PT-2021-7870 · Openssh+10 · Openssh+10

Published

2021-09-26

·

Updated

2026-04-27

·

CVE-2021-41617

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSH versions 6.2 through 8.x before 8.8
Description The issue is related to the management of privileges in OpenSSH, allowing privilege escalation when certain non-default configurations are used. This occurs because supplemental groups are not initialized as expected, potentially granting access to confidential data, disrupting data integrity, and causing denial of service. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process if the configuration specifies running the command as a different user.
Recommendations For OpenSSH versions 6.2 through 8.x before 8.8, update to version 8.8 or later to resolve the issue. As a temporary workaround, consider disabling the use of AuthorizedKeysCommand and AuthorizedPrincipalsCommand until a patch is available. Restrict access to helper programs for these commands to minimize the risk of exploitation. Avoid using configurations that specify running these commands as a non-root user until the issue is resolved.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:2013
ALT-PU-2021-2910
ALT-PU-2023-4460
ALT-PU-2024-12010
ALT-PU-2024-12012
ALT-PU-2024-17672
ALT-PU-2024-7257
ALT-PU-2024-7261
ALT-PU-2024-7269
ALT-PU-2024-7315
ALT-PU-2024-7319
ALT-PU-2024-7508
ALT-PU-2024-7510
ALT-PU-2024-9513
BDU:2023-03837
CESA-2021_4782
CESA-2022_2013
CVE-2021-41617
DLA-3694-1
DSA-5586-1
MGASA-2021-0561
OESA-2021-1377
OPENSUSE-SU-2021:3950-1
OPENSUSE-SU-2021_3950-1
OPENSUSE-SU-2024:13842-1
RHSA-2021:4782
RHSA-2021_4782
RHSA-2022:2013
RHSA-2022_2013
RLSA-2022:2013
SUSE-SU-2021:14847-1
SUSE-SU-2021:14870-1
SUSE-SU-2021:3875-1
SUSE-SU-2021:3887-1
SUSE-SU-2021:3947-1
SUSE-SU-2021:3950-1
SUSE-SU-2021:3951-1
SUSE-SU-2021_14847-1
SUSE-SU-2021_14870-1
SUSE-SU-2021_3875-1
SUSE-SU-2021_3887-1
SUSE-SU-2021_3947-1
SUSE-SU-2021_3950-1
SUSE-SU-2021_3951-1
SUSE-SU-2022:0805-1
SUSE-SU-2022_0805-1
USN-5666-1
USN-6565-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Openssh
Red Hat
Rocky Linux
Suse
Ubuntu