Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
References
| Link | Resource |
|---|---|
| https://ubuntu.com/security/CVE-2026-3497 | Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2026/03/12/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/12/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/14/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/14/4 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/2 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/4 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/5 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/7 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Jun 2026, 19:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openbsd
Openbsd openssh Debian debian Linux Redhat Debian Canonical ubuntu Linux Redhat enterprise Linux Canonical |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
|
| References | () https://ubuntu.com/security/CVE-2026-3497 - Third Party Advisory | |
| References | () https://www.openwall.com/lists/oss-security/2026/03/12/3 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/12/3 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/14/3 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/14/4 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/18/2 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/18/4 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/18/5 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/18/7 - Mailing List, Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html - Mailing List, Third Party Advisory |
16 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Mar 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Mar 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
12 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-12 19:16
Updated : 2026-06-02 19:43
NVD link : CVE-2026-3497
Mitre link : CVE-2026-3497
CVE.ORG link : CVE-2026-3497
JSON object : View
Products Affected
openbsd
- openssh
debian
- debian_linux
canonical
- ubuntu_linux
redhat
- enterprise_linux
CWE
CWE-908
Use of Uninitialized Resource
