CVE-2021-28041
published 2021-03-05CVE-2021-28041: ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy…
PriorityP338high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
EPSS
3.42%
87.6th percentile
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssh | < openssh 1:8.4p1-5 (bookworm) | openssh 1:8.4p1-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | openssh-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | openssh-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | openssh-clients-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | openssh-clients-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | openssh-debuginfo-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | openssh-debuginfo-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | openssh-server-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | openssh-server-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| openbsd | openssh | >= 0 < 1:8.4p1-5 | 1:8.4p1-5 |
| openbsd | openssh | >= 0 < 1:8.4p1-5 | 1:8.4p1-5 |
| openbsd | openssh | >= 0 < 1:8.4p1-5 | 1:8.4p1-5 |
| openbsd | openssh | >= 0 < 1:8.4p1-5 | 1:8.4p1-5 |
| openbsd | openssh | >= 8.2 < 8.5 | 8.5 |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | zfs_storage_appliance | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp5m-rxrx-pfrj: ssh-agent in OpenSSH before 8
ghsa_unreviewed·2022-05-24
CVE-2021-28041 [CRITICAL] CWE-415 GHSA-gp5m-rxrx-pfrj: ssh-agent in OpenSSH before 8
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
OSV
CVE-2021-28041: ssh-agent in OpenSSH before 8
osv·2021-03-05·CVSS 7.1
CVE-2021-28041 [HIGH] CVE-2021-28041: ssh-agent in OpenSSH before 8
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Palo Alto
PAN-OS: Informational: Impact of the OpenSSH vulnerability CVE-2021-28041
vendor_paloalto·2021-03-24·CVSS 7.1
CVE-2021-28041 [HIGH] PAN-OS: Informational: Impact of the OpenSSH vulnerability CVE-2021-28041
PAN-OS: Informational: Impact of the OpenSSH vulnerability CVE-2021-28041
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSH software CVE-2021-28041 vulnerability.
PAN-OS software does not utilize the ssh-agent component or provide access to the agent socket related to this vulnerability. There are no scenarios that enable successful exploitation of the vulnerability in PAN-OS software.
Affected products: PAN-OS
Solution: No product updates are required for this vulnerability.
Ubuntu
OpenSSH vulnerability
vendor_ubuntu·2021-03-10
CVE-2021-28041 OpenSSH vulnerability
Title: OpenSSH vulnerability
Summary: OpenSSH could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that the OpenSSH ssh-agent incorrectly handled memory. A
remote attacker able to connect to the agent could use this issue to cause
it to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios such as unconstrained agent-socket access on a legacy operating system or the forwarding of an age
vendor_msrc·2021-03-09·CVSS 7.1
CVE-2021-28041 [HIGH] CWE-415 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios such as unconstrained agent-socket access on a legacy operating system or the forwarding of an age
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios such as unconstrained agent-socket access on a legacy operating system or the forwarding of an agent to an attacker-controlled host.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products
Red Hat
openssh: double-free memory corruption may lead to arbitrary code execution
vendor_redhat·2021-03-03·CVSS 7.1
CVE-2021-28041 [HIGH] CWE-416 openssh: double-free memory corruption may lead to arbitrary code execution
openssh: double-free memory corruption may lead to arbitrary code execution
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
A double-free memory corruption flaw was found in OpenSSH 8.2, more specifically in ssh-agent application. This flaw allows an attacker with access to the agent socket to forward an agent either to an account shared with a malicious user or to a host with an attacker holding root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Statement: This issue doesn't affected any versions of OpenSSH packaged and shipped wi
Debian
CVE-2021-28041: openssh - ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few ...
vendor_debian·2021·CVSS 7.1
CVE-2021-28041 [HIGH] CVE-2021-28041: openssh - ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few ...
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Scope: local
bookworm: resolved (fixed in 1:8.4p1-5)
bullseye: resolved (fixed in 1:8.4p1-5)
forky: resolved (fixed in 1:8.4p1-5)
sid: resolved (fixed in 1:8.4p1-5)
trixie: resolved (fixed in 1:8.4p1-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568dbhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQWGII3LQR4AOTPPFXGMTYE7UDEWIUKI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/https://security.gentoo.org/glsa/202105-35https://security.netapp.com/advisory/ntap-20210416-0002/https://www.openssh.com/security.htmlhttps://www.openssh.com/txt/release-8.5https://www.openwall.com/lists/oss-security/2021/03/03/1https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568dbhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQWGII3LQR4AOTPPFXGMTYE7UDEWIUKI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/https://security.gentoo.org/glsa/202105-35https://security.netapp.com/advisory/ntap-20210416-0002/https://www.openssh.com/security.htmlhttps://www.openssh.com/txt/release-8.5https://www.openwall.com/lists/oss-security/2021/03/03/1https://www.oracle.com//security-alerts/cpujul2021.html
2021-03-05
Published