GHSA-wcpp-3x59-h8vp · Severity: medium — Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This...
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Conclusion & alert: CVE-2026-3497 is rated Moderate Risk (56.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.96%). Core evidence: EPSS rose +1.90% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 1.96% | +1.90% |
| 2 | 2026-06-03 | 0.03% | 0.06% | +0.03% |
| 3 | 2026-03-21 | — | 0.03% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-wcpp-3x59-h8vp · Severity: medium — Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-3497 not yet assigned priority: Debian including 1 source packages (openssh), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2026-3497 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2026-3497 |
suse
|
medium | CVE-2026-3497 severity moderate: SUSE including 18 source package names (openssh, openssh-8.0p1-28.el8_10, …), 18 product×package rows across 3 product lines (SUSE Liberty Linux 8, SUSE Liberty Linux 9, SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE): Fixed 14, Known Not Affected 4. | https://www.suse.com/security/cve/CVE-2026-3497/ |
ubuntu
|
medium | CVE-2026-3497 medium priority: Ubuntu including 2 source packages (openssh, openssh-ssh1), 14 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): ignored 6, released 4, not-affected 3, needs-triage 1. | https://ubuntu.com/security/CVE-2026-3497 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canonical | ubuntu_linux | 25.10 | cpe:2.3:a:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:* |
| openbsd | openssh | — | cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 20.04 | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 22.04 | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 24.04 | cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 9.0 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 10.0 | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://ubuntu.com/security/CVE-2026-3497 | Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2026/03/12/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/12/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/14/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/14/4 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/2 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/4 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/5 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/18/7 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2026/04/msg00014.html | Mailing List Third Party Advisory |