PT-2021-2469 · Openssh+6 · Openssh+6

Published

2021-02-17

·

Updated

2026-03-10

·

CVE-2021-28041

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 8.5
Description The issue is related to a double free in ssh-agent, which may be relevant in less-common scenarios such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host. This can potentially allow a remote attacker to cause a denial of service or execute arbitrary code. The problem is associated with the use of memory after it has been freed.
Recommendations For versions prior to 8.5, update to version 8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ssh-agent to minimize the risk of exploitation.

Fix

DoS

Use After Free

Double Free

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2021-01836
CVE-2021-28041
MGASA-2021-0261
OESA-2021-1466
OESA-2022-2083
OPENSUSE-SU-2021:4153-1
OPENSUSE-SU-2021_4153-1
OPENSUSE-SU-2024:13842-1
SUSE-SU-2021:4153-1
SUSE-SU-2021_4153-1
USN-4762-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openssh
Red Os
Suse
Ubuntu