CVE-2026-3497Disclosure(canonical / debian_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch canonical debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908CWE-824

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • enterprise_linux
  • openssh
  • ubuntu_linux

Threat summary

  • Patch or workaround signal is available
  • 16 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 6 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-12); latest day: 1
  • 16 total mentions across 6 days

Affected systems

Products
debian_linuxenterprise_linuxopensshubuntu_linux

9 versions affected across 4 products

Deep dive

Activity timeline16 mentions / 6d
01234Mentions · 2026-03-12: 4Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-03-17: 4Mentions · 2026-03-18: 2Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-12: 3Patch / Workaround · 2026-03-13: 3Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-21: 103-1203-1303-1403-1703-1803-21
Signal classification3 categories
Disclosure
743.8%
General
637.5%
Patch
318.8%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-124
Disclosure2General1Patch1
2026-03-134
Disclosure1General1Patch2
2026-03-141
Disclosure1
2026-03-174
Disclosure2General2
2026-03-182
General2
2026-03-211
Disclosure1
Full discourse16 posts
  • Hunt.io@Huntio
    Disclosure

    ⚠️ OpenSSH Bug Enables Pre-Auth Crash and Data Leak https://securityonline.info/a-single-line-of-code-pre-auth-openssh-flaw-exposes-ubuntu-and-debian-servers/ A critical vulnerability (CVE-2026-3497) has been identified in OpenSSH’s GSSAPI Key Exchange patch used by several Linux distributions. A single coding mistake allows heap corruption and data exposure before authentication. The bug stems from using a non-terminating error function, letting execution reach unintended code paths. Attackers can trigger it with a crafted SSH packet, causing crashes, leaking memory, or corrupting the heap. Systems running Ubuntu or Debian OpenSSH with GSSAPIKeyExchange enabled should update immediately. #CyberSecurity #Linux #Vulnerability

    Post summary

    The post announces CVE‑2026‑3497, a pre‑auth OpenSSH GSSAPI Key Exchange bug that can cause heap corruption and memory leaks on Ubuntu/Debian servers, and urges affected users to update immediately.

    111135142.4K
    5.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A pre-auth flaw in OpenSSH's GSSAPI Key Exchange (CVE-2026-3497) exposes Ubuntu and Debian servers to heap corruption and data leaks. Patch now. #OpenSSH #LinuxSecurity #CyberSecurity #InfoSec #Vulnerability #Ubuntu #Debian #PatchAlert #HeapCorruption https://securityonline.info/a-single-line-of-code-pre-auth-openssh-flaw-exposes-ubuntu-and-debian-servers/ https://t.co/bYp4t3moFn

    Post summary

    The tweet announces a pre-auth OpenSSH flaw (CVE‑2026‑3497) that causes heap corruption and data leaks on Ubuntu/Debian servers, and urges users to apply the available patch.

    0811771.4K
    10.6K followersView on X
  • Fomalhaut Weisszwerg@FmtWeisszwerg
    General

    @shirouzu 現状ではサポート対象の Debian 全てが脆弱性の影響を受け、修正リリースもまだという状況ですね https://security-tracker.debian.org/tracker/CVE-2026-3497 Gitリポジトリを見ても修正コミットが見当たりません https://salsa.debian.org/ssh-team/openssh/-/commits/master?ref_type=heads

    Post summary

    The conversation notes that all supported Debian releases are affected by CVE‑2026‑3497 and that no fix commit or patch has been released yet.

    13131388
    661 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3497: OpenSSH GSSAPI Key Exchange patch issue https://www.openwall.com/lists/oss-security/2026/03/12/3 Many Linux distros carry this patch on top of OpenSSH. Affects servers with "GSSAPIKeyExchange yes". Triggered by single tiny crafted SSH packet, no authentication or credentials needed. Impact varies.

    Post summary

    CVE‑2026‑3497 exposes a vulnerability in OpenSSH’s GSSAPI key exchange that can be triggered by a single crafted SSH packet without authentication. Many Linux distributions have already applied the patch.

    010611.2K
    4.4K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical security bulletin for #Fedora 42: CVE-2026-3497 (OpenSSH). Uninitialized variables in gssapi-keyex create a vector for information disclosure and denial of service. Read more: 👉 https://tinyurl.com/3j4fwkuw #Security https://t.co/rVnuNK8j5w

    Post summary

    The tweet announces a critical security bulletin for Fedora 42 about CVE‑2026‑3497 in OpenSSH, giving technical details of the vulnerability but providing no PoC, exploit code, or patch information.

    00040161
    1.5K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 OpenSSHの脆弱性(Important: CVE-2026-3497) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260317/

    Post summary

    The blog update announces a newly disclosed OpenSSH vulnerability (CVE‑2026‑3497) but offers no further exploitation or technical details.

