Page 1 of 1

CVE-2026-55653 - Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips kno

Posted: Tue Jun 23, 2026 5:04 am
by Starburst-David
CVE ID: CVE-2026-55653
Published: June 23, 2026
Description: A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Severity: 4.3 | MEDIUM

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-55653