PT-2026-51471 · Openbsd+1 · Openssh+1

·

CVE-2026-55653

·

Published

2026-06-22

·

Updated

2026-08-31

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSH (affected versions not specified)
Description A double free flaw exists in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. A malicious SSH server can exploit this to cause client-side process termination, leading to a Denial of Service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47755
ALSA-2026:47756
ALSA-2026:47757
AZL-91200
CVE-2026-55653
ECHO-BC9C-5617-0A3C
RHSA-2026:36759
RHSA-2026:47755
RHSA-2026:47756
RHSA-2026:47757

Affected Products

Openssh
Rocky Linux