CVE-2026-55653 - Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips kno

CVE Advisories
Post Reply
Starburst-David
Posts: 289
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-55653 - Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips kno

Post by Starburst-David »

CVE ID: CVE-2026-55653
Published: June 23, 2026
Description: A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Severity: 4.3 | MEDIUM

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-55653
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”