QID 239849

Date Published: 2021-11-10

QID 239849: Red Hat Update for linuxptp security (RHSA-2021:4321)

the linuxptp packages provide precision time protocol (ptp) implementation for linux according to ieee standard 1588 for linux.
The dual design goals are to provide a robust implementation of the standard and to use the most relevant and modern application programming interfaces (api) offered by the linux kernel.

Security Fix(es):
  • linuxptp: wrong length of one-step follow-up in transparent clock (cve-2021-3571)

Affected Products:

  • Red Hat enterprise linux for x86_64 8 x86_64
  • Red Hat enterprise linux for ibm z systems 8 s390x
  • Red Hat enterprise linux for power, little endian 8 ppc64le
  • Red Hat enterprise linux for arm 64 8 aarch64



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch.

    Refer to Refer to :
    Applying Package Updates to RHEL system
    for details.

    Refer to Red Hat security advisory RHSA-2021:4321 Update to address this issue and obtain more information.

    Vendor References

    CVEs related to QID 239849

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2021:4321 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2021:4321