CVE-2026-55653: OpenBSD OpenSSH
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Affected products
- OpenBSD OpenSSH: affected versions not specified
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only; version 10.0 only
- Red Hat Hardened Images: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
Published 2026-06-23. Last modified 2026-10-07.