CVE-2026-55653
Discovered by AISLEPUBLISHEDCWE-415
Description
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
CVSS Base Scores
CVSS v3.1(Primary)
4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Enterprise Linux 10 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Enterprise Linux 10 | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat Enterprise Linux 8 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Enterprise Linux 8 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Enterprise Linux 8 | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Enterprise Linux 9 | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat Hardened Images | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Hardened Images | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Hardened Images | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Hardened Images | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat Enterprise Linux 6 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Enterprise Linux 6 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Enterprise Linux 6 | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat Enterprise Linux 7 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat Enterprise Linux 7 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat Enterprise Linux 7 | 10.3p1-6.hum1 | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | 0:9.9p1-25.el10_2 | unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | 0:8.0p1-30.el8_10 | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | 0:9.9p1-9.el9_8 | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | 10.3p1-6.hum1 | — |