Medium severity4.3NVD Advisory· Published Jun 23, 2026· Updated Jul 30, 2026
CVE-2026-55653
CVE-2026-55653
Description
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/almalinux/opensshpkg:rpm/almalinux/openssh-askpasspkg:rpm/almalinux/openssh-cavspkg:rpm/almalinux/openssh-clientspkg:rpm/almalinux/openssh-keycatpkg:rpm/almalinux/openssh-keysignpkg:rpm/almalinux/openssh-ldappkg:rpm/almalinux/openssh-serverpkg:rpm/almalinux/pam_ssh_agent_auth
< 8.0p1-30.el8_10+ 8 more
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 9.9p1-25.el10_2.alma.1
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 8.0p1-30.el8_10
- (no CPE)range: < 0.10.3-7.30.el8_10
Patches
Vulnerability mechanics
References
6- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingVendor Advisory
- access.redhat.com/security/cve/CVE-2026-55653nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:36759nvd
- access.redhat.com/errata/RHSA-2026:47755nvd
- access.redhat.com/errata/RHSA-2026:47756nvd
- access.redhat.com/errata/RHSA-2026:47757nvd
News mentions
0No linked articles in our index yet.