Multiple OpenSSH Vulnerabilities (CVE-2026-35386, CVE-2026-35414, CVE-2026-35387, CVE-2026-35388)
|
Brocade Security Advisory ID |
BSA-2026-4106 |
|
Component |
OpenSSH |
|
|
|
Brocade Security Advisory: Multiple OpenSSH Vulnerabilities
Severity: High
CVEs: CVE-2026-35386, CVE-2026-35414, CVE-2026-35387, CVE-2026-35388
Brocade Security Advisory ID: 2026-4106
Summary
Brocade is issuing a security advisory regarding multiple security vulnerabilities discovered in OpenSSH.
Vulnerability Details
CVE-2026-35386: Remote Code Execution via Shell Metacharacters in Usernames
- Severity / CVSS v3 Base Score: High / 8.1
- Common Weakness Enumeration: CWE-287 (Improper Authentication) / CWE-78 (OS Command Injection)
- Description: Command-line username validation fails to properly sanitize shell metacharacters prior to token expansion in ssh_config (such as %u tokens used in ProxyCommand). A remote or untrusted user supplying a crafted username containing characters like ; or $() can inject arbitrary OS commands into client execution contexts.
CVE-2026-35387: Authentication Restriction Bypass via Improper ECDSA Algorithm Matching
- Severity / CVSS v3 Base Score: Medium / 6.5
- Common Weakness Enumeration: CWE-287 (Improper Authentication)
- Description: OpenSSH improperly processes algorithm configuration lists when specific ECDSA key types are listed in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms. Mentioning a single ECDSA variant incorrectly causes the parser to accept all ECDSA curves, potentially bypassing administrator-enforced cryptographic curve restrictions.
CVE-2026-3497: Memory Access Issue in GSSAPI Extension
- Severity / CVSS v3 Base Score: Medium / 6.4
- Common Weakness Enumeration: CWE-287 (Improper Authentication) / CWE-908 (Uninitialized Resource Access)
- Description: A logic flaw in distribution-specific GSSAPI patches causes OpenSSH to handle error conditions using non-terminating disconnect calls (sshpkt_disconnect) during GSSAPI key exchanges. An unauthenticated network attacker sending malformed GSSAPI messages can trigger access to uninitialized memory, leading to service crashes or potential information exposure.
CVE-2026-35388: Omitted Connection Multiplexing Confirmation
- Severity / CVSS v3 Base Score: Low / 2.5
- Common Weakness Enumeration: CWE-345 (Insufficient Verification of Data Integrity)
- Description: OpenSSH omits confirmation notifications during proxy-mode connection multiplexing sessions. This lack of integrity verification allows unauthorized channels to be requested without explicit client confirmation.
Products Confirmed Not Affected
- Brocade ASCG- [VEX]:Vulnerable_code_not_in_execute_path
Solution
- A security update is provided in Brocade ASCG 3.5.0 OVA
Solution & Remediation
Brocade recommends that administrators upgrade affected installations to the patched release listed below as soon as possible.
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/3/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.