Back

MEDIUM

openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

Published Mar 12, 2026

Description

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.

Affected products

Remediation

Red Hat statement

IMPORTANT: This vulnerability affects the OpenSSH GSSAPI delta as implemented in Red Hat Enterprise Linux and OpenShift Container Platform. An unauthenticated attacker could send a specially crafted GSSAPI message during key exchange, leading to the use of uninitialized variables and potentially undefined behavior. The severity of the impact is dependent on compiler hardening configurations.

Red Hat mitigation

To mitigate this issue, disable GSSAPI key exchange in the OpenSSH server configuration. This prevents the server from processing GSSAPI messages, eliminating the vulnerability's attack surface. Edit `/etc/ssh/sshd_config` and add or modify the line: ``` GSSAPIKeyExchange no ``` After saving the changes, restart the `sshd` service for the mitigation to take effect. This action will prevent users from authenticating via GSSAPI. ``` # systemctl restart sshd ```

Weaknesses (2)

References (46)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Mar 12, 2026
Updated Sep 8, 2026
Reserved Mar 3, 2026
CISA Vulnrichment
Updated Mar 12, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Mar 12, 2026
ENISA EUVD
Assigner canonical
Published Mar 12, 2026
Updated Sep 8, 2026
Exploited since n/a
EUVD-2026-11684