rocky_linux | — | Upgrade linuxptp-debuginfoUpgrade linuxptpUpgrade linuxptp-debugsource | May 5, 2022 | Jul 9, 2021 |
| Suse | — | Upgrade linuxptp | Jul 22, 2021 | Jul 7, 2021 |
| Ubuntu | — | Upgrade linuxptpUpgrade linuxptp (Ubuntu Pro) | May 30, 2023 | Jul 9, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 9, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub