First published: Fri Mar 05 2021(Updated: )
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | >=8.2<8.5 | |
Red Hat Fedora | =33 | |
Red Hat Fedora | =34 | |
NetApp Cloud Backup | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node | ||
NetApp HCI Storage Nodes | ||
NetApp HCI Storage Nodes | ||
Oracle Communications Offline Mediation Controller | =12.0.0.3.0 | |
Oracle Sun ZFS Storage Appliance Kit | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-28041 is high with a CVSS score of 7.1.
CVE-2021-28041 affects OpenSSH versions before 8.5.
CVE-2021-28041 affects OpenBSD, Fedora 33, and Fedora 34.
No, Netapp HCI Compute Node and Netapp HCI Storage Node are not vulnerable to CVE-2021-28041.
The CWE for CVE-2021-28041 is CWE-415 (Double Free).