Ubuntu OpenSSH Vulnerabilities Lead to Denial of Service Risks in Ubuntu
Article Content
- •Critical vulnerabilities in OpenSSH could lead to denial of service and arbitrary code execution.
- •Affected Ubuntu versions include 20.04 LTS and others; updates were released on March 12, 2026.
- •Users should apply patches immediately to mitigate risks associated with these vulnerabilities.
Multiple vulnerabilities in OpenSSH have been identified, affecting various Ubuntu versions, including 20.04 LTS. The vulnerabilities include a critical issue discovered by Jeremy Brown regarding the GSSAPI Key Exchange, which can lead to denial of service or arbitrary code execution (CVE-2026-3497). Additionally, David Leadbeater found vulnerabilities related to control characters in usernames (CVE-2025-61984) and NULL characters in ssh:// URIs (CVE-2025-61985), both of which can also allow for arbitrary code execution. The vulnerabilities were patched in updates released on March 12, 2026. Users are advised to update their systems to mitigate these risks. The issues primarily affect users with non-default configurations enabled. The vulnerabilities were disclosed in advisories from Ubuntu and Linuxsecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Ubuntu and CVE-2025-61984 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…