Low severity3.7NVD Advisory· Published Jun 23, 2026· Updated Jul 30, 2026
CVE-2026-55654
CVE-2026-55654
Description
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords7 versionspkg:rpm/almalinux/opensshpkg:rpm/almalinux/openssh-askpasspkg:rpm/almalinux/openssh-clientspkg:rpm/almalinux/openssh-keycatpkg:rpm/almalinux/openssh-keysignpkg:rpm/almalinux/openssh-serverpkg:rpm/almalinux/pam_ssh_agent_auth
< 9.9p1-9.el9_8.alma.1+ 6 more
- (no CPE)range: < 9.9p1-9.el9_8.alma.1
- (no CPE)range: < 9.9p1-9.el9_8.alma.1
- (no CPE)range: < 9.9p1-9.el9_8.alma.1
- (no CPE)range: < 9.9p1-9.el9_8.alma.1
- (no CPE)range: < 9.9p1-25.el10_2.alma.1
- (no CPE)range: < 9.9p1-9.el9_8.alma.1
- (no CPE)range: < 0.10.4-7.9.el9_8.alma.1
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingVendor Advisory
- access.redhat.com/security/cve/CVE-2026-55654nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:36759nvd
- access.redhat.com/errata/RHSA-2026:47756nvd
- access.redhat.com/errata/RHSA-2026:47757nvd
News mentions
0No linked articles in our index yet.