CVE-2021-28041

Source
https://cve.org/CVERecord?id=CVE-2021-28041
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28041.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-28041
Downstream
Related
Published
2021-03-05T21:15:13.200Z
Modified
2026-03-03T01:16:44.812574Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

References

Affected packages

Git / github.com/openssh/openssh-portable

Affected ranges

Type
GIT
Repo
https://github.com/openssh/openssh-portable
Events

Affected versions

Other
V_8_2_P1
V_8_4_P1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28041.json"