7.1

CVE-2021-28041

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbsd ≫ Openssh Version >= 8.2 < 8.5
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Netapp ≫ Cloud Backup Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Hci Compute Node Firmware Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ Hci Storage Node Firmware Version -
   Netapp ≫ Hci Storage Node Version -
Oracle ≫ Zfs Storage Appliance Version 8.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.42% 0.874
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.2 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:N/AC:H/Au:S/C:P/I:P/A:P
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory
https://security.gentoo.org/glsa/202105-35
Third Party Advisory
https://www.openssh.com/security.html
Vendor Advisory
Not Applicable
https://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568db
Patch
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQWGII3LQR4AOTPPFXGMTYE7UDEWIUKI/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXST2CML2MWY3PNVUXX7FFJE3ATJMNVZ/
https://security.netapp.com/advisory/ntap-20210416-0002/
Third Party Advisory
https://www.openssh.com/txt/release-8.5
Vendor Advisory
Release Notes
https://www.openwall.com/lists/oss-security/2021/03/03/1
Patch
Third Party Advisory
Mailing List