Fedora OpenSSH Update Addresses CVE-2026-3497 Information Disclosure Vulnerability

Fedora OpenSSH Update Addresses CVE-2026-3497 Information Disclosure Vulnerability

First seen 21 Mar 2026, 09:41 UTC Linuxsecurity 97% similarity 57.1

Article Content

Browse articles
ThreatCluster

A major update for OpenSSH in Fedora 43 and an important fix for Fedora 42 were released to address CVE-2026-3497, which involves information disclosure or denial of service due to uninitialized variables in gssapi-keyex. The vulnerability affects both Fedora 42 and Fedora 43 systems, potentially allowing attackers to exploit the issue if not patched. The updates were published on March 18, 2026, and are available for installation via the 'dnf' update program. Users are advised to upgrade to the latest versions to mitigate the risks associated with this vulnerability. The specific versions affected include OpenSSH 10.0p1-7 for Fedora 43 and 9.9p1-13 for Fedora 42. The vulnerability was published on March 12, 2026, and is categorized as a medium severity issue. Both articles emphasize the importance of applying the updates promptly to ensure system security.

Key Points: • CVE-2026-3497 addresses information disclosure and DoS risks in OpenSSH. • Fedora 42 and 43 users are urged to update their systems immediately. • The vulnerability was published on March 12, 2026, and patches were released on March 18, 2026.

ThreatCluster AI

Timeline

2026-03-12
CVE-2026-3497 published
2026-03-18
Patches released for Fedora 42 and 43
2026-03-21
Articles published detailing the updates

Community

Browse all →