CVE-2026-55653

Discovered by AISLEPUBLISHEDCWE-415

Description

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

CVSS Base Scores

CVSS v3.1(Primary)
4.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 100:9.9p1-25.el10_2unaffected
Red HatRed Hat Enterprise Linux 80:8.0p1-30.el8_10unaffected
Red HatRed Hat Enterprise Linux 90:9.9p1-9.el9_8unaffected
Red HatRed Hat Hardened Images10.3p1-6.hum1unaffected
Red HatRed Hat Update Infrastructure 51786435483unaffected
Red HatRed Hat Update Infrastructure 51786533529unaffected
Red HatRed Hat Update Infrastructure 51787135742unaffected
Red HatRed Hat Update Infrastructure 51787241260unaffected
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat OpenShift Container Platform 4——

Credits

  • This issue was discovered by In partnership with Red Hat (Aisle.com).

References