Linuxsecurity
Fedora OpenSSH Update Addresses CVE-2026-3497 Information Disclosure Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A major update for OpenSSH in Fedora 43 and an important fix for Fedora 42 were released to address CVE-2026-3497, which involves information disclosure or denial of service due to uninitialized variables in gssapi-keyex. The vulnerability affects both Fedora 42 and Fedora 43 systems, potentially allowing attackers to exploit the issue if not patched. The updates were published on March 18, 2026, and are available for installation via the 'dnf' update program. Users are advised to upgrade to the latest versions to mitigate the risks associated with this vulnerability. The specific versions affected include OpenSSH 10.0p1-7 for Fedora 43 and 9.9p1-13 for Fedora 42. The vulnerability was published on March 12, 2026, and is categorized as a medium severity issue. Both articles emphasize the importance of applying the updates promptly to ensure system security.
Key Points: • CVE-2026-3497 addresses information disclosure and DoS risks in OpenSSH. • Fedora 42 and 43 users are urged to update their systems immediately. • The vulnerability was published on March 12, 2026, and patches were released on March 18, 2026.