GHSA-28f3-55mq-pp68MediumCVSS 4.3
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-55653
- https://access.redhat.com/security/cve/CVE-2026-55653
- https://bugzilla.redhat.com/show_bug.cgi?id=2462351
- https://access.redhat.com/errata/RHSA-2026:36759
- https://access.redhat.com/errata/RHSA-2026:47755
- https://access.redhat.com/errata/RHSA-2026:47756
- https://access.redhat.com/errata/RHSA-2026:47757
- https://access.redhat.com/errata/RHSA-2026:54387
- https://github.com/advisories/GHSA-28f3-55mq-pp68