Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6463 - Security Advisory
Issued:
2026-04-02
Updated:
2026-04-02

RHSA-2026:6463 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: openssh security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssh is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables (CVE-2026-3497)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2447085 - CVE-2026-3497 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

CVEs

  • CVE-2026-3497

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
openssh-9.9p1-13.el10_1.src.rpm SHA-256: 5f3f0295c946398886b966281a49bb16088a1a5dd52a6b6deff4a35d693c154d
x86_64
openssh-9.9p1-13.el10_1.x86_64.rpm SHA-256: 8f45d26386e0476f6b58a9cdd2adceb7e8f2fb04b6c157fc378f39d5d8bd6fc2
openssh-askpass-9.9p1-13.el10_1.x86_64.rpm SHA-256: ebee586dd118fc454f8ad3a11cc71260e012dcf6adcdc021729a91f4073f116a
openssh-askpass-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 0a6e1c4a3f48ecbfdab96e9441c2d2bbc7cf1334bb2a666f79ba79bbb56eefbd
openssh-askpass-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 0a6e1c4a3f48ecbfdab96e9441c2d2bbc7cf1334bb2a666f79ba79bbb56eefbd
openssh-clients-9.9p1-13.el10_1.x86_64.rpm SHA-256: 4ff276d910b8ce01f15ecf58ccb28e82feb6759dda10afb1d2a195c9b019d08e
openssh-clients-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: f23e7ec75f77a8f52899cf7729edd9b7c2e4293f7438a795f8fcd1516cbfac0c
openssh-clients-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: f23e7ec75f77a8f52899cf7729edd9b7c2e4293f7438a795f8fcd1516cbfac0c
openssh-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: d57c8aa72b7d4c794ce983f79fb86e7f00450cc1860179cffae885b487306fe5
openssh-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: d57c8aa72b7d4c794ce983f79fb86e7f00450cc1860179cffae885b487306fe5
openssh-debugsource-9.9p1-13.el10_1.x86_64.rpm SHA-256: 2b31f8d329709d219be353f1addc6b8ee110df5258283631aa738f4ae5d89e90
openssh-debugsource-9.9p1-13.el10_1.x86_64.rpm SHA-256: 2b31f8d329709d219be353f1addc6b8ee110df5258283631aa738f4ae5d89e90
openssh-keycat-9.9p1-13.el10_1.x86_64.rpm SHA-256: 4bd2f71f8b2cd038e7611a8dec92651456eec5ee4ede08e4ceb6b74038f88721
openssh-keycat-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: b454c4f9bb83badbd15996c0fb0af4fd76d03050a74f9daa8e8aaf6d4da2f50a
openssh-keycat-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: b454c4f9bb83badbd15996c0fb0af4fd76d03050a74f9daa8e8aaf6d4da2f50a
openssh-keysign-9.9p1-13.el10_1.x86_64.rpm SHA-256: 785cab5202aaf18bd19f20481540ed271f609012571a1c348a6e5c164b752ca1
openssh-keysign-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 1633ab9a5d53af86391cf0ed9130e6ca59b0f196e52003f819a133f40788191c
openssh-keysign-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 1633ab9a5d53af86391cf0ed9130e6ca59b0f196e52003f819a133f40788191c
openssh-server-9.9p1-13.el10_1.x86_64.rpm SHA-256: 3d799963410f92aa27498fae855334c2c426d408afc4110ab30042ae5b203796
openssh-server-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: a9314936df532f0e2acdb03a5c29934c2f95ed72fcc01ca4efd17c4a02593736
openssh-server-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: a9314936df532f0e2acdb03a5c29934c2f95ed72fcc01ca4efd17c4a02593736
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 31a8e7604b67f940d1950ba67e24ee4a069da3dbd8ae6e100a9c736b668b8c53
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.x86_64.rpm SHA-256: 31a8e7604b67f940d1950ba67e24ee4a069da3dbd8ae6e100a9c736b668b8c53

