{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "wrong length of one-step follow-up in transparent clock",
    "tracking": {
      "current_release_date": "2026-07-28T07:06:39+00:00",
      "generator": {
        "date": "2026-07-28T07:06:39+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2021-3571",
      "initial_release_date": "2021-07-05T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-28T07:06:39+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8.10.z::appstream",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8::appstream"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.5",
            "product": {
              "name": "Red Hat Enterprise Linux 8.5",
              "product_id": "rhel-8.5.0::appstream",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8::appstream"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.0",
            "product": {
              "name": "Red Hat Enterprise Linux 9.0",
              "product_id": "rhel-9.0",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.5",
            "product": {
              "name": "Red Hat Enterprise Linux 8.5",
              "product_id": "rhel-br-8.5.0::appstream",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8::appstream"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp",
            "product": {
              "name": "linuxptp",
              "product_id": "linuxptp",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp",
            "product": {
              "name": "linuxptp",
              "product_id": "linuxptp-0:3.1.1-1.el8",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp@3.1.1-1.el8?epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp",
            "product": {
              "name": "linuxptp",
              "product_id": "linuxptp-0:3.1.1-1.el8.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp@3.1.1-1.el8?arch=src&epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp-debuginfo",
            "product": {
              "name": "linuxptp-debuginfo",
              "product_id": "linuxptp-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp-debugsource",
            "product": {
              "name": "linuxptp-debugsource",
              "product_id": "linuxptp-debugsource",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp-debugsource"
              }
            }
          },
          {
            "category": "product_version",
            "name": "linuxptp",
            "product": {
              "name": "linuxptp",
              "product_id": "linuxptp.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/linuxptp?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:linuxptp"
        },
        "product_reference": "linuxptp",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:linuxptp"
        },
        "product_reference": "linuxptp",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:linuxptp"
        },
        "product_reference": "linuxptp",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:linuxptp"
        },
        "product_reference": "linuxptp",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-0:3.1.1-1.el8 as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-8.5.0::appstream:linuxptp-0:3.1.1-1.el8"
        },
        "product_reference": "linuxptp-0:3.1.1-1.el8",
        "relates_to_product_reference": "rhel-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-0:3.1.1-1.el8 as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8"
        },
        "product_reference": "linuxptp-0:3.1.1-1.el8",
        "relates_to_product_reference": "rhel-br-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-0:3.1.1-1.el8 as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z::appstream:linuxptp-0:3.1.1-1.el8"
        },
        "product_reference": "linuxptp-0:3.1.1-1.el8",
        "relates_to_product_reference": "rhel-8.10.z::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-0:3.1.1-1.el8.src as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8.src"
        },
        "product_reference": "linuxptp-0:3.1.1-1.el8.src",
        "relates_to_product_reference": "rhel-br-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debuginfo as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-br-8.5.0::appstream:linuxptp-debuginfo"
        },
        "product_reference": "linuxptp-debuginfo",
        "relates_to_product_reference": "rhel-br-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:linuxptp-debuginfo"
        },
        "product_reference": "linuxptp-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debuginfo as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z::appstream:linuxptp-debuginfo"
        },
        "product_reference": "linuxptp-debuginfo",
        "relates_to_product_reference": "rhel-8.10.z::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:linuxptp-debuginfo"
        },
        "product_reference": "linuxptp-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debuginfo as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-8.5.0::appstream:linuxptp-debuginfo"
        },
        "product_reference": "linuxptp-debuginfo",
        "relates_to_product_reference": "rhel-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debugsource as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8.10.z::appstream:linuxptp-debugsource"
        },
        "product_reference": "linuxptp-debugsource",
        "relates_to_product_reference": "rhel-8.10.z::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debugsource as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-8.5.0::appstream:linuxptp-debugsource"
        },
        "product_reference": "linuxptp-debugsource",
        "relates_to_product_reference": "rhel-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp-debugsource as a component of Red Hat Enterprise Linux 8.5",
          "product_id": "rhel-br-8.5.0::appstream:linuxptp-debugsource"
        },
        "product_reference": "linuxptp-debugsource",
        "relates_to_product_reference": "rhel-br-8.5.0::appstream"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp.src as a component of Red Hat Enterprise Linux 9.0",
          "product_id": "rhel-9.0:linuxptp.src"
        },
        "product_reference": "linuxptp.src",
