A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1.
Conclusion & alert: CVE-2021-3571 is rated Moderate Risk (53.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.72%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.43% | 0.72% | +0.29% |
| 2 | 2025-11-18 | 0.72% | 0.43% | -0.29% |
| 3 | 2025-10-08 | — | 0.72% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
2.8 | 4.2 | [email protected] |
| 5.5 | 2.0 | MEDIUM |
|
8.0 | 4.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-3571 not yet assigned priority: Debian including 1 source packages (linuxptp), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-3571 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-3571 |
suse
|
high | CVE-2021-3571 severity important: SUSE including 2 source package names (linuxptp, linuxptp-3.1.1-1.el8), 45 product×package rows across 45 product lines (HPE Helion OpenStack 8, SUSE CaaS Platform 4.0, … (45 product lines)): Known Not Affected 44, Fixed 1. | https://www.suse.com/security/cve/CVE-2021-3571/ |
ubuntu
|
medium | CVE-2021-3571 medium priority: Ubuntu including 1 source packages (linuxptp), 11 status rows across 11 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, trusty, upstream, xenial): not-affected 7, ignored 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2021-3571 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linuxptp_project | linuxptp | < 2.0.1 | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* |
| linuxptp_project | linuxptp | >= 3.0, < 3.1.1 | cpe:2.3:a:linuxptp_project:linuxptp:*:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |