A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-23 04:17
Updated : 2026-09-01 13:19
NVD link : CVE-2026-55653
Mitre link : CVE-2026-55653
CVE.ORG link : CVE-2026-55653
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
- hardened_images
openbsd
- openssh
CWE
CWE-415
Double Free
