High severity7.1NVD Advisory· Published Mar 5, 2021· Updated Jun 17, 2026
CVE-2021-28041
CVE-2021-28041
Description
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- OpenSSH/OpenSSHdescription
- osv-coords7 versionspkg:rpm/opensuse/openssh-askpass-gnome&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/openssh&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/openssh&distro=openSUSE%20Tumbleweedpkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
< 8.4p1-3.9.1+ 6 more
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 9.6p1-3.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
Patches
Vulnerability mechanics
References
9- github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568dbnvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2021/03/03/1nvdMailing ListPatchThird Party Advisory
- security.gentoo.org/glsa/202105-35nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20210416-0002/nvdThird Party Advisory
- www.openssh.com/security.htmlnvdNot ApplicableVendor Advisory
- www.openssh.com/txt/release-8.5nvdRelease NotesVendor Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQWGII3LQR4AOTPPFXGMTYE7UDEWIUKI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/nvd
News mentions
0No linked articles in our index yet.