A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:36759 | |
| https://access.redhat.com/security/cve/CVE-2026-55653 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2462351 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Jul 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Jun 2026, 16:57
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* |
|
| First Time |
Redhat enterprise Linux
Redhat hardened Images Openbsd openssh Redhat Redhat openshift Container Platform Openbsd |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-55653 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2462351 - Exploit, Issue Tracking, Vendor Advisory |
23 Jun 2026, 04:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 04:17
Updated : 2026-07-08 14:17
NVD link : CVE-2026-55653
Mitre link : CVE-2026-55653
CVE.ORG link : CVE-2026-55653
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
- hardened_images
openbsd
- openssh
CWE
CWE-415
Double Free
