An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
There seems to be an agreement on the linuxptp mailing list that this CVE is bogus: https://lists.nwtime.org/sympa/arc/linuxptp-devel/2024-09/msg00080.html