CVE detail
CVE-2026-3497
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
43 source links · newest first
- https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 12, 2026, 7:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3497.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 12, 2026, 7:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2447085bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/security/cve/CVE-2026-3497access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:9732access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:9415access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:7107access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:6463access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:6462access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:6461access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:5475access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:25096access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:21695access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:21690access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:20087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:20040access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:19725access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:19724access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:17596access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:16174access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:16030access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:16009access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:16008access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:15893access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:15891access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:15087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:14924access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:14773access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:13812access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:13750access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:12071access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:10714access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:10065access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 12, 2026, 7:16 PM No excerpt available.
Vendor Advisorylists.debian.orgMar 12, 2026, 7:16 PM- http://www.openwall.com/lists/oss-security/2026/03/18/7www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/18/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/18/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/18/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/14/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/14/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/03/12/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM - https://www.openwall.com/lists/oss-security/2026/03/12/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2026, 7:16 PM No excerpt available.
Third Party Advisoryubuntu.comMar 12, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2019-11038CVSS 5.3 · Medium
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19…
- CVE-2019-11833CVSS 5.5 · Medium
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive informat…
- CVE-2019-11459CVSS 5.5 · Medium
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOrie…
- CVE-2018-5095CVSS 9.8 · Critical
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized…
- CVE-2019-6111CVSS 5.9 · Medium
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the…
- CVE-2019-6109CVSS 6.8 · Medium
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object nam…