LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-3497

canonical · ubuntu linux

Published
CVSS7.5
Severityhigh
WeaknessCWE-908
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined

References

← Back to the CVE Tracker

Our coverage of CVE-2026-3497

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-3497.