cbcvebase.
CVE-2021-28041
published 2021-03-05

CVE-2021-28041: ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy…

high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianopenssh< openssh 1:8.4p1-5 (bookworm)openssh 1:8.4p1-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcopenssh-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcopenssh-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcopenssh-clients-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcopenssh-clients-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcopenssh-debuginfo-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcopenssh-debuginfo-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcopenssh-server-8.5p1-1.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcopenssh-server-8.5p1-1.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
openbsdopenssh>= 0 < 1:8.4p1-51:8.4p1-5
openbsdopenssh>= 0 < 1:8.4p1-51:8.4p1-5
openbsdopenssh>= 0 < 1:8.4p1-51:8.4p1-5
openbsdopenssh>= 0 < 1:8.4p1-51:8.4p1-5
openbsdopenssh>= 8.2 < 8.58.5
oraclecommunications_offline_mediation_controller
oraclezfs_storage_appliance
paloaltopan-os

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.1HIGH