Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-3497'

View all threats tagged with 'cve-2026-3497'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-3497

Threats Tagged 'cve-2026-3497'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Security Advisory: OpenShift Container Platform 4.12.91 bug fix and security updateCVE-2025-9714
0

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.91. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:21694 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes Security Fix(es): None For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor.

Join the discussion
Red Hat Security Advisory: OpenShift Container Platform 4.16.60 bug fix and security updateCVE-2025-61662
0

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.60. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:10096 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Security Fix(es): * libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) * grub2: Missing unregister call for gettext command may lead to use-after-free (CVE-2025-61662) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) * vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749) * vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) * vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc)or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPM ReleaseCVE-2025-61984
0

Red Hat Hardened Images RPM Release

Join the discussion
Red Hat Security Advisory: OpenShift Container Platform 4.14.65 bug fix and security updateCVE-2025-61662
0

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.65. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:15086 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ Security Fix(es): * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) * libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) * grub2: Missing unregister call for gettext command may lead to use-after-free (CVE-2025-61662) * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) * vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749) * vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) * vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion
Red Hat Security Advisory: OpenShift Container Platform 4.19.32 bug fix and security updateCVE-2026-3497
0

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.32. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:20039 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Security Fix(es): * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) * libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing (CVE-2026-4424) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode (CVE-2026-35385) * sudo: Sudo: Privilege escalation due to failure in privilege drop calls (CVE-2026-35535) * libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing (CVE-2026-5121) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)CVE-2026-3497
0

Red Hat® AI Inference Server

Join the discussion
Red Hat Security Advisory: openssh security updateCVE-2026-3497
0

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
Security update for gnutlsCVE-2025-9820
0

This update for gnutls fixes the following issues - CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704). - CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705). - CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708).

Join the discussion
CVE-2026-3497: CWE-908 Use of Uninitialized Resource in Ubuntu opensshCVE-2026-3497
0

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cve-2026-3497
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses