
⚠️ OpenSSH Bug Enables Pre-Auth Crash and Data Leak https://securityonline.info/a-single-line-of-code-pre-auth-openssh-flaw-exposes-ubuntu-and-debian-servers/ A critical vulnerability (CVE-2026-3497) has been identified in OpenSSH’s GSSAPI Key Exchange patch used by several Linux distributions. A single coding mistake allows heap corruption and data exposure before authentication. The bug stems from using a non-terminating error function, letting execution reach unintended code paths. Attackers can trigger it with a crafted SSH packet, causing crashes, leaking memory, or corrupting the heap. Systems running Ubuntu or Debian OpenSSH with GSSAPIKeyExchange enabled should update immediately. #CyberSecurity #Linux #Vulnerability
Post summary
The post announces CVE‑2026‑3497, a pre‑auth OpenSSH GSSAPI Key Exchange bug that can cause heap corruption and memory leaks on Ubuntu/Debian servers, and urges affected users to update immediately.













