CVE-2021-28041
HIGHssh-agent <8.5 - Use After Free
Title source: llmDescription
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Scores
CVSS v3
7.1
EPSS
0.0024
EPSS Percentile
46.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (10)
fedoraproject/fedora
openbsd/openssh
< 8.5
fedoraproject/fedora
netapp/cloud_backup
netapp/hci_management_node
netapp/solidfire
netapp/hci_compute_node_firmware
netapp/hci_storage_node_firmware
oracle/communications_offline_mediation_controller
oracle/zfs_storage_appliance
Timeline
Published
Mar 05, 2021
Tracked Since
Feb 18, 2026