---
id: CVE-2021-41617
title: >-
  sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
  configurations are used, allows privilege escalation because supplemental
  groups are not initialized as expected
summary: >-
  sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
  configurations are used, allows privilege escalation because supplemental
  groups are not initialized as expected. Helper programs for
  AuthorizedKeysCommand and Authoriz…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: openbsd
product: openssh
affected:
  - 'openssh >= 6.2, < 8.8'
  - fedora = 33
  - fedora = 34
  - fedora = 35
  - active_iq_unified_manager
  - clustered_data_ontap
  - hci_management_node
  - ontap_select_deploy_administration_utility
  - solidfire
  - aff_a250_firmware
  - aff_500f_firmware
  - http_server = 12.2.1.2.0
  - http_server = 12.2.1.3.0
  - http_server = 12.2.1.4.0
  - zfs_storage_appliance_kit = 8.8
  - starwind_virtual_san = v8r13
patched:
  - openssh 8.8
published: '2021-09-26'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41617'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1190975'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20211014-0004/'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2023/dsa-5586'
    label: cve@mitre.org
  - url: 'https://www.openssh.com/security.html'
    label: cve@mitre.org
  - url: 'https://www.openssh.com/txt/release-8.8'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2021/09/26/1'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://www.starwindsoftware.com/security/sw-20220805-0001/'
    label: cve@mitre.org
  - url: 'https://www.tenable.com/plugins/nessus/154174'
    label: cve@mitre.org
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1190975'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211014-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5586'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssh.com/security.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssh.com/txt/release-8.8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2021/09/26/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.starwindsoftware.com/security/sw-20220805-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/plugins/nessus/154174'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-019113.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-082556.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.02545
epssPercentile: 0.8435
ingestedAt: '2026-07-14T12:36:47.650Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/AdnanApriliyansyahh/CVE-2021-41617'
  checkedAt: '2026-09-26T09:05:27.218Z'
exploitAvailable: true
---

## Overview

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

## Affected

- `openssh >= 6.2, < 8.8`
- `fedora = 33`
- `fedora = 34`
- `fedora = 35`
- `active_iq_unified_manager`
- `clustered_data_ontap`
- `hci_management_node`
- `ontap_select_deploy_administration_utility`
- `solidfire`
- `aff_a250_firmware`
- `aff_500f_firmware`
- `http_server = 12.2.1.2.0`
- `http_server = 12.2.1.3.0`
- `http_server = 12.2.1.4.0`
- `zfs_storage_appliance_kit = 8.8`
- `starwind_virtual_san = v8r13`

## Remediation

Upgrade past the affected range:

- `openssh 8.8`
