openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables
Published Mar 12, 2026
6.9
MEDIUMCVSS 4.0
EPSS 1.25%
Description
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Affected products
-
- Version 1:10.0p1-5ubuntu5StatusaffectedConstraints<1:10.0p1-5ubuntu5.1
- Version 1:8.9p1-3StatusaffectedConstraints<1:8.9p1-3ubuntu0.14
- Version 1:9.6p1-3ubuntu13StatusaffectedConstraints<1:9.6p1-3ubuntu13.15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- 25.10
- n/a
- 20.04
- 22.04
- 24.04
- 11.0
- 8.0
- 9.0
- 10.0
No data.
RHEL-8 based Middleware Containers
rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680
Fixed · RHSA-2026:13812
RHEL-8 based Middleware Containers
rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708
Fixed · RHSA-2026:13812
Red Hat AI Inference Server 3.2
rhaiis/model-opt-cuda-rhel9:1780681984
Fixed · RHSA-2026:25096
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:1779223654
Fixed · RHSA-2026:19724
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:1779223651
Fixed · RHSA-2026:19725
Red Hat AI Inference Server 3.3
rhaiis/model-opt-cuda-rhel9:1778244559
Fixed · RHSA-2026:16008
Red Hat AI Inference Server 3.3
rhaiis/vllm-cuda-rhel9:1778274666
Fixed · RHSA-2026:16030
Red Hat AI Inference Server 3.3
rhaiis/vllm-rocm-rhel9:1778244531
Fixed · RHSA-2026:16009
Red Hat AI Inference Server 3.3
rhaiis/vllm-spyre-rhel9:1778244546
Fixed · RHSA-2026:16174
Red Hat Enterprise Linux 10
openssh-0:9.9p1-13.el10_1
Fixed · RHSA-2026:6463
Red Hat Enterprise Linux 10.0 Extended Update Support
openssh-0:9.9p1-7.el10_0.2
Fixed · RHSA-2026:7107
Red Hat Enterprise Linux 8
openssh-0:8.0p1-28.el8_10
Fixed · RHSA-2026:6461
Red Hat Enterprise Linux 8
openssh-0:8.0p1-28.el8_10
Fixed · RHSA-2026:6461
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
openssh-0:8.0p1-7.el8_4.1
Fixed · RHSA-2026:15891
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
openssh-0:8.0p1-7.el8_4.1
Fixed · RHSA-2026:15891
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
openssh-0:8.0p1-15.el8_6.4
Fixed · RHSA-2026:15893
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
openssh-0:8.0p1-15.el8_6.4
Fixed · RHSA-2026:15893
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
openssh-0:8.0p1-15.el8_6.4
Fixed · RHSA-2026:15893
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
openssh-0:8.0p1-20.el8_8.3
Fixed · RHSA-2026:14924
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
openssh-0:8.0p1-20.el8_8.3
Fixed · RHSA-2026:14924
Red Hat Enterprise Linux 9
openssh-0:8.7p1-48.el9_7
Fixed · RHSA-2026:6462
Red Hat Enterprise Linux 9
openssh-0:8.7p1-48.el9_7
Fixed · RHSA-2026:6462
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
openssh-0:8.7p1-13.el9_0.2
Fixed · RHSA-2026:13750
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
openssh-0:8.7p1-30.el9_2.10
Fixed · RHSA-2026:10714
Red Hat Enterprise Linux 9.4 Extended Update Support
openssh-0:8.7p1-38.el9_4.7
Fixed · RHSA-2026:9732
Red Hat Enterprise Linux 9.6 Extended Update Support
openssh-0:8.7p1-45.el9_6.2
Fixed · RHSA-2026:9415
Red Hat Hardened Images
openssh-main-10.2p1-9.hum1
Fixed · RHSA-2026:5475
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202605271418-0
Fixed · RHSA-2026:21695
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202605271328-0
Fixed · RHSA-2026:21690
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202605060243-0
Fixed · RHSA-2026:15087
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202605060220-0
Fixed · RHSA-2026:14773
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202605200242-0
Fixed · RHSA-2026:20087
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202605112123-0
Fixed · RHSA-2026:17596
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202604240015-0
Fixed · RHSA-2026:12071
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202605201155-0
Fixed · RHSA-2026:20040
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1776868772
Fixed · RHSA-2026:10065
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1776868842
Fixed · RHSA-2026:10065
Multicluster Engine for Kubernetes
multicluster-engine/hive-rhel9
Under investigation
OpenShift Pipelines
openshift-pipelines/pipelines-resolvers-rhel9
Under investigation
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/multicluster-operators-subscription-rhel9
Under investigation
Red Hat Enterprise Linux 6
openssh
Not affected
Red Hat Enterprise Linux 7
openssh
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1777325677 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1777325711 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-controller-rhel8:7.13.5-4.1777325710 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1777325680 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1777325709 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1777325680 | Fixed | RHSA-2026:13812 |
| RHEL-8 based Middleware Containers | rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1777325708 | Fixed | RHSA-2026:13812 |
| Red Hat AI Inference Server 3.2 | rhaiis/model-opt-cuda-rhel9:1780681984 | Fixed | RHSA-2026:25096 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:1779223654 | Fixed | RHSA-2026:19724 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:1779223651 | Fixed | RHSA-2026:19725 |
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1778244559 | Fixed | RHSA-2026:16008 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-cuda-rhel9:1778274666 | Fixed | RHSA-2026:16030 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1778244531 | Fixed | RHSA-2026:16009 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-spyre-rhel9:1778244546 | Fixed | RHSA-2026:16174 |
