Double Free in OpenSSH - CVE-2021-28041

 

Double Free in OpenSSH - CVE-2021-28041

Published: March 14, 2021


Vulnerability identifier: #VU51444
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28041
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in ssh-agent. A remote attacker can trick the victim to connect to a server, where the attacker has root privileges, pass specially crafted data to the ssh client, trigger a double free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

OpenSSH
Gentoo Linux
Arch Linux
SUSE MicroOS
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
openEuler
Ubuntu
Fedora
Security Event Manager (SEM)
pam_ssh_agent_auth
openssh-client (Ubuntu package)
openssh-helpers
openssh
openssh-clients
openssh-clients-debuginfo
openssh-helpers-debuginfo
openssh-common
openssh-askpass-gnome-debugsource
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome
openssh-server-debuginfo
openssh-server
openssh-fips
openssh-debugsource
openssh-debuginfo
openssh-common-debuginfo
kde-settings
RecoverPoint for VMs

How to mitigate CVE-2021-28041

Install updates from vendor's website.

OpenSSH - update to 8.5p1
Security Event Manager (SEM) - update to 2024.2
pam_ssh_agent_auth - addressed in versions 0.10.3-9.14, 0.10.3-9.15, 0.10.3-9.16
RecoverPoint for VMs - update to 6.0.SP1.P1
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.2, 1:8.3p1-1ubuntu0.1
openssh-helpers - update to 8.4p1-3.9.1
openssh - update to 8.4p1-3.9.1
openssh-clients - update to 8.4p1-3.9.1
openssh-clients-debuginfo - update to 8.4p1-3.9.1
openssh-helpers-debuginfo - update to 8.4p1-3.9.1
openssh-common - update to 8.4p1-3.9.1
openssh-askpass-gnome-debugsource - update to 8.4p1-3.9.1
openssh-askpass-gnome-debuginfo - update to 8.4p1-3.9.1
openssh-askpass-gnome - update to 8.4p1-3.9.1
openssh-server-debuginfo - update to 8.4p1-3.9.1
openssh-server - update to 8.4p1-3.9.1
openssh-fips - update to 8.4p1-3.9.1
openssh-debugsource - update to 8.4p1-3.9.1
openssh-debuginfo - update to 8.4p1-3.9.1
openssh-common-debuginfo - update to 8.4p1-3.9.1
openssh - addressed in versions 8.4p1-7.fc33, 8.5p1-2.fc34
kde-settings - update to 34.0-9.fc34

External References

Related Security Bulletins