Security Advisory

CVE-2026-55653

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-23 03:36:22
Last updated 2026-07-08 13:59:46
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).