        "relates_to_product_reference": "rhel-9.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:linuxptp.src"
        },
        "product_reference": "linuxptp.src",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:linuxptp.src"
        },
        "product_reference": "linuxptp.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linuxptp.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:linuxptp.src"
        },
        "product_reference": "linuxptp.src",
        "relates_to_product_reference": "rhel-7-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3571",
      "cwe": {
        "id": "CWE-119",
        "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer"
      },
      "discovery_date": "2021-05-25T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:linuxptp",
            "rhel-6-els.els:linuxptp-debuginfo",
            "rhel-6-els.els:linuxptp.src",
            "rhel-7-els.els:linuxptp-debuginfo",
            "rhel-8.10.z::appstream:linuxptp-debuginfo",
            "rhel-8.10.z::appstream:linuxptp-debugsource",
            "rhel-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-8.5.0::appstream:linuxptp-debugsource",
            "rhel-br-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-br-8.5.0::appstream:linuxptp-debugsource"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "This flaw has been rated as having a Moderate impact. The information leak is probably not very useful on its own as `ptp4l` doesn't handle any confidential data like passwords or private keys.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "rhel-8.10.z::appstream:linuxptp-0:3.1.1-1.el8",
          "rhel-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
          "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
          "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8.src"
        ],
        "known_affected": [
          "rhel-7-els.els:linuxptp",
          "rhel-7-els.els:linuxptp.src",
          "rhel-8:linuxptp",
          "rhel-8:linuxptp.src",
          "rhel-9.0:linuxptp",
          "rhel-9.0:linuxptp.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:linuxptp",
          "rhel-6-els.els:linuxptp-debuginfo",
          "rhel-6-els.els:linuxptp.src",
          "rhel-7-els.els:linuxptp-debuginfo",
          "rhel-8.10.z::appstream:linuxptp-debuginfo",
          "rhel-8.10.z::appstream:linuxptp-debugsource",
          "rhel-8.5.0::appstream:linuxptp-debuginfo",
          "rhel-8.5.0::appstream:linuxptp-debugsource",
          "rhel-br-8.5.0::appstream:linuxptp-debuginfo",
          "rhel-br-8.5.0::appstream:linuxptp-debugsource"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-3571"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3571"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3571"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "rhel-7-els.els:linuxptp",
            "rhel-7-els.els:linuxptp.src"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "rhel-8:linuxptp",
            "rhel-8:linuxptp.src",
            "rhel-9.0:linuxptp",
            "rhel-9.0:linuxptp.src"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2021-11-09T17:52:05+00:00",
          "details": "Apply advisory RHSA-2021:4321 as per vendors instructions.",
          "product_ids": [
            "rhel-8.10.z::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8.src"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:4321"
        },
        {
          "category": "workaround",
          "details": "Only attackers that can connect to the `ptp4l` service can exploit this vulnerability. If `ptp4l` is bound only to a private network interface, or is protected by firewall rules to block incoming PTP management messages, the attack surface is correspondingly limited. When using the UDP IPv4 or IPv6 network transport, the following tcpdump filter can be used to detect PTP management messages:\n\n```\n(port 319 or port 320) and udp[8]&0xf=0xd\n```",
          "product_ids": [
            "rhel-7-els.els:linuxptp",
            "rhel-7-els.els:linuxptp.src",
            "rhel-8:linuxptp",
            "rhel-8:linuxptp.src",
            "rhel-9.0:linuxptp",
            "rhel-9.0:linuxptp.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "baseScore": 7.1,
            "baseSeverity": "HIGH"
          },
          "products": [
            "rhel-6-els.els:linuxptp",
            "rhel-6-els.els:linuxptp-debuginfo",
            "rhel-6-els.els:linuxptp.src",
            "rhel-7-els.els:linuxptp",
            "rhel-7-els.els:linuxptp-debuginfo",
            "rhel-7-els.els:linuxptp.src",
            "rhel-8.10.z::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-8.10.z::appstream:linuxptp-debuginfo",
            "rhel-8.10.z::appstream:linuxptp-debugsource",
            "rhel-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-8.5.0::appstream:linuxptp-debugsource",
            "rhel-8:linuxptp",
            "rhel-8:linuxptp.src",
            "rhel-9.0:linuxptp",
            "rhel-9.0:linuxptp.src",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8.src",
            "rhel-br-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-br-8.5.0::appstream:linuxptp-debugsource"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhel-6-els.els:linuxptp",
            "rhel-6-els.els:linuxptp-debuginfo",
            "rhel-6-els.els:linuxptp.src",
            "rhel-7-els.els:linuxptp",
            "rhel-7-els.els:linuxptp-debuginfo",
            "rhel-7-els.els:linuxptp.src",
            "rhel-8.10.z::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-8.10.z::appstream:linuxptp-debuginfo",
            "rhel-8.10.z::appstream:linuxptp-debugsource",
            "rhel-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-8.5.0::appstream:linuxptp-debugsource",
            "rhel-8:linuxptp",
            "rhel-8:linuxptp.src",
            "rhel-9.0:linuxptp",
            "rhel-9.0:linuxptp.src",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8",
            "rhel-br-8.5.0::appstream:linuxptp-0:3.1.1-1.el8.src",
            "rhel-br-8.5.0::appstream:linuxptp-debuginfo",
            "rhel-br-8.5.0::appstream:linuxptp-debugsource"
          ]
        }
      ],
      "title": "wrong length of one-step follow-up in transparent clock"
    }
  ]
}