Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-cavsUpgrade openssh-clientsUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-askpassUpgrade openssh-keycatUpgrade opensshUpgrade pam_ssh_agent_auth | Apr 13, 2026 | Apr 2, 2026 |
| Amazon_linux_2023 | — | Upgrade pam_ssh_agent_authUpgrade openssh-clients-debuginfoUpgrade openssh-server-debuginfoUpgrade opensshUpgrade openssh-clientsUpgrade openssh-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-debugsourceUpgrade openssh-serverUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keycat | May 28, 2026 | Mar 12, 2026 |
| Debian | — | Upgrade openssh | Apr 13, 2026 | Apr 13, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Jun 2, 2026 |
| Oracle_linux | — | Upgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-keysignUpgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-cavsUpgrade openssh-clientsUpgrade openssh-askpass | Apr 22, 2026 | Mar 12, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Mar 12, 2026 |
| Redhat_linux | — | Upgrade pam_ssh_agent_authUpgrade openssh-keysign-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-keycat-debuginfoUpgrade openssh-keycatUpgrade openssh-cavs-debuginfoUpgrade openssh-keysignUpgrade opensshUpgrade openssh-debugsourceUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-cavsUpgrade openssh-ldap-debuginfoUpgrade openssh-debuginfoUpgrade openssh-askpass-debuginfo | Apr 3, 2026 | Mar 12, 2026 |
| Rocky_linux | — | Upgrade openssh-keysign-debuginfoUpgrade openssh-ldapUpgrade pam_ssh_agent_authUpgrade openssh-server-debuginfoUpgrade openssh-debugsourceUpgrade openssh-clients-debuginfoUpgrade openssh-clientsUpgrade openssh-keysignUpgrade openssh-cavs-debuginfoUpgrade openssh-askpass-debuginfoUpgrade opensshUpgrade openssh-askpassUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-keycat-debuginfoUpgrade openssh-cavsUpgrade openssh-keycatUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-ldap-debuginfo | Apr 10, 2026 | Apr 9, 2026 |
| Suse | — | Upgrade openssh-clientsUpgrade openssh8.4-serverUpgrade openssh8.4-fipsUpgrade openssh8.4-helpersUpgrade openssh-fipsUpgrade openssh-server-config-disallow-rootloginUpgrade openssh-commonUpgrade openssh8.4-commonUpgrade openssh-helpersUpgrade opensshUpgrade openssh-askpass-gnomeUpgrade openssh-cavsUpgrade openssh8.4-clientsUpgrade openssh-server-config-rootloginUpgrade openssh-serverUpgrade openssh8.4 | Jun 17, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade openssh-serverUpgrade openssh-client (Ubuntu Pro)Upgrade openssh-clientUpgrade openssh-server (Ubuntu Pro) | Mar 13, 2026 | Mar 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub