CVE-2026-3497Use of Uninitialized Resource in Openssh

Severity
6.9MEDIUMNVD
OSV3.6
EPSS
0.0%
top 89.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program with

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5ubuntu/openssh1:10.0p1-5ubuntu51:10.0p1-5ubuntu5.1+2
Debianopenbsd/openssh< 1:9.2p1-2+deb12u9+2
Ubuntuopenbsd/openssh< 1:8.9p1-3ubuntu0.14+3

🔴Vulnerability Details

5
OSV
openssh vulnerabilities2026-03-12
GHSA
GHSA-wcpp-3x59-h8vp: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions2026-03-12
OSV
CVE-2026-3497: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions2026-03-12
OSV
openssh vulnerabilities2026-03-12
CVEList
CVE-2026-3497: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions2026-03-12

📋Vendor Advisories

4
Red Hat
openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables2026-03-12
Ubuntu
OpenSSH vulnerabilities2026-03-12
Ubuntu
OpenSSH vulnerabilities2026-03-12
Debian
CVE-2026-3497: openssh - Vulnerability in the OpenSSH GSSAPI delta included in various Linux distribution...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-3497 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-3497 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables2026-03-12
CVE-2026-3497 — Use of Uninitialized Resource | cvebase