Junglewise Threat Intelligence

CVE-2021-41617: OpenSSH privilege escalation in AuthorizedKeysCommand helper programs

CVE-2021-41617 · Severity: high · CVSS 7 · Published 2021-09-26

Technologies: SUSE Linux Enterprise Server, OpenBSD Openssh. Vendors: Suse, Debian, OpenBSD.

Executive brief

OpenSSH is a widely used tool for secure remote access to servers. A vulnerability in the server component (sshd) could allow a local user to gain higher-level system privileges under specific configurations. This occurs when the server is set up to use external helper programs to verify user keys or identities, potentially allowing those programs to run with more authority than intended.

Technical details

A privilege escalation vulnerability exists in OpenSSH's sshd process between versions 6.2 and 8.8. When the 'AuthorizedKeysCommand' or 'AuthorizedPrincipalsCommand' directives are used with a 'User' specified (e.g., AuthorizedKeysCommandUser), the process fails to properly initialize supplemental groups. Instead of running with only the intended user's groups, the helper programs inherit the supplemental groups of the parent sshd process (typically root). A local attacker with low privileges could exploit this to execute commands with elevated group permissions. This requires a non-default configuration where these specific commands are enabled. The issue is resolved in OpenSSH 8.8.

Affected products

  • OpenBSD OpenSSH 6.2 through 8.x before 8.8
  • SUSE SUSE Linux Enterprise Server 11, 12, 15
  • Fedora Project Fedora 34
  • Debian Debian GNU/Linux 10 (buster)

Timeline

  • 2021-09-26: disclosed: Initial disclosure and OpenSSH 8.8 release notes published.
  • 2021-09-26: patched: Fixed in OpenSSH 8.8.
  • 2021-09-26: advisory: NVD publication date.

References

Related threats