Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-ldapUpgrade openssh-keycatUpgrade openssh-askpass | Apr 13, 2026 | Apr 2, 2026 |
| Amazon_linux_2023 | — | Upgrade openssh-debugsourceUpgrade openssh-keycatUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-serverUpgrade opensshUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-server-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-clients-debuginfo | May 28, 2026 | Mar 12, 2026 |
| Debian | — | Upgrade openssh | Apr 13, 2026 | Apr 13, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Jun 2, 2026 |
| Oracle_linux | — | Upgrade opensshUpgrade openssh-keysignUpgrade pam_ssh_agent_authUpgrade openssh-askpassUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-ldap | Apr 22, 2026 | Mar 12, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Mar 12, 2026 |
| Redhat_linux | — | Upgrade openssh-debuginfoUpgrade openssh-ldap-debuginfoUpgrade openssh-cavsUpgrade openssh-ldapUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-debugsourceUpgrade openssh-keycat-debuginfoUpgrade openssh-keysignUpgrade openssh-keycatUpgrade opensshUpgrade openssh-askpassUpgrade openssh-askpass-debuginfoUpgrade openssh-serverUpgrade openssh-cavs-debuginfoUpgrade openssh-clientsUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-keysign-debuginfo | Apr 3, 2026 | Mar 12, 2026 |
| Rocky_linux | — | Upgrade openssh-keysignUpgrade opensshUpgrade openssh-askpassUpgrade openssh-cavsUpgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-serverUpgrade openssh-keycatUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-ldap-debuginfoUpgrade openssh-ldapUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade openssh-clients-debuginfoUpgrade openssh-debugsourceUpgrade openssh-server-debuginfoUpgrade openssh-keysign-debuginfo | Apr 10, 2026 | Apr 9, 2026 |
| Suse | — | Upgrade openssh8.4-clientsUpgrade openssh8.4Upgrade openssh-serverUpgrade openssh-server-config-rootloginUpgrade openssh-cavsUpgrade openssh-fipsUpgrade openssh-commonUpgrade openssh8.4-helpersUpgrade openssh8.4-fipsUpgrade openssh8.4-commonUpgrade opensshUpgrade openssh-helpersUpgrade openssh8.4-serverUpgrade openssh-clientsUpgrade openssh-askpass-gnomeUpgrade openssh-server-config-disallow-rootlogin | Jun 17, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade openssh-clientUpgrade openssh-client (Ubuntu Pro)Upgrade openssh-server (Ubuntu Pro)Upgrade openssh-server | Mar 13, 2026 | Mar 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub