First published: Fri Mar 05 2021(Updated: )
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbsd Openssh | >=8.2<8.5 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Netapp Cloud Backup | ||
Netapp Hci Management Node | ||
Netapp Solidfire | ||
IBM Cloud Pak for Business Automation | ||
Netapp Hci Compute Node | ||
Netapp Hci Storage Node Firmware | ||
Netapp Hci Storage Node | ||
Oracle Communications Offline Mediation Controller | =12.0.0.3.0 | |
Oracle ZFS Storage Appliance | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-28041 is high with a CVSS score of 7.1.
CVE-2021-28041 affects OpenSSH versions before 8.5.
CVE-2021-28041 affects OpenBSD, Fedora 33, and Fedora 34.
No, Netapp HCI Compute Node and Netapp HCI Storage Node are not vulnerable to CVE-2021-28041.
The CWE for CVE-2021-28041 is CWE-415 (Double Free).