USN-8090-1 Unknown

USN-8090-1: OpenSSH vulnerabilities

Canonical (Ubuntu) Released: March 12, 2026 Updated: March 16, 2026 Restart Required

Description

Jeremy Brown discovered that the OpenSSH GSSAPI Key Exchange incorrectly handled disconnecting clients. In non-default configurations where the GSSAPIKeyExchange setting is enabled, a remote attacker could use this issue to cause OpenSSH to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-3497) David Leadbeater discovered that OpenSSH incorrectly handled certain control characters in usernames. When untrusted usernames and the ProxyCommand are being used, an attacker could possibly use this issue to execute arbitrary code. (CVE-2025-61984) David Leadbeater discovered that OpenSSH incorrectly handled NULL characters in ssh:// URIs. When the ProxyCommand is being used, an attacker could possibly use this issue to execute arbitrary code. (CVE-2025-61985)

Fixed Vulnerabilities 2

CVE-2026-3497 N/A 0.0 ⚠️ KEV fixed
Mar 12, 2026

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not…

CVE-2025-61984 N/A 0.0 ⚠️ KEV fixed
Oct 06, 2025

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand…

Quick Info

Patch ID: USN-8090-1
Vendor: Canonical (Ubuntu)
Severity: Unknown
CVEs Fixed: 2
Restart: Required

Additional Info

action:
usn id: USN-8090-1
summary: Several security issues were fixed in OpenSSH.
usn number: 8090-1
instructions: In general, a standard system update will make all the necessary changes.

Share