Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Openbsd Subscribe
Openssh Subscribe
Enterprise Linux Subscribe
Openssh Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4535-1 openssh security update
Debian DSA Debian DSA DSA-6204-1 openssh security update
Ubuntu USN Ubuntu USN USN-8090-1 OpenSSH vulnerabilities
Ubuntu USN Ubuntu USN USN-8090-2 OpenSSH vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://www.openwall.com/lists/oss-security/2026/03/12/3 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/14/3 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/14/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/2 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/5 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/7 cve-icon
https://access.redhat.com/errata/RHSA-2026:10065 cve-icon
https://access.redhat.com/errata/RHSA-2026:10714 cve-icon
https://access.redhat.com/errata/RHSA-2026:12071 cve-icon
https://access.redhat.com/errata/RHSA-2026:13750 cve-icon
https://access.redhat.com/errata/RHSA-2026:13812 cve-icon
https://access.redhat.com/errata/RHSA-2026:14773 cve-icon
https://access.redhat.com/errata/RHSA-2026:14924 cve-icon
https://access.redhat.com/errata/RHSA-2026:15087 cve-icon
https://access.redhat.com/errata/RHSA-2026:15891 cve-icon
https://access.redhat.com/errata/RHSA-2026:15893 cve-icon
https://access.redhat.com/errata/RHSA-2026:16008 cve-icon
https://access.redhat.com/errata/RHSA-2026:16009 cve-icon
https://access.redhat.com/errata/RHSA-2026:16030 cve-icon
https://access.redhat.com/errata/RHSA-2026:16174 cve-icon
https://access.redhat.com/errata/RHSA-2026:17596 cve-icon
https://access.redhat.com/errata/RHSA-2026:19724 cve-icon
https://access.redhat.com/errata/RHSA-2026:19725 cve-icon
https://access.redhat.com/errata/RHSA-2026:20040 cve-icon
https://access.redhat.com/errata/RHSA-2026:20087 cve-icon
https://access.redhat.com/errata/RHSA-2026:21690 cve-icon
https://access.redhat.com/errata/RHSA-2026:21695 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:5475 cve-icon
https://access.redhat.com/errata/RHSA-2026:6461 cve-icon
https://access.redhat.com/errata/RHSA-2026:6462 cve-icon
https://access.redhat.com/errata/RHSA-2026:6463 cve-icon
https://access.redhat.com/errata/RHSA-2026:7107 cve-icon
https://access.redhat.com/errata/RHSA-2026:9415 cve-icon
https://access.redhat.com/errata/RHSA-2026:9732 cve-icon
https://access.redhat.com/security/cve/CVE-2026-3497 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2447085 cve-icon
https://cert-portal.siemens.com/productcert/html/ssa-019113.html cve-icon
https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-3497 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.json cve-icon
https://ubuntu.com/security/CVE-2026-3497 cve-icon cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-3497 cve-icon
https://www.openwall.com/lists/oss-security/2026/03/12/3 cve-icon cve-icon cve-icon
History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical ubuntu Linux
Debian
Debian debian Linux
Openbsd
Openbsd openssh
Redhat
Redhat enterprise Linux
CPEs cpe:2.3:a:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Canonical
Canonical ubuntu Linux
Debian
Debian debian Linux
Openbsd
Openbsd openssh
Redhat
Redhat enterprise Linux
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 16 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Mar 2026 14:30:00 +0000


Fri, 13 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Important


Fri, 13 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ubuntu
Ubuntu openssh
Vendors & Products Ubuntu
Ubuntu openssh

Thu, 12 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
References

Thu, 12 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
References

Thu, 12 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Weaknesses CWE-908
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-07-15T01:03:33.787Z

Reserved: 2026-03-03T19:33:05.664Z

Link: CVE-2026-3497

cve-icon Vulnrichment

Updated: 2026-04-16T18:24:30.556Z

cve-icon NVD

Status : Modified

Published: 2026-03-12T19:16:19.910

Modified: 2026-07-15T02:21:00.033

Link: CVE-2026-3497

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-12T18:27:44Z

Links: CVE-2026-3497 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T10:30:05Z

Weaknesses