Security Advisory

CVE-2026-55653

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-23 03:36:22
Last updated 2026-08-21 12:01:36
Assigner redhat
CVSS score 4.3
State PUBLISHED

Description

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).