USN-6097-1: Linux PTP vulnerability
29 May 2023
Linux PTP could be made to crash, run arbitrary code, or expose sensitive information if it received specially crafted input.
Releases
Packages
- linuxptp - Precision Time Protocol (PTP, IEEE1588) implementation for Linux
Details
It was discovered that Linux PTP did not properly perform a length check
when forwarding a PTP message between ports. A remote attacker could
possibly use this issue to access sensitive information, execute
arbitrary code, or cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
-
linuxptp
-
1.6-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.