Double Free Vulnerability in OpenSSH Affects FIPS Mode Client Operations
CVE-2026-55653
4.3MEDIUM
What is CVE-2026-55653?
A significant flaw has been identified in OpenSSH that allows a malicious SSH server to exploit a double free vulnerability through the Diffie-Hellman Group Exchange (DH-GEX) client path. This vulnerability becomes evident during the Federal Information Processing Standards (FIPS) mode known-group validation as the client interacts with attacker-controlled DH-GEX group parameters. If successfully exploited, this flaw can cause the termination of the client-side process, leading to a Denial of Service (DoS), which disrupts users' ability to connect securely.