    01021179
    360 followersView on X
  • Shirouzu Hiroaki(白水啓章)@shirouzu
    General

    まだ Debian では CVE-2026-3497 への動きがなさそうかな? 手元では # sshd -T | grep gssapi で、gssapiauthentication no なのは確認済なので大丈夫とは思いつつ。 https://x.com/FmtWeisszwerg/status/2032352202858394054

    Post summary

    The user notes that Debian appears not yet patched for CVE‑2026‑3497 and that disabling GSSAPI authentication is considered a safe interim step.

    01100541
    2.7K followersView on X
  • Shirouzu Hiroaki(白水啓章)@shirouzu
    Patch

    @FmtWeisszwerg なるほど、ありがとうございます! 今も動きが無いっぽいですね…一方、Ubuntu は対策済みと。 https://ubuntu.com/security/CVE-2026-3497

    Post summary

    The tweet reports that CVE-2026-3497 has been patched by Ubuntu and that no active exploitation activity has been detected.

    01000128
    2.7K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Ubuntu issues USN-8090-2 for 20.04 LTS, patching 3 OpenSSH bugs including CVE-2026-3497 that may allow remote DoS or code execution in GSSAPI key exchange. Update now. #OpenSSH https://threatcluster.io/cluster/critical-openssh-vulnerabilities-discovered-affecting-ubuntu-bd84c8cf

    Post summary

    Ubuntu released USN-8090-2 for 20.04 LTS, patching three OpenSSH bugs including CVE‑2026‑3497 that could enable remote DoS or code execution; users are urged to update.

    1000043
    100 followersView on X
  • トミー@メモ@TommiyTw
    General

    #後で読む 用メモです→ OpenSSHのGSSAPI Key Exchange パッチに脆弱性(CVE-2026-3497) https://ift.tt/vqgpDHK

    Post summary

    The tweet simply notes that CVE-2026-3497 is a vulnerability in OpenSSH's GSSAPI Key Exchange patch, without detailing technical aspects, exploitation, or mitigation.

    0000031
    133 followersView on X
  • Paraxiom@ParaxiomAPI
    General

    CVE-2026-3497: OpenSSH GSSAPI flaw crashes SSH with one packet. Off by default, but the pattern is the problem — 25 years of C + distro patches = endless attack surface. qssh: ML-KEM-1024 + Falcon-512, pure Rust, no GSSAPI, no C. The vulnerable code path doesn't exist. http://paraxiom.org/qssh.html

    Post summary

    The post highlights that CVE‑2026‑3497 is an OpenSSH GSSAPI flaw causing a crash with a single packet, and introduces a Rust‐based ssh client (qssh) that omits the vulnerable code path.

    0000054
    5 followersView on X
  • IT関連サイト記事@itit7777
    Disclosure

    IT関連サイト記事が更新されました!記事はこちらから⇒ OpenSSHの脆弱性(Important: CVE-2026-3497) https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260317/

    Post summary

    An article announcing the discovery of a vulnerability in OpenSSH (CVE-2026-3497) was published, but the provided text offers no evidence of a PoC, exploit, or patch.

    0000053
    443 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    OpenSSHのGSSAPI Key Exchange パッチに脆弱性(CVE-2026-3497) https://rocket-boys.co.jp/security-measures-lab/openssh-gssapi-key-exchange-flaw-cve-2026-3497/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post simply links to an article about CVE-2026-3497, a vulnerability in OpenSSH’s GSSAPI key‑exchange patch, without providing additional technical, exploit, or mitigation details.

    00000127
    337 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @Huntio OpenSSH vulnerabilities hit different when you realize they're everywhere! CVE-2026-3497 affecting multiple. Pre-auth heap corruption = priority one patching time. https://vulntracker.io/cves/CVE-2026-3497

    Post summary

    The tweet announces a pre‑authentication heap corruption flaw in OpenSSH (CVE‑2026‑3497) and stresses the urgency of applying a patch.

    0000086
    423 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3497 Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions an… https://www.cve.org/CVERecord?id=CVE-2026-3497

    Post summary

    The post briefly notes that CVE-2026-3497 concerns OpenSSH GSSAPI with reference to Linux distribution patches, but offers no technical or exploit specifics.

    00000142
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3497 OpenSSH GSSAPI Vulnerability Leads to Potential Undefined Behavior in Linux Distributions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3497

    Post summary

    The post announces CVE-2026‑3497, a vulnerability in OpenSSH’s GSSAPI that can lead to undefined behavior on Linux distributions.

    0000038
    4.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux20.04--
OScanonicalubuntu_linux22.04--
OScanonicalubuntu_linux24.04--
Appcanonicalubuntu_linux25.10--
OSdebiandebian_linux11.0--
Appopenbsdopenssh---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more