CVE-2026-3497: vulnerability in OpenSSH used in Linux

A vulnerability has been identified in the gssapi.patch used in many Linux distributions, which adds GSSAPI-based key exchange support to OpenSSH. This vulnerability leads to memory corruption and bypassing of the privilege separation mechanism. It can be exploited remotely. The vulnerability has currently been confirmed in Debian and Ubuntu. It manifests when the option 'GSSAPIKeyExchange yes' is enabled in the settings.

Interestingly, the OpenSSH developers initially rejected the change to support GSSAPI due to concerns about its security. However, many Linux distributions have included this patch in their OpenSSH packages.

Report on debian.org

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster