Hello,
We have assigned CVE-2026-3497 to this issue.
"Bug: Non-terminating error handler (sshpktdisconnect) in GSSAPI KEX server code allows fallthrough to uninitialized variable use
- Potentially Affected: Ubuntu/Debian OpenSSH servers with GSSAPIKeyExchange yes
Thanks,
Marc. -- Marc Deslauriers Ubuntu Security Engineer | http://www.ubuntu.com/ Canonical Ltd. | http://www.canonical.com/