| Red Hat Enterprise Linux 10 | openssh-0:9.9p1-13.el10_1 | Fixed | RHSA-2026:6463 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | openssh-0:9.9p1-7.el10_0.2 | Fixed | RHSA-2026:7107 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-28.el8_10 | Fixed | RHSA-2026:6461 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-28.el8_10 | Fixed | RHSA-2026:6461 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | openssh-0:8.0p1-7.el8_4.1 | Fixed | RHSA-2026:15891 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | openssh-0:8.0p1-7.el8_4.1 | Fixed | RHSA-2026:15891 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | openssh-0:8.0p1-15.el8_6.4 | Fixed | RHSA-2026:15893 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | openssh-0:8.0p1-15.el8_6.4 | Fixed | RHSA-2026:15893 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | openssh-0:8.0p1-15.el8_6.4 | Fixed | RHSA-2026:15893 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | openssh-0:8.0p1-20.el8_8.3 | Fixed | RHSA-2026:14924 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | openssh-0:8.0p1-20.el8_8.3 | Fixed | RHSA-2026:14924 |
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-48.el9_7 | Fixed | RHSA-2026:6462 |
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-48.el9_7 | Fixed | RHSA-2026:6462 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | openssh-0:8.7p1-13.el9_0.2 | Fixed | RHSA-2026:13750 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | openssh-0:8.7p1-30.el9_2.10 | Fixed | RHSA-2026:10714 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | openssh-0:8.7p1-38.el9_4.7 | Fixed | RHSA-2026:9732 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | openssh-0:8.7p1-45.el9_6.2 | Fixed | RHSA-2026:9415 |
| Red Hat Hardened Images | openssh-main-10.2p1-9.hum1 | Fixed | RHSA-2026:5475 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202605271418-0 | Fixed | RHSA-2026:21695 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202605271328-0 | Fixed | RHSA-2026:21690 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202605060243-0 | Fixed | RHSA-2026:15087 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202605060220-0 | Fixed | RHSA-2026:14773 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202605200242-0 | Fixed | RHSA-2026:20087 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202605112123-0 | Fixed | RHSA-2026:17596 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202604240015-0 | Fixed | RHSA-2026:12071 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202605201155-0 | Fixed | RHSA-2026:20040 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1776868772 | Fixed | RHSA-2026:10065 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1776868842 | Fixed | RHSA-2026:10065 |
| Multicluster Engine for Kubernetes | multicluster-engine/hive-rhel9 | Under investigation | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-resolvers-rhel9 | Under investigation | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-operators-subscription-rhel9 | Under investigation | n/a |
| Red Hat Enterprise Linux 6 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssh | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
IMPORTANT: This vulnerability affects the OpenSSH GSSAPI delta as implemented in Red Hat Enterprise Linux and OpenShift Container Platform. An unauthenticated attacker could send a specially crafted GSSAPI message during key exchange, leading to the use of uninitialized variables and potentially undefined behavior. The severity of the impact is dependent on compiler hardening configurations.
Red Hat mitigation
To mitigate this issue, disable GSSAPI key exchange in the OpenSSH server configuration. This prevents the server from processing GSSAPI messages, eliminating the vulnerability's attack surface. Edit `/etc/ssh/sshd_config` and add or modify the line: ``` GSSAPIKeyExchange no ``` After saving the changes, restart the `sshd` service for the mitigation to take effect. This action will prevent users from authenticating via GSSAPI. ``` # systemctl restart sshd ```
References (46)
- http://www.openwall.com/lists/oss-security/2026/03/12/3 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/14/3 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/14/4 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/18/2 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/18/4 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/18/5 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/03/18/7 Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:10065
- https://access.redhat.com/errata/RHSA-2026:10714
- https://access.redhat.com/errata/RHSA-2026:12071
- https://access.redhat.com/errata/RHSA-2026:13750
- https://access.redhat.com/errata/RHSA-2026:13812
- https://access.redhat.com/errata/RHSA-2026:14773
- https://access.redhat.com/errata/RHSA-2026:14924
- https://access.redhat.com/errata/RHSA-2026:15087
- https://access.redhat.com/errata/RHSA-2026:15891
- https://access.redhat.com/errata/RHSA-2026:15893
- https://access.redhat.com/errata/RHSA-2026:16008
- https://access.redhat.com/errata/RHSA-2026:16009
- https://access.redhat.com/errata/RHSA-2026:16030
- https://access.redhat.com/errata/RHSA-2026:16174
- https://access.redhat.com/errata/RHSA-2026:17596
- https://access.redhat.com/errata/RHSA-2026:19724
- https://access.redhat.com/errata/RHSA-2026:19725
- https://access.redhat.com/errata/RHSA-2026:20040
- https://access.redhat.com/errata/RHSA-2026:20087
- https://access.redhat.com/errata/RHSA-2026:21690
- https://access.redhat.com/errata/RHSA-2026:21695
- https://access.redhat.com/errata/RHSA-2026:25096
- https://access.redhat.com/errata/RHSA-2026:5475
- https://access.redhat.com/errata/RHSA-2026:6461
- https://access.redhat.com/errata/RHSA-2026:6462
- https://access.redhat.com/errata/RHSA-2026:6463
- https://access.redhat.com/errata/RHSA-2026:7107
- https://access.redhat.com/errata/RHSA-2026:9415
- https://access.redhat.com/errata/RHSA-2026:9732
- https://access.redhat.com/security/cve/CVE-2026-3497 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2447085 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11684 Advisory
- https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3497
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.json
- https://ubuntu.com/security/CVE-2026-3497 vdb-entryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-3497
- https://www.openwall.com/lists/oss-security/2026/03/12/3 Mailing ListThird Party Advisory
Change history (0)
No recorded changes yet.