7.1

CVE-2021-28041

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenbsdOpenssh Version >= 8.2 < 8.5
FedoraprojectFedora Version33
FedoraprojectFedora Version34
NetappCloud Backup Version-
NetappSolidfire Version-
NetappHci Compute Node Firmware Version-
   NetappHci Compute Node Version-
NetappHci Storage Node Firmware Version-
   NetappHci Storage Node Version-
OracleZfs Storage Appliance Version8.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.489
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.2 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:N/AC:H/Au:S/C:P/I:P/A:P
CWE-415 Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.