CVE-2026-3497

MEDIUM EPSS 77.8%
Published Mar 12, 20263mo ago · Modified Jun 17, 20261w ago
6.9 CVSS 4.0
Medium
Find Similar
Published Mar 12, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.

CVSS Details

Base Score
6.9
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
77.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-908

Affected Products 9

VendorProductVersionRange
canonicalubuntu_linux25.10any
openbsdopenssh*any
canonicalubuntu_linux20.04any
canonicalubuntu_linux22.04any
canonicalubuntu_linux24.04any
debiandebian_linux11.0any
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any
redhatenterprise_linux10.0any

References 10

  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/12/3
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/14/3
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/14/4
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/18/2
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/18/4
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/18/5
    Mailing ListThird Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/18/7
    Mailing ListThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html
    Mailing ListThird Party Advisory
  • ubuntu.com https://ubuntu.com/security/CVE-2026-3497
    Third Party Advisory
  • openwall.com https://www.openwall.com/lists/oss-security/2026/03/12/3
    Mailing ListThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.