High severity7.1NVD Advisory· Published Mar 5, 2021· Updated Jun 17, 2026
CVE-2021-28041
CVE-2021-28041
Description
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:hci_compute_node_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:hci_storage_node_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:zfs_storage_appliance:8.8:*:*:*:*:*:*:*
- osv-coords7 versionspkg:rpm/opensuse/openssh&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/openssh&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/openssh-askpass-gnome&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3
< 8.4p1-3.9.1+ 6 more
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 9.6p1-3.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
- (no CPE)range: < 8.4p1-3.9.1
Patches
Vulnerability mechanics
References
9- github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568dbnvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2021/03/03/1nvdMailing ListPatchThird Party Advisory
- security.gentoo.org/glsa/202105-35nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20210416-0002/nvdThird Party Advisory
- www.openssh.com/security.htmlnvdNot ApplicableVendor Advisory
- www.openssh.com/txt/release-8.5nvdRelease NotesVendor Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQWGII3LQR4AOTPPFXGMTYE7UDEWIUKI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/nvd
News mentions
0No linked articles in our index yet.