Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55653

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

Отчет

This Moderate flaw in OpenSSH affects clients operating in FIPS mode when negotiating Diffie-Hellman Group Exchange (DH-GEX) with a malicious SSH server. While it can lead to client process termination, resulting in a denial of service, the impact is limited to availability and does not result in broader system compromise. In order to exploit this vulnerability the attacker needs to trick the user to connect to an untrusted malicious server or compromise the server first. The availability impact is considered Low as the only impacted process is the single run of the SSH client trying to connect to the malicious server. This vulnerability affects only the OpenSSH versions shipped with Red Hat products.

Меры по смягчению последствий

To mitigate this issue, OpenSSH clients operating in FIPS mode should avoid negotiating the diffie-hellman-group-exchange-sha256 key exchange algorithm. This can be achieved by explicitly listing allowed key exchange algorithms in the client's SSH configuration file (e.g., /etc/ssh/ssh_config or ~/.ssh/config), ensuring diffie-hellman-group-exchange-sha256 is not included. For example, to use a subset of common algorithms, you might configure:

KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1

(Note: The above example KexAlgorithms list is illustrative and should be adjusted based on your environment's security requirements.) Additionally, avoid using non-fatal client flows, such as ssh-keyscan, against untrusted SSH servers while FIPS mode is enabled. Changes to ssh_config will take effect for new SSH connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshAffected
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshAffected
Red Hat Enterprise Linux 8opensshAffected
Red Hat Enterprise Linux 9opensshAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.3p1-6.hum1FixedRHSA-2026:3675908.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2462351openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 1 месяца назад

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

CVSS3: 4.3
nvd
около 1 месяца назад

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

msrc
около 1 месяца назад

Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service

CVSS3: 4.3
debian
около 1 месяца назад

A flaw was found in OpenSSH. A malicious SSH server can exploit a doub ...

CVSS3: 4.3
github
около 1 месяца назад

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3