CVE-2026-3497 is a medium-severity vulnerability found in the OpenSSH GSSAPI delta included in various Linux distributions, not the upstream OpenSSH project. This flaw allows an unauthenticated attacker to send an unexpected GSSAPI message during key exchange, leading to the server accessing uninitialized variables and potentially causing undefined behavior, such as denial of service or information disclosure. With a CVSS score of 6.9 (Medium) and low attack complexity (AV:N/AC:L), it is network-exploitable, though its impact depends on compiler hardening configurations. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage, as reflected by its very low EPSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
25.10CPE matchmatch criteria | cpe:2.3:a:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:* | ||
20.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* | ||
22.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* | ||
24.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.