Double Free Vulnerability in OpenSSH Affects FIPS Mode Client Operations
CVE-2026-55653
4.3MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 23 June 2026
What is CVE-2026-55653?
A significant flaw has been identified in OpenSSH that allows a malicious SSH server to exploit a double free vulnerability through the Diffie-Hellman Group Exchange (DH-GEX) client path. This vulnerability becomes evident during the Federal Information Processing Standards (FIPS) mode known-group validation as the client interacts with attacker-controlled DH-GEX group parameters. If successfully exploited, this flaw can cause the termination of the client-side process, leading to a Denial of Service (DoS), which disrupts users' ability to connect securely.
Affected Version(s)
Red Hat Hardened Images 10.3p1-6.hum1