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
openssh-9.9p1-13.el10_1.src.rpm SHA-256: 5f3f0295c946398886b966281a49bb16088a1a5dd52a6b6deff4a35d693c154d
s390x
openssh-9.9p1-13.el10_1.s390x.rpm SHA-256: 5102a92970ea6299c2a6e36f06db56309c7aa7c02cd080efb97f95e377578a14
openssh-askpass-9.9p1-13.el10_1.s390x.rpm SHA-256: cc69780486cda3868e19e22a33a6d478c00191255a079922aa29831f08177342
openssh-askpass-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: d5bcdfc968924e2328e4ee1aef622f78f93469729e19808c9a489ab320084125
openssh-askpass-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: d5bcdfc968924e2328e4ee1aef622f78f93469729e19808c9a489ab320084125
openssh-clients-9.9p1-13.el10_1.s390x.rpm SHA-256: a055d32d374988b4e1ef913acfebce04a1108a5413b276c12c295949c0dc4e33
openssh-clients-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 3acee63ee17448972dbd453fbcab44048f465c1858c59566604fd7518b4f10ec
openssh-clients-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 3acee63ee17448972dbd453fbcab44048f465c1858c59566604fd7518b4f10ec
openssh-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 0e2f335a320c82eaed7bfec5c92d2480e38de1e6f6dec578c47af0c056b43fcb
openssh-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 0e2f335a320c82eaed7bfec5c92d2480e38de1e6f6dec578c47af0c056b43fcb
openssh-debugsource-9.9p1-13.el10_1.s390x.rpm SHA-256: e55562d82203742852163540a240e91db00db2d336ce3bb4ea53a156d4ffb07d
openssh-debugsource-9.9p1-13.el10_1.s390x.rpm SHA-256: e55562d82203742852163540a240e91db00db2d336ce3bb4ea53a156d4ffb07d
openssh-keycat-9.9p1-13.el10_1.s390x.rpm SHA-256: cb3d1d6fa0901ca1de47d3147a718473c8ef55e36ad82d700a07270170ed6222
openssh-keycat-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 027aaeb2978bfd30dc0177e977d637deef36bb652e43182d8d8bdac1b5a00747
openssh-keycat-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 027aaeb2978bfd30dc0177e977d637deef36bb652e43182d8d8bdac1b5a00747
openssh-keysign-9.9p1-13.el10_1.s390x.rpm SHA-256: 11e86dfe26091da72249b73283412af6c23c78905824e67161a8fa8643679025
openssh-keysign-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: bbf7e4d1c0423bc171ded486bf9a83031ed2b22bfdb0ea0506554f4942a6db81
openssh-keysign-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: bbf7e4d1c0423bc171ded486bf9a83031ed2b22bfdb0ea0506554f4942a6db81
openssh-server-9.9p1-13.el10_1.s390x.rpm SHA-256: fe1e4cfa647651a8740d805f6fb49e9e2f5a7651ff806631995ee6fe26c702cb
openssh-server-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 2fdf6ef790ecefbb78dac14322ad0fc8be50885d0bb9e01c46e53d29bd5d8833
openssh-server-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 2fdf6ef790ecefbb78dac14322ad0fc8be50885d0bb9e01c46e53d29bd5d8833
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 889a46b1c0805ce060841f3b665bc4d07bdcae57813c0b7a27d0c5b80baf0891
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.s390x.rpm SHA-256: 889a46b1c0805ce060841f3b665bc4d07bdcae57813c0b7a27d0c5b80baf0891

Red Hat Enterprise Linux for Power, little endian 10

SRPM
openssh-9.9p1-13.el10_1.src.rpm SHA-256: 5f3f0295c946398886b966281a49bb16088a1a5dd52a6b6deff4a35d693c154d
ppc64le
openssh-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 15fa87241a495ec3d9167d87fdba298f1f446f7a2ce51647d150b237130a0569
openssh-askpass-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 0cbc3498b4c3f394fb52e54e455991d7764357d25ee2f980d043452112959254
openssh-askpass-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 73a4b3f2e409e3192b7481452b6b68546706630fc54d52edb929cd729d5cc93b
openssh-askpass-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 73a4b3f2e409e3192b7481452b6b68546706630fc54d52edb929cd729d5cc93b
openssh-clients-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 78d7288590a03ec768f8cdb0186ccb67f64eff55a916d82b7e2f6556222b982e
openssh-clients-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 1a691e1329a7296716befd21a68cb4d706f2512af6791b1adc7d56e1474937cb
openssh-clients-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 1a691e1329a7296716befd21a68cb4d706f2512af6791b1adc7d56e1474937cb
openssh-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 18fdabacdbb857fe64154d13a51ac46efeef36cf6708a57596323afa17090f2f
openssh-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 18fdabacdbb857fe64154d13a51ac46efeef36cf6708a57596323afa17090f2f
openssh-debugsource-9.9p1-13.el10_1.ppc64le.rpm SHA-256: bbd96e15e0c1951136d0ee5d6b649c3f3df7229b39cb8cbbb1362083714ab26d
openssh-debugsource-9.9p1-13.el10_1.ppc64le.rpm SHA-256: bbd96e15e0c1951136d0ee5d6b649c3f3df7229b39cb8cbbb1362083714ab26d
openssh-keycat-9.9p1-13.el10_1.ppc64le.rpm SHA-256: a39192aedc9b2efbe8841970e668e85b241bdda8cb29762127c9a31539219685
openssh-keycat-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: bc8bbffc8f5f21fd005320a27952aae47060dde117ef7c332111f6f2b9af1d6a
openssh-keycat-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: bc8bbffc8f5f21fd005320a27952aae47060dde117ef7c332111f6f2b9af1d6a
openssh-keysign-9.9p1-13.el10_1.ppc64le.rpm SHA-256: d39014fc696f729195875171def15524481afad47582b5c4def4a31e65ff83cc
openssh-keysign-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: c342ddb7622041a8d6ce25ad9835bb6f2c39f983295e703bb6888902bed4c332
openssh-keysign-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: c342ddb7622041a8d6ce25ad9835bb6f2c39f983295e703bb6888902bed4c332
openssh-server-9.9p1-13.el10_1.ppc64le.rpm SHA-256: 558faf383f1aac9a525ceb6cfee790c21d91721e6a9b2ec76fcbf18409623e4f
openssh-server-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: cc3019179f568668a2a557b1d332012d7be5e6af21001ef214e9ca46cefd5620
openssh-server-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: cc3019179f568668a2a557b1d332012d7be5e6af21001ef214e9ca46cefd5620
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: f5ebcf91d846158b4384ce8229a518a37f9b5a47787720548353857bcab0e68c
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.ppc64le.rpm SHA-256: f5ebcf91d846158b4384ce8229a518a37f9b5a47787720548353857bcab0e68c

Red Hat Enterprise Linux for ARM 64 10

SRPM
openssh-9.9p1-13.el10_1.src.rpm SHA-256: 5f3f0295c946398886b966281a49bb16088a1a5dd52a6b6deff4a35d693c154d
aarch64
openssh-9.9p1-13.el10_1.aarch64.rpm SHA-256: 6425ee29597c29a08c162c7bacd13d232bf97b5ce26976562fc285d986590bf1
openssh-askpass-9.9p1-13.el10_1.aarch64.rpm SHA-256: 3c892cc17c9faa6faa416542e8b21b675d48e42c34fdb065efd4054fbc47c6bc
openssh-askpass-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 04f9c2c73438ca2a5bc89ad4a420b1733091f7f71920a0a789d3d9b829aad799
openssh-askpass-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 04f9c2c73438ca2a5bc89ad4a420b1733091f7f71920a0a789d3d9b829aad799
openssh-clients-9.9p1-13.el10_1.aarch64.rpm SHA-256: 4c001e3bdba69a81f3bbbc5237f4405111c467ddc72a6b9cab432b6ea0445909
openssh-clients-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 1853e5554ac4272b68a3f494ce8ca2827c9417ddd6926f4a1b22f3ca420336a4
openssh-clients-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 1853e5554ac4272b68a3f494ce8ca2827c9417ddd6926f4a1b22f3ca420336a4
openssh-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 5e240b73bae39b8bff5d2ade9e425a108cdc822b8029ef13b3b57be2603ce813
openssh-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 5e240b73bae39b8bff5d2ade9e425a108cdc822b8029ef13b3b57be2603ce813
openssh-debugsource-9.9p1-13.el10_1.aarch64.rpm SHA-256: 30171e0fe1f43065990dba74faf7b393c64673056a5c4091c7fda84e7bc3ca8c
openssh-debugsource-9.9p1-13.el10_1.aarch64.rpm SHA-256: 30171e0fe1f43065990dba74faf7b393c64673056a5c4091c7fda84e7bc3ca8c
openssh-keycat-9.9p1-13.el10_1.aarch64.rpm SHA-256: 61c5bac6b1c7d2b17ebfb0894347c332336347413746a77cdafaa7dd541ca002
openssh-keycat-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 9180dff7e17a149ab4cec06e157a23c674aca65d094b8bdc788ec4c4184a2737
openssh-keycat-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 9180dff7e17a149ab4cec06e157a23c674aca65d094b8bdc788ec4c4184a2737
openssh-keysign-9.9p1-13.el10_1.aarch64.rpm SHA-256: 6342468e7a1f8df6db91f52ed2d04052bf1cd7b1266abf66be4c7e1bf6a526ae
openssh-keysign-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 412bcfaf411854a10701c145b075022e51e7b899ebbcbe04ea40a45eac5df9ac
openssh-keysign-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 412bcfaf411854a10701c145b075022e51e7b899ebbcbe04ea40a45eac5df9ac
openssh-server-9.9p1-13.el10_1.aarch64.rpm SHA-256: b3856b4b7998256a82eb4f2bac70a2025f8ec3c0cf43cbce7235285af04737d0
openssh-server-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 2a21abd2c9a8608d2fa53f5bfdba6c63735459f91861edd5072d7c6eb64fa6de
openssh-server-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 2a21abd2c9a8608d2fa53f5bfdba6c63735459f91861edd5072d7c6eb64fa6de
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 6a643d9d7934d89edb183aca209a5a64cf2ac55ebd00325782920b06aa71fe05
openssh-sk-dummy-debuginfo-9.9p1-13.el10_1.aarch64.rpm SHA-256: 6a643d9d7934d89edb183aca209a5a64cf2ac55ebd00325782920b06aa71fe05

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility