Database/Control plane, storage & DevOps
linuxptp / ptp4l (transparent clock on little-endian): A crafted PTP packet against ptp4l running as a transparent
Impact
A crafted PTP packet against ptp4l running as a transparent clock on a little-endian machine — i.e. every x86 and ARM64 server in your cluster — produces a fault. Transparent-clock mode is exactly the configuration used when PTP is carried across switches inside the cluster, so the affected deployment is the mainstream one, not an edge case.
Who can reach it
Remote, unauthenticated — a crafted PTP message from anything that can reach the node's PTP port.
What to do
linuxptp package upgrade plus ptp4l restart. Same segmentation advice as the companion issue: PTP traffic should not be sourceable by tenant workloads.
References
Related entries
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserialization: Unsafe deserialization of dataCVE-2022-32521 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - Java deserializationHigh
- IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections fromCVE-2022-41737 · IBM Storage Scale Container Native Storage Access (namespace boundary)High
- SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outCVE-2025-6202 · SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12)High
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreCVE-2025-68313 · AMD Zen 5 RDSEED (16-bit and 32-bit variants)High
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorCVE-2026-14199 · Grafana Auth Proxy authentication (identity cache key built by concatenation)High
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsCVE-2026-16494 · GitLab EE (project update endpoint authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.