[Git][security-tracker-team/security-tracker][master] Add CVE-2026-3497/openssh

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Mar 13 05:18:01 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d29154a by Salvatore Bonaccorso at 2026-03-13T06:16:58+01:00
Add CVE-2026-3497/openssh

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -21,7 +21,8 @@ CVE-2026-3989 (SGLangs `replay_request_dump.py` contains an insecure pickle.load
 CVE-2026-3841 (A command injection vulnerability has been identified in the Telnet co ...)
 	NOT-FOR-US: TPLink
 CVE-2026-3497 (Vulnerability in the OpenSSH GSSAPI delta included in various Linux di ...)
-	TODO: check
+	- openssh <unfixed>
+	NOTE: https://www.openwall.com/lists/oss-security/2026/03/12/3
 CVE-2026-3060 (SGLang' encoder parallel disaggregation system is vulnerable to unauth ...)
 	TODO: check
 CVE-2026-3059 (SGLang's multimodal generation module is vulnerable to unauthenticated ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d29154a5053f15216659b7eb1a9c2f4d4dd4049

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d29154a5053f15216659b7eb1a9c2f4d4dd4049
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260313/314225ba/attachment.htm>


More information about the debian-security-tracker-commits mailing list