Improper Privilege Management in OpenSSH - CVE-2021-41617

 

Improper Privilege Management in OpenSSH - CVE-2021-41617

Published: November 23, 2021 / Updated: January 10, 2022


Vulnerability identifier: #VU58333
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41617
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management in sshd, when certain non-default configurations are used, because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. A local user can escalate privileges on the system.


Affected software

OpenSSH
Juniper Junos Space
Debian Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
IBM AIX
IBM i
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
IBM Integrated Analytics System
IBM QRadar Network Security
Migration Toolkit for Containers
Traffix SDC
HPE Moonshot 1500 Chassis Manager
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Management for Kubernetes
Security Event Manager (SEM)
Session Smart Router
IBM VIOS
IBM Security Guardium
openssh-server (Ubuntu package)
pam_ssh_agent_auth
openssh-openssl1
openssh-openssl1-helpers
openssh-askpass-gnome-debuginfo
openssh-debugsource
openssh-debuginfo
openssh-helpers
openssh-fips
openssh-askpass-gnome
openssh
openssh-helpers-debuginfo
openssh-server-sysvinit
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-askpass
openssh (Red Hat Package)
openssh-askpass-gnome-debugsource
openssh (Red Hat package)
openssh-client (Ubuntu package)
openssh-help
openssh-server-debuginfo
openssh-common-debuginfo
openssh-common
openssh-clients-debuginfo
openssh (Debian package)
QuTS hero
Cloud Pak for Security (CP4S)
Enterprise SONiC
QNAP QTS

How to mitigate CVE-2021-41617

Install updates from vendor's website.

OpenSSH - update to 8.8p1
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2, 1.7.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5
IBM QRadar Network Security - addressed in versions 5.4.0.16, 5.5.0.11
Security Event Manager (SEM) - update to 2024.2
openssh-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
QuTS hero - update to h5.1.8.2823 build 20240712
pam_ssh_agent_auth - addressed in versions 0.10.3-2.22, 0.10.3-7.13.0.1
pam_ssh_agent_auth - update to 0.10.3-9.14
Cloud Pak for Security (CP4S) - update to 1.10.5.0
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Enterprise SONiC - update to 4.2.1
Red Hat OpenShift Container Platform - update to 4.11.0
QNAP QTS - update to 5.1.8.2823 20240712
Session Smart Router - addressed in versions 5.4.7, 5.5.3
openssh-openssl1 - update to 6.6p1-19.12.1
openssh-openssl1-helpers - update to 6.6p1-19.12.1
openssh-askpass-gnome-debuginfo - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-debugsource - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-debuginfo - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-helpers - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-fips - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-askpass-gnome - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh - addressed in versions 6.6p1-36.26.1, 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-74.60.1, 7.2p2-78.13.1, 7.6p1-9.44.1, 7.9p1-6.28.1, 8.4p1-3.6.1
openssh - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-server-sysvinit - update to 7.4p1-22
openssh-server - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-ldap - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-keycat - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-clients - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-cavs - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh-askpass - addressed in versions 7.4p1-22, 8.0p1-13.0.1
openssh (Red Hat Package) - update to 7.4p1-22.el7_9
openssh-askpass-gnome-debugsource - addressed in versions 7.9p1-6.28.1, 8.4p1-3.6.1
openssh (Red Hat package) - update to 8.0p1-13.el8
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh-help - update to 8.2p1-14
openssh-ldap - update to 8.2p1-14
openssh-clients - update to 8.2p1-14
openssh-debuginfo - update to 8.2p1-14
openssh-askpass - update to 8.2p1-14
openssh-server - update to 8.2p1-14
openssh-debugsource - update to 8.2p1-14
openssh-cavs - update to 8.2p1-14
openssh - update to 8.2p1-14
openssh-keycat - update to 8.2p1-14
openssh-server-debuginfo - update to 8.4p1-3.6.1
openssh-server - update to 8.4p1-3.6.1
openssh-common-debuginfo - update to 8.4p1-3.6.1
openssh-common - update to 8.4p1-3.6.1
openssh-clients-debuginfo - update to 8.4p1-3.6.1
openssh-clients - update to 8.4p1-3.6.1
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
openssh - addressed in versions 8.4p1-8.fc33, 8.6p1-5.fc34, 8.7p1-2.fc35
Juniper Junos Space - update to 22.1R1

External References

Related Security Bulletins