Description
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Published: 2026-03-12
Score: 2.7 Low
EPSS: 2.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from uninitialized variables used during the GSSAPI key exchange in the OpenSSH server. When an attacker sends an unexpected GSSAPI message type, the server uses sshpkt_disconnect() which does not terminate the connection. This allows the code to use related connection variables that were never set to NULL, leading to random memory access and undefined behavior. The impact can include accidental disclosure of memory contents or a denial of service if the undefined behavior crashes the process. The weakness corresponds to CWE-824 and CWE-908.

Affected Systems

Affected systems are Ubuntu distributions that include the patched OpenSSH GSSAPI implementation. The issue is limited to OpenSSH packages customized by Ubuntu; the upstream OpenSSH project is not affected. No specific affected version numbers are enumerated in the available data, so any Ubuntu OpenSSH release that includes the distribution's GSSAPI patch is potentially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 2.7 and an EPSS score of 2%, and it is not listed as a Known Exploited Vulnerability. Exploitation requires network access to an SSH server and the ability to send crafted GSSAPI messages. It may expose sensitive data or cause a service disruption, especially on systems with weaker compiler hardening. The recommended mitigation is to update to an Ubuntu OpenSSH package that contains the patch or to apply an alternative code change that forces proper process termination on error.

Generated by OpenCVE AI on June 18, 2026 at 10:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ubuntu OpenSSH package that includes the GSSAPI patch.
  • If an update is not yet available, modify the OpenSSH source to replace sshpkt_disconnect() with ssh_packet_disconnect() to ensure termination of the connection on error.
  • Rebuild the package ensuring compiler hardening flags such as -fstack-protector are enabled to reduce the chance of undefined behavior.
  • Verify that GSSAPI is disabled or restricted in sshd_config when not required, and monitor SSH logs for unexpected disconnect or GSSAPI errors.

Generated by OpenCVE AI on June 18, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4535-1 openssh security update
Debian DSA Debian DSA DSA-6204-1 openssh security update
Ubuntu USN Ubuntu USN USN-8090-1 OpenSSH vulnerabilities
Ubuntu USN Ubuntu USN USN-8090-2 OpenSSH vulnerabilities
References
Link Providers
http://www.openwall.com/lists/oss-security/2026/03/12/3 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/14/3 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/14/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/2 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/5 cve-icon
http://www.openwall.com/lists/oss-security/2026/03/18/7 cve-icon
https://access.redhat.com/errata/RHSA-2026:10065 cve-icon
https://access.redhat.com/errata/RHSA-2026:10714 cve-icon
https://access.redhat.com/errata/RHSA-2026:12071 cve-icon
https://access.redhat.com/errata/RHSA-2026:13750 cve-icon
https://access.redhat.com/errata/RHSA-2026:13812 cve-icon
https://access.redhat.com/errata/RHSA-2026:14773 cve-icon
https://access.redhat.com/errata/RHSA-2026:14924 cve-icon
https://access.redhat.com/errata/RHSA-2026:15087 cve-icon
https://access.redhat.com/errata/RHSA-2026:15891 cve-icon
https://access.redhat.com/errata/RHSA-2026:15893 cve-icon
https://access.redhat.com/errata/RHSA-2026:16008 cve-icon
https://access.redhat.com/errata/RHSA-2026:16009 cve-icon
https://access.redhat.com/errata/RHSA-2026:16030 cve-icon
https://access.redhat.com/errata/RHSA-2026:16174 cve-icon
https://access.redhat.com/errata/RHSA-2026:17596 cve-icon
https://access.redhat.com/errata/RHSA-2026:19724 cve-icon
https://access.redhat.com/errata/RHSA-2026:19725 cve-icon
https://access.redhat.com/errata/RHSA-2026:20040 cve-icon
https://access.redhat.com/errata/RHSA-2026:20087 cve-icon
https://access.redhat.com/errata/RHSA-2026:21690 cve-icon
https://access.redhat.com/errata/RHSA-2026:21695 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:5475 cve-icon
https://access.redhat.com/errata/RHSA-2026:6461 cve-icon
https://access.redhat.com/errata/RHSA-2026:6462 cve-icon
https://access.redhat.com/errata/RHSA-2026:6463 cve-icon
https://access.redhat.com/errata/RHSA-2026:7107 cve-icon
https://access.redhat.com/errata/RHSA-2026:9415 cve-icon
https://access.redhat.com/errata/RHSA-2026:9732 cve-icon
https://access.redhat.com/security/cve/CVE-2026-3497 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2447085 cve-icon
https://cert-portal.siemens.com/productcert/html/ssa-019113.html cve-icon
https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-3497 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.json cve-icon
https://ubuntu.com/security/CVE-2026-3497 cve-icon cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-3497 cve-icon
https://www.openwall.com/lists/oss-security/2026/03/12/3 cve-icon cve-icon cve-icon
History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical ubuntu Linux
Debian
Debian debian Linux
Openbsd
Openbsd openssh
Redhat
Redhat enterprise Linux
CPEs cpe:2.3:a:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Canonical
Canonical ubuntu Linux
Debian
Debian debian Linux
Openbsd
Openbsd openssh
Redhat
Redhat enterprise Linux
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 16 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Mar 2026 14:30:00 +0000


Fri, 13 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Important


Fri, 13 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ubuntu
Ubuntu openssh
Vendors & Products Ubuntu
Ubuntu openssh

Thu, 12 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
References

Thu, 12 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
References

Thu, 12 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Weaknesses CWE-908
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Openbsd Openssh
Redhat Enterprise Linux
Ubuntu Openssh
cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-08-21T12:12:58.488Z

Reserved: 2026-03-03T19:33:05.664Z

Link: CVE-2026-3497

cve-icon Vulnrichment

Updated: 2026-04-16T18:24:30.556Z

cve-icon NVD

Status : Modified

Published: 2026-03-12T19:16:19.910

Modified: 2026-07-15T02:21:00.033

Link: CVE-2026-3497

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-12T18:27:44Z

Links: CVE-2026-3497 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T10:30:05Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer

  • CWE-908

    Use of Uninitialized Resource