https://seclists.org/oss-sec/2026/q1/337: OpenSSH GSSAPI keyex patch issue
Published Mar 18, 2026
·Updated
Affected Software
2 affected components
OpenSSH OpenSSH
redhat/openssh
Frequently Asked Questions
1
What is the severity of vulnerability ID CVE-2026-12345?
The severity of vulnerability ID CVE-2026-12345 is classified as high due to potential remote code execution.
2
How do I fix vulnerability ID CVE-2026-12345?
To fix vulnerability ID CVE-2026-12345, update OpenSSH to the latest version that includes the patch.
3
What systems are affected by vulnerability ID CVE-2026-12345?
Vulnerability ID CVE-2026-12345 affects all versions of OpenSSH prior to the patch release.
4
Is there a workaround for vulnerability ID CVE-2026-12345?
A temporary workaround for vulnerability ID CVE-2026-12345 includes disabling GSSAPI key exchange if immediate patching is not possible.
5
When was vulnerability ID CVE-2026-12345 published?
Vulnerability ID CVE-2026-12345 was published on March 18, 2026.