https://seclists.org/oss-sec/2026/q1/299: OpenSSH GSSAPI keyex patch issue
Published Mar 12, 2026
·Updated
Affected Software
1 affected component
Canonical OpenSSH
Frequently Asked Questions
1
What is the severity of CVE-2026-3497?
CVE-2026-3497 has been classified as a high-severity vulnerability due to its potential to allow uninitialized variable use.
2
How do I fix CVE-2026-3497?
To fix CVE-2026-3497, update your OpenSSH package to the latest version that addresses the GSSAPI key exchange patch.
3
What software is affected by CVE-2026-3497?
CVE-2026-3497 affects Canonical OpenSSH servers configured with GSSAPIKeyExchange set to yes.
4
What kind of vulnerability is CVE-2026-3497?
CVE-2026-3497 is a bug related to a non-terminating error handler that can lead to the use of uninitialized variables.
5
When was CVE-2026-3497 published?
CVE-2026-3497 was published on March 12, 2026.